SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Scyne wraps summit tour on government cyber supply risks

Scyne wraps summit tour on government cyber supply risks

Mon, 12th Oct 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Scyne has completed its national Government Sector Cyber Resilience Summit tour, with the final event held in Perth after stops in Sydney, Melbourne, Brisbane and Adelaide.

The summit brought together cyber security leaders from federal, state and local government, along with industry groups and small business advocates, to discuss risks in public sector supply chains.

Across the events, discussion centred on the exposure created when government agencies rely on large numbers of small and medium-sized businesses to deliver services. Scyne said those supplier relationships can create entry points for attackers and increase the risk of disruption to services used by communities.

A key theme was the use of independent certification instead of self-assessed security questionnaires. Delegates examined how SMB1001 certification could provide verified assurance on the cyber posture of smaller suppliers and feed that information into procurement decisions.

The sessions also focused on practical security steps for smaller businesses. The approach discussed at the summit was intended to reduce friction for suppliers while giving public sector buyers more reliable information about third-party cyber risk.

Supply chain focus

Attention on supplier cyber security has grown as public agencies review how breaches at third parties can spread into government networks. The summit examined how weaknesses in vendor systems can be exploited and how agencies can gain better visibility into the organisations they rely on.

The programme included contributions from Fortinet, LastPass, MyCISO, Cyber Wardens and Coalition Insurance. Their involvement reflected a broader effort to address supply chain security through coordination between government, advisers, technology providers and small business support groups.

The national series was designed to highlight the need for a more consistent, evidence-based way of assessing supplier cyber risk, Scyne said. It argued that static questionnaires often do not give agencies enough confidence that security controls are in place and operating.

That issue is particularly relevant in government procurement, where agencies may engage thousands of smaller suppliers across technology, operations and frontline services. For those organisations, the burden of meeting varied security assessment requirements can also be hard to manage.

Procurement questions

Discussions in each city examined how cyber assurance can be built into procurement and risk management processes. Rather than relying on vendor declarations alone, the model presented at the summit emphasised independently verified information that can be compared across suppliers.

Scyne presented this as a way to improve public sector decision-making while keeping compliance demands manageable for smaller businesses. The broader message from the tour was that cyber resilience in government supply chains depends not only on agency defences, but also on the security practices of the businesses that support public services.

"The summit convened cyber leaders from federal, state and local government, industry peak bodies and small business advocates to address the critical risks embedded in public sector supply chains," Scyne said.

"The sessions highlighted how attackers exploit supplier vulnerabilities to reach government networks, and outlined practical, low-friction security measures that small businesses can implement to feed verified risk data directly into procurement decisions," it said.