Category: Cyber security

  • Submission to the Inquiry into cyber security for small to medium sized businesses and organisations

    Australian small and medium businesses (SMBs) are widely seen as more vulnerable to cyber security incidents and crime. To better understand the issue and find directions for new solutions, the Australian House of Representatives voted to create a Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations.

    The Chair of this committee, Sally Sitou MP, described it as the first federal inquiry to specifically examine this issue for small businesses, noting that “small businesses are on the frontline of cyber risk but too often they’re expected to defend themselves without the time, tools or resources they need.”

    This committee received bipartisan support, with the Shadow Minister for the Digital Economy, Aaron Violi MP, calling it an “important committee” and putting forward a supportive proposal for a member of the Opposition to be deputy Chair, which was accepted by the Government.

    We provided a submission to the Committee to share what we’ve learnt about this problem in our work at Lumenas, and put forward a range of proposed actions for government, the business community and industry associations to address this issue systematically. Lumenas provides one part of broader solution through our tools for accidental IT leaders, but we think there’s more work to be done across the economy so small businesses are better supported.

    To read our full submission click here.

  • Ice Cream Shop or Military Base?

    Ice Cream Shop or Military Base?

    Cyber security can often feel like a game of absolutes — either we’re secure or we aren’t. But it’s more complicated than that. The answer is almost always that we’re somewhere in between.

    Cyber risk, like all other risk, exists on a spectrum. We have to decide how much risk we can tolerate, then apply treatments and other mitigations to close the gap. Determining that tolerance is one of the most important technology decisions boards and executives make — it informs the whole cyber security program.

    But how do we know what our risk appetite is?

    One discussion exercise I run with organisations helps find the answer. Everyone in the room gives a number from 1 to 5 describing the organisation’s ideal cyber risk posture. One is an ice cream shop. Five is a military base.

    The purpose isn’t to land on some point in between that describes us perfectly. The purpose is to have an open conversation about the kinds of risks we face, the ways we use technology, and how much tolerance the business has for disruption.

    Take the ice cream shop. We’re probably taking digital payments and using some systems for ordering ingredients and managing staff, but we aren’t storing sensitive customer data. If we go offline, we can keep operating on cash, or take payments from a backup mobile terminal. Cyber hygiene still matters, but security may not be a major area of investment. Even at the low end the basics are non-negotiable — the scale starts from one because no one is at zero.

    Now think about the military base. Security is top of mind. We’re storing extremely sensitive information, and we need assurance that it hasn’t been accessed without authorisation or altered. The success of our information systems can be a matter of life and death — we rely on them for far more than information storage, from accessing controlled stores to communicating time-sensitive orders and managing access by identity and clearance. Here there’s serious investment in a layered security program that is continuously monitored, reviewed, and improved.

    Most of the organisations I work with land somewhere in the middle. The exercise gives us a group conversation that can challenge assumptions and build a consensus on what our ideal posture looks like. Usually we start with a few different positions in the room — some say three, some say five — and over the course of the discussion we work out why those positions were chosen. I’m yet to work with a group that couldn’t reach a consensus to carry forward into the decisions that follow.

    From there, I most organisations benefit from formalising the output of that discussion in a risk appetite statement. That can be used alongside governance activities like reviewing cyber risk assessments, developing treatment plans, or shaping an organisational cyber security program. As leaders, we can direct investment more confidently and understand the trade-offs we’re making with risk because we’ve had a clear conversation about what it actually means for our organisation.


     This article was originally published here on Linkedin as part of the Leading Digital series from Longitude Advisory.