SPEECH TO ISACA CANBERRA CHAPTER AND AISA CANBERRA BRANCH

24/02/2022

SPEECH TO ISACA CANBERRA CHAPTER AND AISA CANBERRA BRANCH

THURSDAY, 24 FEBRUARY 2022

CANBERRA, ACT

###CHECK AGAINST DELIVERY###

Thank you Jonathan and Leonard for inviting me to speak tonight.

I acknowledge the traditional owners of this land, the Ngunnawal people, and pay my respects to their elders past and present.

I also want to express my solidarity toward the people of Ukraine and to anyone in the audience with friends and family in the country tonight. It's a grim day.

I appreciate being able to share the sense of community and collaboration that so often characterises infosec in the room here tonight not only given the events in Ukraine today, but also given how challenging the past few years have been.

While everyone has been battling the challenges of the pandemic in the physical world these past two years, in the digital world, the infosec community has also been dealing with ever increasing threats from nation state actors and criminal groups alike.

I know that for those defending networks, and particularly those responding to incidents, it's been an intense and demanding period and I want to express my thanks for the work you've been doing.

Ransomware would have already been a regular topic of conversation for everyone in this room in 2019 and certainly by 2020.

But it wasn't until 2021 that ransomware went mainstream amongst my peers in the policy community.

Security firm Emisoft received reports of just over half a million ransomware incidents around the world in 2021.

We saw governments around the world increasingly become targets - more than 2,300 local governments, schools, and healthcare organizations in the US were affected by ransomware attacks in 2021.

While high-profile incidents like the Colonial Pipeline attack dominated global headlines, attracting the attention of mainstream political leaders.

Australia has not been immune from these global trends.

In the last year or so we've seen major incidents impacting our essential services and critical infrastructure operators including hospitals operated by UnitingCare in Queensland and Gippsland Health Alliance in Victoria, Queensland's government energy company CS Energy, and Australia's largest meat processor JBS Foods.

Yet in February 2021 when I released a discussion paper on the need to develop a National Ransomware Strategy, the then Minister for Home Affairs hadn't said the word 'ransomware' in Parliament once.

Despite my raising the issue constantly since taking the portfolio in 2019, it wasn't until December 2020 that a member of the government even mentioned the word in Parliament.

Thankfully, the days of politicians being oblivious to this issue are now gone.

Exactly 365 days after I began calling for a national ransomware strategy, the Government introduced legislation into the Parliament giving effect to the first elements of its Ransomware Action Plan -

although it must be said that it has moved so slowly that there is almost certainly no time to pass this legislation before the election.

Beyond our shores though, ransomware has now become a top agenda item at diplomatic summits and multilateral security fora, including the G7 and bilateral meetings between major global powers.

This has been welcome, and the resulting policy interventions have been much overdue, particularly the renewed effort to enforce AML obligations on crypto exchanges, the roll out of targeted sanctions against ransomware groups and associated individuals and an increased willingness to deploy offensive cyber operations to combat this threat.

But as I indicated in my Ransomware discussion paper a year ago - there are no silver bullets in this space.

While concerted government action to both reduce the returns of ransomware attacks and increase the costs of mounting these attacks can move the needle, reducing the volume of these attacks over time, this isn't a threat that's going to go away any time soon.

Indeed, there are early indicators of a worsening outlook in 2022.

We can now see clearly that ransomware, and the cyber threat environment more generally, is strongly correlated with conditions in the broader geo-strategic environment.

Ransomware groups have long sheltered in nation states that lack the will or capability to take action on them within their own borders.

And a number of states now use ransomware gangs like the privateers of the 19th century, deploying them as quasi-deniable tools of statecraft.

In a geostrategic environment characterised by heightened tensions across multiple fronts, it's easy to imagine a scenario in which these quasi-state backed ransomware groups became more active as relations between states deteriorate.

In this context, the ACSC, CISA and the NCSC have all warned of the potential for cyber-attacks on domestic organisations within their jurisdictions either as unintended spill overs from Russian cyberattacks against Ukraine or from a general deterioration of the cyber threat environment.

This is far from the only threat we've had to confront in recent years.

APTs and increasingly well-resourced ransomware groups have increasingly used supply chain attacks to obtain access to downstream targets.

The SolarWinds supply chain attack showed how sophisticated actors could leverage this attack vector.

The Kaseya and Frontier Software incidents highlighted the potential for smaller firms with lower product maturity levels and less scrutinised software offerings to be used as an attack vector into technology supply chains

We've seen commodity attacks spawn at a rapid clip from what were once tightly held zero days as APTs have been increasingly willing to burn these vulnerabilities in their operations.

This is the situation that all of us in this room face today, whether you're a private or public sector CISO, or a policy maker like me.

It's a lot.

I've been vocal in arguing that government needs to play an active role in trying to shape the strategic environment here, that government can't just play blame the victim and wash its hands of responsibility when Australian orgs get popped.

But at the same time, all of us - public and private sector alike - have an obligation to lift the cyber maturity and resilience levels of our organisations in the face of this worsening threat environment.

Unfortunately we have some ground to make up in this regard.

I sit on the Parliamentary Joint Committee of Public Accounts and Audit.

It's one of those boring sounding but very important Parliamentary committees that's little known to all but the wonkiest public policy buffs.

But it's one of the most important institutions of accountability within the Parliamentary system.

It's a legislatively established committee of the Parliament that is the voice of the Auditor-General in the Parliament.

Commonwealth cyber resilience has been a focus of the ANAO for almost a decade now.

Over six ANAO performance audits and three JCPAA inquiries we've heard the same issues again and again.

Almost nine years since the Australian Signals Directorate's Top Four cyber security mitigations became mandatory for Commonwealth entities, less than a quarter of Commonwealth entities audited by the ANAO have been found to be fully compliant.

The Government's own Cyber Posture Report has confirmed that:

"entities' self-assessed implementation of the mandatory Top Four mitigation strategies remains at low levels across the Australian Government".

Reflecting on five years in the role, the Auditor-General highlighted systemic non-compliance with these mandatory cyber security mitigations as one of the most significant issues of concern in his mid-term report.

I fully appreciate the limitations of evaluating an organisation's cyber resilience through a compliance lens, but these metrics are the only substantive window into Commonwealth cyber-resilience available to external observers.

This persistent failure to implement a fundamental set of cyber security mitigations across the Commonwealth over the past decade should be a significant concern for everyone given the worsening threat environment.

This failure to effectively implement the Top Four over such an extended period of time also dampens expectations of what we should expect from AGD's recent commitment to mandate Essential 8 implementation at some point in the future.

We can iterate the ISM as much as we want, but until we address the culture and accountability problems within Commonwealth cyber security we're unlikely to make real progress.

I've become increasingly focused on this culture question during my time in this role.

The need for a cultural change in the approach to cyber security across the Commonwealth has become clear to me from my work with the ANAO, the Commonwealth PSPF policy holders and audited agencies during my time on the JCPAA.

Members of this committee have heard the same issues again and again.

The ANAO has clearly identified that the root cause of this systemic non-compliance is a failure of accountability within government.

In its latest report, the ANAO made its view clear when it declared that:

"The cyber policy and operational entities have not established processes to improve the accountability of entities' cybe

About
Our Community
Volunteer
Contact Information

Electorate Office

Ground Floor 455 Melbourne Road,
Newport, 3015

 

(03) 9687 7661

 

[email protected]

Privacy & Legals


About
Our Community
Volunteer
Contact Information

Electorate Office

Ground Floor 455 Melbourne Road,
Newport, 3015

 

(03) 9687 7661

 

[email protected]

Privacy & Legals

I’d like to acknowledge the Traditional Owners of the land on which we meet today. I would also like to pay my respects to Elders past and present and future custodians and Elders of the nation.