Category: Risk Management & Compliance

Operational Resilience and the SOCI Act: Shifting to Adaptive Infrastructure Protection in 2026

Why Traditional Protection Models Fail Under Stress Traditional critical infrastructure protection models were designed around known threats and static risk profiles. This historical approach is increasingly ineffective in today’s interconnected environment. As Dr Jill Slay AM noted in the landmark…
READ MORE
critical infrastructure

SOCI Act Compliance: A Leader’s Roadmap to Critical Infrastructure Resilience

Disclaimer: The information contained in this article is general in nature and does not constitute legal advice. Readers are encouraged to obtain legal advice that applies to their particular circumstances. Why SOCI Matters to Boards and Executives For Australia’s infrastructure…
READ MORE

Security Compliance in Medicinal Cannabis: A Licence-to-Operate Requirement

Author: Mark Bezzina Medicinal cannabis is regulated as a Schedule 8 controlled drug in Australia, placing it under heightened scrutiny from multiple regulators. Security compliance is not an operational afterthought; it is a core requirement for licensing, ongoing approvals and…
READ MORE
security audit

Does Your Business Need To Undertake A Security Audit?

When a company conducts a security audit, it typically involves a thorough evaluation of the business’s information systems, policies and procedures, in order to identify potential security vulnerabilities and risks. The following are some of the key steps involved in…
READ MORE
cybersecurity

New Cybersecurity Agenda for the Federal Government

After the major Optus and Medibank data breaches of 2022, the Australian federal government is pursuing a new cybersecurity agenda. “For businesses these days, cybersecurity is as important as having a lock on the door”, said Prime Minister Anthony Albanese.…
READ MORE
ISO 27001

2022 Updates to ISO 27001

The information security management standard ISO 27001 and it’s companion standard ISO 27002 were updated in 2022. One key change is that there is now more focus on how an organisation must deal with the needs and expectations of interested…
READ MORE
cyber crime

Project REDSPICE and Australia’s Cybersecurity Investment

The Australian Federal Government has created a ten year plan which invests heavily in the cyber security sector. The government initially established a cyber security strategy in 2020, with the goal of ensuring full online security for individuals, businesses and…
READ MORE
credit cards

Payment Card Industry Data Security Standard (PCI DSS)

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for businesses that handle branded credit cards from the major card schemes such as MasterCard, Visa and American Express. The PCI DSS is required by those handling cardholder data, whether you are a…
READ MORE
critical infrastructure

Security Legislation Amendment 2022 to Critical Infrastructure

Australia has been facing an increase in cyber security threats to essential services, businesses, and all levels of governments. In recent years we have seen cyber-attacks on federal Parliamentary networks, logistics, the medical sector and universities. While owners and operators…
READ MORE
credit card

Requirements for SAQ D Service Providers

If you’re in the Payment Card Industry (PCI), you’ll be familiar with a long set of assessment questions called the Self Assessment Questionnaire (SAQ) D. It is required for merchants/ service providers, and focuses on safeguarding electronic card data that…
READ MORE
cyber security

Labor Party Pledges to Reform Cyber Security Culture

The Federal Labor Party has promised to “radically change the Commonwealth’s cyber security culture” and normalise the involvement of the wider information security community, if they win the next federal election. Cyber security culture often refers to the attitudes, knowledge,…
READ MORE

Risk Management and Cybersecurity Obligations for Critical Infrastructure

The Security Legislation Amendment (Critical Infrastructure) Act 2021 was submitted and enacted on 2 December 2021, and a new set of amendments will be submitted in early 2022, to form a second Bill. A draft version of the Bill discusses…
READ MORE
house-of-representatives-bill-2021

Amendment to Security Legislation – Bill 2021

Recently, the Security of Critical Infrastructure Act 2018 was amended in the House of Representatives. This article will discuss and explain the Security Legislation Amendment (Critical Infrastructure) Bill 2021 which was passed and came into effect on the 2nd December…
READ MORE
cyber theft

Cyber Theft Affects 80,000 State Government Employees

Thousands of employees who worked for Government agencies in South Australia had their personal details stolen through a large-scale ransomware cyber-attack. Data stolen included names, addresses, tax file numbers and banking details. Frontier Payroll Service It has been estimated that…
READ MORE
trolls

Australia To Implement New Laws Against Online Trolls

The Australian Prime minister, Scott Morrison, has announced new social media anti-trolling legislation, which requires certain information of anonymous users who post abusive content through social platforms. Within the proposed new legislation, major social media platforms such as Twitter and…
READ MORE
cyber strategy

Australian Government’s Cyber Standards Fail

Recent reports by the Australian National Audit Office (ANAO) has revealed that the Australian Government did not fully meet the implementation of the cyber security risk mitigation strategy agreed upon eight years ago, and have failed to adhere to their…
READ MORE
2020 Threat Landscape

Threat Landscape in 2020 Exposes 22 Billion Records

Living in a pandemic is stressful. But protecting system assets from cyber-attack during a pandemic is close to slaying a dragon for cyber professionals. With 2020 behind us Tenable has compiled a threat landscape report on cyber-attacks of the year.…
READ MORE
online trolls

Australian Government’s Proposed Legislation to Target Online Trolls

Recently the Australian Federal Government proposed a bill that will target online trolls in a power move to stop “harmful” content from circulating online. The draft legislation will give the government the ability to take action to counter “harmful” content…
READ MORE
cybersecurity

Understanding the Essential Eight Framework for Cybersecurity

Cyber-attacks have been reported all over the world, as the fight to secure the digital space from threat actors continues. Governments, corporations, academic institutions and even individuals can all be targeted, and sometimes exploited, through cyber-attacks and espionage, so cybersecurity…
READ MORE
cybersecurity critical infrastructure

Australia’s Critical Infrastructure Law Reform

Last month, Australia’s ongoing law reform aimed at protecting critical infrastructure assets and systems of national significance took a major step towards achieving Australia’s Cyber Security Strategy 2020, The Exposure Draft of the Security Legislation Amendment (Critical Infrastructure) Bill 2020…
READ MORE