My Authors
Read all threads
What do Ministers and Commonwealth entities do when the Prime Minister gives a press conference telling the nation to lift its game on cyber security?

Nothing apparently.

@KKeneally has written to Peter Dutton to ask why.

A thread 🧵👇

theaustralian.com.au/nation/politic…
Last month, the PM held a dramatic press conference to warn that a “sophisticated state-based cyber actor” was targeting organisations across Australia.

pm.gov.au/media/statemen…
The purpose the press conference was “to raise awareness of this important issue and to encourage organisations... to take expert advice and implement technical defences to thwart this malicious cyber activity.”
The dramatic press conference certainly caught the attention of the media and the Australian public, but there’s one group that still hasn’t gotten the PM’s message in the face of this threat: the Morrison Government itself.
The Commonwealth is a major target for state-based hackers seeking sensitive data about the operation of govt, Oz citizens & businesses.

Valuable IP & scientific research are also targeted, as the successful hack of the Bureau of Meteorology showed. abc.net.au/news/2016-10-1…
Despite this, over the 7 years of the Abbott-Turnbull-Morrison Government, Australian National Audit Office reports have found that only 29% of Commonwealth departments have implemented the *mandatory* ASD developed, ‘Top Four’ cyber security mitigations.
anao.gov.au/work/performan…
The Morrison Government’s own 2019 Commonwealth Cyber Security Posture Report conceded that implementation of these mandatory cyber security standards “remains at low levels across the Australian government”.

cyber.gov.au/acsc/view-all-…
You’d like to think that a Prime Ministerial press conference warning that these entities are facing a sustained, sophisticated campaign by a foreign country might prompt some attention to this issue.

Alas, no.
But when the Attorney-General’s Department, Home Affairs and ASD appeared before a Parliamentary inquiry into this issue, there was no sign that the Morrison Government has heard Scott Morrison’s message to lift its game.

parlinfo.aph.gov.au/parlInfo/searc…
Not a cent of the Government’s recent billion-dollar ASD funding announcement would go to Commonwealth entities to help them implement these mandatory protections.
There has been no move inside government to lift the Commonwealth’s implementation of mandatory ASD’s Top Four cyber security measures in the wake of the press conference.
No initiative to fix a broken accountability system that has seen Commonwealth entities fail to implement mandatory cyber security measures without consequence for seven years.
No urgency to consider whether the increasing scale of the threat now justifies moving beyond the Top Four and mandating the ASD’s more comprehensive “Essential Eight” cyber security measures.
After nearly two hours of bureaucratic buck passing, the Auditor General, who was also appearing, made this modest observation 👇

It’s an important point, because at present, no one in the Morrison Govt is held accountable for the cyber security failings of Commonwealth entities
We don’t know which Commonwealth entities have implemented ASD protections, and which haven’t. We don’t know which Ministers are ignoring the cyber security failings of the entities for which they are responsible.

The Morrison Government won’t say.
We’ll only find out if they are breached by the state back actor that the PM tells us is currently targeting them.
Cyber security reflects the Government’s broader approach to public policy. On the surface, the attention-grabbing press conferences and heavily promoted funding announcements promise a lot. But beneath the surface, the Government is underdelivering, and neglecting the basics.
After years of ANAO reports, Parliamentary Inquiries and Prime Ministerial Press Conferences, our Government’s cyber security remains unjustifiably vulnerable.

If the worst happens, no one will be able to say they weren’t warned.
Missing some Tweet in this thread? You can try to force a refresh.

Keep Current with Tim Watts MP

Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!