Why a cyber security strategy should be part of the 2022-23 Budget

Expectations remain low with the upcoming Labor 2022-23 Budget relating to anything remotely actionable and practical regarding cyber security and keeping Australians safe online, writes Jacqueline Jayne, Security Awareness Advocate at KnowBe4.

The rhetoric has been a predictable year on year with โ€˜uplifting our cyber postureโ€™ and โ€˜building capability across national priority sectorsโ€™ plus โ€˜improving safety, security and trustโ€™. Please note that there is nothing wrong with that. Itโ€™s whatโ€™s missing that is a concern.

The 2020 Cyber Security Strategy was delivered without the necessary measurable deliverables and outcomes linked to cyber security’s human element, and the budgets have followed suit.

Human error the cause of most cyber security breaches

Considering the overwhelming evidence that most successful cyber attacks result from human error, it stands to reason and logic that education and awareness of humans should be non-negotiable.

Think about this for a moment. Now, and for many years, anywhere from eight to nine out of ten of successful cyber attacks or breaches result from human error. Thatโ€™s a lot.

Correct me if I am wrong. If we were to educate humans, increase their awareness, and provide them with the tools, skills and knowledge to make better decisions regarding being safe and secure online, would fewer errors be made? I say yes.

Australia has been great at promoting safety on the roads, in the sun, at the beach and work. How about a National Cyber Awareness Education Campaign for everyone, such as โ€˜Think Cyber Firstโ€™ or โ€˜Think before you clickโ€™? We already have a baseline to work with; if done correctly, the Australian Government can move the needle. Even a tiny drop would be incredible when you consider the cost of reported cyber crime to Australians was $33 billion from 1 July 2020 to 30 June 2021.

woman logging into phone with PIN number

Cyber awareness sadly lacking

You have heard a lot about the cyber skills gap in recent times and how adding more people to the cyber security workforce will fix the issues we currently face related to the increase of cyber incidents, attacks and breaches.

Let me say this first โ€“ yes, we need more people in the cyber security workforce. However, the recent Optus data breach has highlighted that we have a greater risk at hand. The cyber knowledge or awareness gap exists within the general population, which consists of every human who uses technology and devices and works outside the cyber security bubble.

In the days that followed the Optus breach, our government issued new legislation, laws and commentary towards organisations regarding cyber incidents. The media focused on who should have done what, when and why, and who was to blame.

This response is not surprising when you consider our recent research where KnowBe4 found that two-thirds of Australian IT decision-makers believe the Government should be doing more to protect against security risks; fewer than half understand their data breach reporting requirements; and more than a quarter think technology will keep them safe.

Empowering better decisions around cyber hygiene

While those what, when, why and who questions all require answers, if the consumers affected by this breach had already implemented a basic level of cyber hygiene, the stress, fear and confusion would have been minimal.

A basic level of cyber hygiene includes the use of a password manager, implementation of Multifactor Authentication (MFA) using a third-party authenticator app, and knowledge and awareness of their data – specifically the different types of data they have shared with organisations, and when they need to take action should it be involved with a data breach.

Empowering Australians to make better decisions when it comes to security is the goal that comes from a focus on security awareness, behaviour, and culture. This is a direct result of an ongoing, relevant and engaging security awareness and education program incorporating organisation-wide cooperation.

We can not rely only on government or technology when the majority of breaches directly result from human error. Cyber security is everyoneโ€™s responsibility, and we are far from being in a position where we are making better decisions regarding staying safe online.

My rose-coloured glasses remain on as the 2022/23 Labor Budget is in its final stages prior to release. I will be one of those people watching it unfold on TV and reading every page, with a focus on all things cyber security.


Want more? Get our newsletter delivered straight to your inbox!ย Follow Kochieโ€™s Business Builders onย Facebook,ย Twitter,ย Instagram, andย LinkedIn.