ACSM
Why industry consultation is vital in Cyber Security
By Sarah Sloan Head of Government Affairs and Public Policy, ANZ.
T
he dust is yet to settle following the unfortunate Optus data breach, and the nation’s Minister for Cyber Security, Claire O’Neil, has already flagged plans for reform. The Government’s continued commitment to improving Australia’s cyber security resilience and data security is laudable and should be welcomed. When a major data breach occurs, it is reasonable for governments and citizens to ask whether our current laws are adequate and fit for purpose. Last week, the Government announced that banks and other financial institutions would be informed of data breaches when they occur to help identify and prevent fraudulent activity. These measures could be a major and much-needed boost to enhancing consumer protections in the face of future data breaches, so long it is underpinned by cyber security and privacy principles. As with all policy, however, the devil is in the detail. As noted by ABC News, Minister O’Neil herself has suggested that current data and cyber security requirements need to be fit for purpose. And to make them fit for purpose, it’s essential that the relevant industry stakeholders are in a position to help shape them – or at least contribute to the conversation, so all aspects are considered. The decision to bring the country’s financial services industry into the breach notification loop may be an appropriate first step to elevating data security across the board. Australia’s banks have done a reliably good job of
18 | Australian Cyber Security Magazine
sharing information about cyber security threats and best practices between each other. But any obligations placed on banks or other institutions need to be reasonable and proportionate. Moreover, the scope of any potential regime may need to be expanded to include other companies, as well as state and federal government authorities – such as those that issue driver’s licences or Medicare cards. Today, Australia’s expectations with respect to data governance and data breaches sit firmly within the Privacy Act, so any review into the adequacy of our laws in the wake of this recent breach, must logically start there. The Privacy Act remains the most appropriate instrument to address the public’s concerns around the management and retention of their personally identifiable information. The Government has already flagged amendments to the Privacy Act – saying it may look to increase the penalties associated with data breaches and broaden our privacy obligations to better align with international best practice. While this may be the impetus for cultural change across Australia, the Government may also wish to look at incentives for adherence to good practices. However, precisely what constitutes reasonable and proportionate regulation can only be ascertained through consultation with the industries it may affect. So it’s important that the Government takes a holistic and considered approach to any policies and regulatory changes it deems necessary by talking and listening to