Telstra reminds organisations that managing cyber risks is not having ‘bank-level security’

gettyimages-1229686564.jpg

Image: Getty Images

Telstra has warned organisations to not rely purely on technological capabilities when defending against cyber threats, pointing to a need for “the other parts of cybersecurity” such as cyber risk management programs also be prioritised.

“An information security management system that is driven by managing cyber risk provides the governance of cybersecurity that’s required to go along with all of the technology components that are regularly found to be in place,” said John Powell, Telstra Purple principal security consultant.

In terms of how organisations should undertake the development of cyber risk management programs, Powell said the approach for each organisation would need to be sector-specific rather than focusing on creating “bank-level security”.

“[There’s] this misconception that there is ‘bank-level security’. The key to cyber risk management and information security management is the understanding of your contextual risk,” Powell explained.

“So we look at the organisation’s threat landscape, we look at the organisation’s assets, and that helps us to determine what the organisation’s risks are. From that point, we then work with the organisation to understand what controls they need to put in to deal with their risks so understanding the risk of the organisation itself is what is the right risk management or cybersecurity posture.”

The warning came alongside Telstra Purple launching what it has described as a “bespoke offering” for helping customers comply with the federal government’s recent critical infrastructure reforms.

The reforms have so far come in the form of two pieces of legislation, with the first one already being passed in December to give government “last resort” powers to direct a critical infrastructure entity on how to intervene against cyber attacks.

The second piece of legislation, currently before Parliament, looks to add requirements for critical infrastructure entities to have risk management programs in place and entities deemed “most important to the nation” to adhere to enhanced cybersecurity obligations.

The risk management program under the second set of laws would have to identify hazards, including cyber risks, to critical infrastructure assets and the likelihood of them occurring.

Telstra Purple’s new service entails providing advice about the development of a cyber risk management program, cyber detection and response, incident response readiness assessments, vulnerability assessments, and cyber exercises.

Powell said the target demographic of this new service would be critical infrastructure entities covered by the reforms as well as the supply chain partners to these entities.

“[Telstra Purple’s role] is to actually present to customers and talk about security issues, and help understand some of the security implications associated with either being a critical infrastructure operator or a responsible entity for critical infrastructure asset or being in that supply chain,” Powell explained.

Powell’s warning comes shortly after Prime Minister Scott Morrison called for organisations to boost their cyber defence in light of the Australian government joining other Western governments in placing sanctions on Russia for its invasion into Ukraine.

Morrison said the government had already privately reached out to some entities and that local organisations should read guidance issued by the Australian Cyber Security Centre (ACSC). 

The prime minister added that cyber would be the most obvious vector for Russian retaliation, and that companies could be targeted as well as be cyber collateral damage.

“The cyber attacks can sometimes come from miscalculation and misadventure, we have seen that in the past, where cyber attacks have sought to let loose various worms … or viruses and they get out of control of those who put them in the system,” he said.

Related Coverage

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
AI 走入微型裝置 掌握機器學習 thumbnail

AI 走入微型裝置 掌握機器學習

不少學校開始投入教授 AI 方案, 而獻主會聖母書院早於兩年前已投入於此,這次於暑假期間向筆者分享最新方案,利用 Arduino 將 AI 方案收納其中,務求讓學生於學習時感覺新穎,而設備也有毋需連線及粍電量低的好處, 務求可以較低的門檻讓學生接觸機器學習 (Machine Learning) 。 早於 2019 年,獻主會聖母書院已有發展 AI 教學方案,起初是運用 Raspberry Pi 4 加 Pi Zero Camera ,配合 TensorFlow Lite 製作手語方案,令學生具備基本 AI 認知。次年因應疫情,製作社交距離檢測儀,運用雲端的 Google Colab ,學習物件辨識的運用和盲點。該校過往的教學設計,大多採用 Raspberry Pi ,優點是價錢合理,每件約 400 多港元,但往往要配合特定的作業系統,對新手而言,學習門檻較高。 獻主會聖母書院教師團隊(左起)教師鄭臻諺、彭嘉煒和黃梓駿。傳統程式與機器學習的分別。機器學習降落手中 至於該校新發展,彭嘉煒老師講解,這次會讓學生理解傳統程式與機器學習的分別,傳統程式如要辨識貓,就要命令電腦按規則分析,如顏色、形狀等。機器學習 (Machine Learning) 角色不一樣,把答案和樣本給電腦 「學習」,電腦自行找出規則,如貓有甚麼特徵?顏色是怎樣?形狀是怎樣?經過機器學習後,由電腦決定甚麼規則才有效。至於這次的學習課程及計劃籌備,由黃梓駿老師負責,他運用 TinyML (微型機器學習技術)作全新教學方案。黃老師表示,隨著人工智能成熟,人工智能在雲端以外,逐漸走入至微型設備中,如此一來不用經由雲端資料傳送,加上在電量方面著重低功耗發展,有望在更多設備上應用。此外, TinyML 能儲存於 Arduino ,成本更低之餘,操作難度亦降低。 黃老師選用 Arduino Nano 33 BLE…
Read More
Google Chat introduces Smart Compose for quick conversations thumbnail

Google Chat introduces Smart Compose for quick conversations

As part of Google’s recent AI run, the Mountain View, California-based company is now adding ‘Smart Compose’ to Google Chat. The feature, which is already available on Google Docs and Gmail, gives users relevant suggestions on how to finish a sentence using machine learning. According to the company, the feature “saves you time by cutting
Read More
The 5GHz “Problem” for Wi-Fi Networks: DFS (2018) thumbnail

The 5GHz “Problem” for Wi-Fi Networks: DFS (2018)

Wi-Fi networking provides us with 2 bands for the operation of wireless LAN networks: the 2.4Ghz band and the 5GHz band. The 2.4GHz band has a reputation of being something of a “sewer” of a band, due to its limited number of usable channels, the number of Wi-Fi devices already using the band, and the
Read More
Semiconductor world in for a rough ride as chip bubble bursts thumbnail

Semiconductor world in for a rough ride as chip bubble bursts

Analysis The semiconductor gold rush is all but over at the high end, and we've had our fill. Or so the past month of dismal earnings might have you believe. Electronics giant Samsung saw its profits contract 69 percent during the fourth quarter, while revenues slumped eight percent overall. South Korean memory manufacturer SK Hynix
Read More
How durable is the iPhone 13 Pro Max?  (video) thumbnail

How durable is the iPhone 13 Pro Max? (video)

30.09.2021 19:56 | Mobile Apple je nedavno objavio iPhone 13 liniju telefona, a sada je došlo vreme da se vidi kako se modeli iz nove serije snalaze na testovima izdržljivosti. Tako se iPhone 13 Pro Max našao u rukama Zacka, sa YouTube kanala JerryRigEverything.Telefon je podvrgnut uobičajenim testovima grebanja i paljenja ekrana, kao i savijanje…
Read More
Index Of News
Total
0
Share