• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Logo of Agilient Security Consultants, Australia

Agilient Security Consultants Australia

The Best Security Consultants

Menu
  • Industries
      • Aviation and Airport Security Consultants Australia
      • Defence Industry Security Consulting
      • Government Security Consulting
      • Healthcare & Hospitals Security Consulting
      • Corrections and Detention
      • Maritime Security Consultant
      • Aged Care Facilities
      • Mining, Oil & Gas
      • Public Venues & Events
      • Rail
      • School and Education Security Consultant
      • Telecommunications Security Consultant
      • Utilities
      • Places of Faith and Worship
    • advice-colleagues-communication-newIndustries
  • Services
      • Cybersecurity Consultants
      • Protective Security
      • Business Resilience
      • Building Security Consultants
      • Security Audits
      • Cyber Audits
      • Data
      • Pandemic Planning
      • Azure
      • Electronic Security
      • IT Disaster Recovery Planning
      • Business Continuity Consultants
      • Identity Theft Consultant​
      • Security Consultants
      • Security Camera and CCTV Consultant
      • ISO
      • Duress Alarms
      • Cloud
      • AWS
      • Awareness Training
      • Penetration Testing
      • Security Risk Assessment Consultants
      • Managed Security Service Provider
      • Protection against Vehicles as a Weapon
    • training-1Services
  • Locations
    • Security Consultant Melbourne
    • Security Consultant Sydney
    • Security Consultant Brisbane
    • Security Consultant Adelaide
    • Security Consultant Canberra
    • Security Consultant Perth
  • Resources
    • menumanagers-dealing-customer-agreTraining
    • working-together-newJoin The Tribe
    • Webinars_3-1.jpgUpcoming and Past Events
    • hacking-detected-shutterstock_newResources
  • Articles
  • About
    • About Us
      We are an Australian owned and operated security company specialising in risk, cybersecurity, protective security, crisis and business continuity management services.
    • frequently-asked-questions-smallFAQ’s
    • bg-menu-government-institutionsConsultant Registration
  • Contact Us
Contact Us

Closed Doors and Clean Houses: Taking Every Initiative to Prevent a Data Breach

You are here: Home / Security News / Closed Doors and Clean Houses: Taking Every Initiative to Prevent a Data Breach

Last week, it was revealed that an undisclosed Australian based defence subcontractor had been hacked.  Up to 30GB of data had been stolen from their servers.  The data was related to key defence projects, including the development of Joint Strike Fighter Jets and information on some of Australia’s newly developed submarines.

Two of Australia’s top cyber intelligence agencies, the Australian Signals Directorate (ASD) and the national Computer Emergency Response Team (CERT) worked together to investigate the breach.  It was discovered that the data breach to the subcontractor’s servers had occurred as early as July 2016[1].  The perpetrator, codenamed ‘Alf’ by the ASD had obtained access to the data up until November 2016, after the ASD discovered its activities[2].

The subcontracting company was not aware that they had been the victims of a data breach until after it had been discovered. The joint investigation by the ASD and CERT revealed that there were several deficiencies in the company’s IT defences.  In fact, the breach was initially discovered by a ‘partner organisation’ that worked with the subcontracting company.  They intended to report the breach but were hampered by regulatory and legal processes that they needed to go through[3].

Other security deficiencies that were identified included:

  • Small IT staff numbers in place to maintain data and server security;
  • Unpatched operating systems that had not been updated in almost a year[4];
  • Loose implementation of admin rights on networks, servers and equipment (‘Alf’ hacked their admin portal and installed archiving software thanks to this vulnerability that enabled him to obtain the data); and
  • Lax password renewal, with administrative systems using the default ‘admin’ or ‘guest’ passwords.

News of the data breach coincided with the launch of a new Cyber Security Centre in Melbourne. Along with another centre established in Brisbane, these centres will provide the latest information on cyber security to the public and provide some assistance to businesses in securing their IT systems effectively.

While most businesses may not manage data relating to government projects or national security, it is still imperative that your business, no matter how large or small, be well protected from cyber attacks.

Securing your IT does not require defence agency levels of sophistication either. As per the above, key lessons to learn include:

  • Practice good password management – It is important that all employees change passwords regularly as well as create hard to breach passwords (using numbers, punctuation marks etc)
  • Patch software and operating systems regularly – more importantly, always ensure that the software used comes from reliable sources that can provide patch updates and additional support
  • Control admin rights on your equipment and networks – ensure that access to the backend functions of your systems is restricted to only those who are qualified to use it.
  • Ensure you have well-trained and resilient IT staff – engage staff that are willing and able to adapt to the latest trends in cyber security.

Additionally, ensure that all your staff is trained to some extent to recognise phishing or viral activity.  Social engineering attacks occur when staff open suspicious emails, for example, and inadvertently expose their networks to an attack.

With the increase in cyber attacks around the world that have affected all manner of organisations including healthcare, governments and financial institutions; it is clear that no business, no matter how big or small, is safe from hacking.

There are resources available to you that can assist and consult you in assessing, preparing and protecting your IT systems so that your business is ready to handle the next cyber threat. If your organisation requires assistance in any of the aforementioned areas, do not hesitate to contact Agilient.

The Agilient Team

[1] https://www.abc.net.au/news/2017-10-11/hacker-stole-data-from-defence-subcontractor/9040906

[2] https://www.zdnet.com/article/secret-f-35-p-8-c-130-data-stolen-in-australian-defence-contractor-hack/

[3]https://www.itnews.com.au/news/hacked-aussie-defence-firm-lost-fighter-jet-bomb-ship-plans-475211

[4] https://www.information-age.com/extensive-hack-breaches-australian-defence-data-123469061/

Tweet
Share

Security News

Looking for a security partner? Get in touch with Agilient.

Looking for practical and cost-effective security and risk solutions for your government department, agency or company? Speak with Australia’s leading senior security, risk and resilience experts.


Looking for a pandemic planning partner? Get in touch with Agilient.

Looking for practical and cost-effective risk management solutions for your government department, agency or company? Speak with Australia’s leading senior risk and emergency management experts.



Footer

Agilient is a proud member of

Ai Group Defence Council
Australian Industry & Defence Network
Australian Security Industry Association
Sydney Aerospace & Defence Interest Group

Company and Licensing Details:

ABN: 37 157 911 441
NSW Security Master Licence # 410783087
ACT Security Master Licence # 17502184
Vic Security Registration # 878-460-40S
Qld Security Firm Licence # 3834422

Join The Tribe

Sign up to receive our regular Agilient newsletter including the latest security, risk and resilience updates

Sign up now

Copyright © 2025 Agilient – Level 14, 275 Alfred St, North Sydney NSW 2060 Australia – 1300 341 692

Our Services

Security Consultant

Security Consultant Sydney

Security Consultant Melbourne

Security Consultant Canberra
Security Consultant Perth

Security Consultant Adelaide

Security Consultant Brisbane