Telstra reminds organisations that managing cyber risks is not having ‘bank-level security’

gettyimages-1229686564.jpg

Image: Getty Images

Telstra has warned organisations to not rely purely on technological capabilities when defending against cyber threats, pointing to a need for “the other parts of cybersecurity” such as cyber risk management programs also be prioritised.

“An information security management system that is driven by managing cyber risk provides the governance of cybersecurity that’s required to go along with all of the technology components that are regularly found to be in place,” said John Powell, Telstra Purple principal security consultant.

In terms of how organisations should undertake the development of cyber risk management programs, Powell said the approach for each organisation would need to be sector-specific rather than focusing on creating “bank-level security”.

“[There’s] this misconception that there is ‘bank-level security’. The key to cyber risk management and information security management is the understanding of your contextual risk,” Powell explained.

“So we look at the organisation’s threat landscape, we look at the organisation’s assets, and that helps us to determine what the organisation’s risks are. From that point, we then work with the organisation to understand what controls they need to put in to deal with their risks so understanding the risk of the organisation itself is what is the right risk management or cybersecurity posture.”

The warning came alongside Telstra Purple launching what it has described as a “bespoke offering” for helping customers comply with the federal government’s recent critical infrastructure reforms.

The reforms have so far come in the form of two pieces of legislation, with the first one already being passed in December to give government “last resort” powers to direct a critical infrastructure entity on how to intervene against cyber attacks.

The second piece of legislation, currently before Parliament, looks to add requirements for critical infrastructure entities to have risk management programs in place and entities deemed “most important to the nation” to adhere to enhanced cybersecurity obligations.

The risk management program under the second set of laws would have to identify hazards, including cyber risks, to critical infrastructure assets and the likelihood of them occurring.

Telstra Purple’s new service entails providing advice about the development of a cyber risk management program, cyber detection and response, incident response readiness assessments, vulnerability assessments, and cyber exercises.

Powell said the target demographic of this new service would be critical infrastructure entities covered by the reforms as well as the supply chain partners to these entities.

“[Telstra Purple’s role] is to actually present to customers and talk about security issues, and help understand some of the security implications associated with either being a critical infrastructure operator or a responsible entity for critical infrastructure asset or being in that supply chain,” Powell explained.

Powell’s warning comes shortly after Prime Minister Scott Morrison called for organisations to boost their cyber defence in light of the Australian government joining other Western governments in placing sanctions on Russia for its invasion into Ukraine.

Morrison said the government had already privately reached out to some entities and that local organisations should read guidance issued by the Australian Cyber Security Centre (ACSC). 

The prime minister added that cyber would be the most obvious vector for Russian retaliation, and that companies could be targeted as well as be cyber collateral damage.

“The cyber attacks can sometimes come from miscalculation and misadventure, we have seen that in the past, where cyber attacks have sought to let loose various worms … or viruses and they get out of control of those who put them in the system,” he said.

Related Coverage

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Facebook Renews Its Ambitions to Connect the World thumbnail

Facebook Renews Its Ambitions to Connect the World

Facebook first revealed its plans to build a 37,000-kilometer subsea cable, named 2Africa, in the spring of 2020, and it announced an expansion last month. It’s expected to be completed in 2023 or 2024. The new transatlantic cable project will supposedly provide 200 times more capacity than the submarine cables that were laid in the…
Read More
11 African startups to watch out for in 2022 thumbnail

11 African startups to watch out for in 2022

It’s safe to say the Africa startup ecosystem came full circle last year with a record-breaking number of new innovative startups and huge investment to match it. If innovation is a reflection of economic, social, and technological advancement, then we can say the ecosystem has advanced.  So, out of hundreds of excellent startups in Africa,…
Read More
SMIC beleži rekordan prihod uprkos američkim sankcijama thumbnail

SMIC beleži rekordan prihod uprkos američkim sankcijama

Najveći kineski proizvođač čipova Semiconductor Manufacturing International Corporation prijavio je rekordan prihod i porast profita prošle godine usred globalnog nedostatka čipova, ali velike potražnje. SMIC stavljen na američku trgovinsku crnu listu SMIC je u 2021.godini zabeležio prihod od 5,44 milijarde dolara koji je povećan za 39 odsto u odnosu na prethodnu godinu, što je najbrža stopa rasta…
Read More
 thumbnail
Denne kommentaren ble først publisert i Aftenposten og er gjengitt med tillatelse. Aftenposten har jobbet med pendlerboliger jevnt og trutt siden høstens avsløringer av Kjell Ingolf Ropstads utnyttelse av reglene. Bakgrunnen for arbeidet er en oppriktig tro på at vårt politiske system er avhengig av tillit. Den tilliten er igjen avhengig av at våre folkevalgte…
Read More
International police shut down 15 server infrastructures as part of VPNLab.net's takedown thumbnail

International police shut down 15 server infrastructures as part of VPNLab.net’s takedown

Some 15 server infrastructures used by crims to prepare ransomware attacks were seized by cops yesterday as part of an international sting to take down VPNLab.net. The VPN provider's service gave users "shielded communications and internet access" that was used in "support of serious criminals acts such as ransomware deployment and other cybercrime activities," Europol…
Read More
Index Of News
Total
0
Share