Story image

Australia’s breach disclosure policy has major holes, expert says

18 Oct 2017

Australia’s breach disclosure policy doesn’t go nearly far enough in protecting consumers and pales in comparison to the European Union’s GDPR regulations. In fact, Australian privacy law may not go far enough to bring businesses and their partners in line.

Those are the statements from Carbon Black’s global senior director of compliance, Chris Strand. He believes that while the Privacy Act will pressure Australian organisations to report data breaches, it only applies to certain businesses.

“Its one downside is that the penalties are far below those of many recent privacy mandates. The Australian maximum penalties of $360,000 for individuals or $1.8 million for organisations - and breach disclosure applies only to organisations that exceed $3 million annual turnover,” Strand explains.

Because a large proportion of Australian businesses have less than $3 million annual turnover, this could mean a significant proportion could be exempt from reporting data loss.  

The European Union’s GDPR rules can penalise businesses for the amount which is highest: up to 4% of their GDP or up to 20 million Euros (AU$30 million).

While heavy (or not so heavy) penalties such as fines may scare businesses into compliance, there are other incentives to encourage better security.

Strand believes that privacy law should encourage breach disclosure and reward those that practice privacy by design or make it part of their data policies – including the right protections and plans in place.

These plans should help protect data or report the security policies in place.

He also believes that with the right security and preparation across policy, architecture and implementation, it is possible for organisations to deal with the full scope of a data breach.

“But I’m not convinced they are quite ready to do this today.  Given the recent string of data and information breaches worldwide recently, there is still much to do to ensure breach discovery and report perfection,” he explains.

New technologies are also risking compliance standards, Strand says.

“We have never had a period with more unsupported vulnerable applications and operating systems globally as we do now.  Many of the recent major exploits, such as WannaCry were successful by preying on unsupported system vulnerabilities – something that’s unacceptable in this age of advanced security technology,” he explains.

Strand notes that the Australian Signals Directorate engages with businesses before, during and after the mandatory notification that would be enacted under breach notification laws. It also follows an application whitelisting approach to mitigation.

“This also promotes the adoption of powerful mitigation techniques while encouraging businesses to move to a better security posture and transparency in data privacy and protection policy.”

Strand recommends a defence-in-depth approach with application control and protections.

“Carbon Black advocates that applying a positive security approach that can prioritise events in real time while enforcing the trust policy will lead to eliminating the risk of vulnerabilities, while automating the process of identifying potential anomalies that target systems and data.”

Cloud application attacks in Q1 up by 65% - Proofpoint
Proofpoint found that the education sector was the most targeted of both brute-force and sophisticated phishing attempts.
Singapore firm to launch borderless open data sharing platform
Singapore-based Ocean Protocol, a decentralised data exchange that promotes data sharing, has revealed details of what could be the kickstart to a global and borderless data economy.
Huawei picks up accolades for software-defined camera ecosystem
"The company's software defined capabilities enable it to future-proof its camera ecosystem and greatly lower the total cost of ownership (TCO), as its single camera system is applicable to a variety of application use cases."
Aussies too lax about IoT security - McAfee
Aussie consumers are at a loss when it comes to securing the increasing number of connected devices in their homes and are often opting to take no action at all.
Barracuda expands MSP security offerings with RMM acquisition
Managed Workplace delivers an RMM platform with security tools and services, such as site security assessments, Office 365 account management, and integrated third-party antivirus.
Flashpoint: APAC companies must factor geopolitics in cyber strategies
The diverse geopolitical and economic interests of the states in the region play a significant role in driving and shaping cyber threat activity against entities operating in APAC.
Expert offers password tips to aid a stress-free sleep
For many cybersecurity professionals, the worries of the day often crawl into night-time routines - LogMeIn says better password practices can help.
SolarWinds extends database anomaly detection
As organisations continue their transition from purely on-premises operations into both private and public cloud infrastructures, adapting their IT monitoring and management capabilities can pose a significant challenge.