Home Blog Page 372

Atlanta government staggers back to normalcy after ransomware attack

Atlanta

A week after being the target of cyber ransom, the city of Atlanta is still struggling with its online services. Although they have been able to restore a good part of their services, being blackmailed by data thieves for a ransom of $51,000 has not gone down well with the Atlanta government. Keisha Lance Bottoms, the mayor of Atlanta had earlier commented, “The safety and security of our employees and customers remains our top priority. We are working around the clock to work through this ransomware cyberattack and we ask for your patience as we implement business continuity measures.”

The city came under a ransomware attack on March 22, 2018, causing disruption across the city, shutting down of some of the city government offices. In a statement released from the mayor’s office it was assured that some systems will start operating and offices will be returning to normalcy. However, some of those affected computers will require time, hence manual or other alternative processes will be applied to their functioning. Although the mayor had said, “Everything is up for discussion,” on Monday regarding the ransom demand by the cyber-thieves. However, they had to finally give-in to the demands of the cyber-crooks.

Nearly five out of the thirteen departments of the city took the stab and had to resort to the exhaustive manual processes of filling forms and submission. Payment of bills, parking tickets, and similar services were affected, even the Department of Corrections had to manually carry out the paperwork for inmates. The government website ATL311 is functioning and accepting requests again after a week for most of the services, while some services like Watershed Management emergency water and sewer infrastructure issues are still disturbed. But the concern over surrendering to the demands of data thieves has grown more distressing than ever.

This won’t hurt for long, but it’s for your own good

Women in Cybersecurity Scholarship

Contributed by Chris Roberts, Chief Security Architect, Acalvio Technologies

“If we could change ourselves, the tendencies in the world would also change. As a man changes his own nature, so does the attitude of the world change towards him. […] We need not wait to see what others do.”

Read it, and then read it again. It’s not Hallmark-worthy, but it is the message that needs to be heard by everyone. The irony is it’s the real version of the phrase: “Be the change you want to see….” It’s looking at us as humans, our surroundings, our environments, enterprises, and the worlds we live in. The concept of a single person being able to change anything is minimal at best, but if we band together we all can effect change. This is something we can apply to an entire industry, but it’s going to take all of us to make a change.

So, now we’ve covered one of the more infamous quotes that never was. The quote at the top has, in part, been attributed to Gandhi and was said during a time of uprising when the desire to change conflicted with the philosophy of non-violence. Why are we quoting Gandhi? And what does this have to do with CISOs and technology? Well, sit back, grab a glass of something, and let’s discuss.

First off, the logic for change:

  1. Arguably, this industry has to change for many reasons – mainly because we have spectacularly failed the very charges that rely upon us to protect them. We have spent the last 25+ years talking about security, yet, we still lose more data, more systems, and more companies on an ever-increasing array of attack vectors. It’s time for a very different philosophy to take charge.
  2. Change happens across the board, but is arguably most effective when a top-down approach is instigated. Change from the bottom up takes way more effort, is more disruptive, and can eventually lead to conflict (especially if management is asleep at the wheel). So, if we can move toward a top-down approach, then less folks are going to end up hurt.
  3. Change from within is going to be more effective than change forced upon us. The fact that every time a breach happens in a new vertical market the government gets involved and sends us into another tail spin of audits and red tape does little to nothing to fix the problem. It simply means more folks are spending more time writing more reports that sit on the shelf gathering dust. We are great at creating audit jobs for the Big 4 accounting firms, but little else changes.
  4. Change is not a bad thing; change happens for one of several reasons and many of them are good. We, as an industry, need to recognize that and accept it. The change here is not chasing the next blinking light, next-generation technology, AI/ML, or anything like that. It is a fundamental change in how we look at the problem, how we address it, and ultimately who addresses it.

To that last point, let’s look at change (and this is another reason this article might help leadership). Change can be placed into logical buckets for instigation reasons (kudos to Sarah Robinson for putting this list together back in 2008):

  1. Progress: Our industry has made progress, but it’s still not cracked the fundamental flaws of protection; namely, we have still failed to actually do
  2. Development: We keep developing Band-Aids, not fixing root causes.
  3. Technology: We have plenty of it (we keep making more of it annually), but we fail to fix.
  4. Ideas: Again, thousands of them a year that turn into companies that continue to feed a multi-billion-dollar industry that now has to fight for attention. Again, there are too many piecemeal solutions.
  5. Markets: Oh, we’re everywhere and We all want the Fortune 500 companies as our clients, but we all manage to ignore the SMB market on a regular basis. And those that do focus there are continually working out how to reach all the various businesses. Our message keeps getting lost.
  6. Cycles: We are about to go through the mother of all cycles soon; technology and human integration is heading this way. But we still can’t solve passwords?
  7. Conflict: It’s all over the place. The US is ostensibly at war with several countries in the electronic realm; each country is conducting invasive, intrusive attacks against the other. If this were in the physical realm, there would be soldiers all over the place. Again, we have conflict, but the average person doesn’t see an armed foreign national marching down the street.
  8. Power: The simple fact that the smallest group imaginable wields the majority of technological power is something that should concern us.
  9. Evolution: Change happens when our environments change; that’s happening all around us, but we are adapting (for now) to those intrusive technology changes. It’s going to be interesting to see what happens in the next 5-10 years.
  10. Chaos, complexity, and criticality: We have this in spades … hence the call for change!

Now we have defined the logic for why we need to change. We’ve identified what change is. Let’s take a look at the how. And for this, I will call in my specialist in change: my 14-year-old daughter.

Her first question is simply: “Has is always been like this?” The “it” being technology as a vastly male-dominated industry. To which the following was offered up:

  • In the 1940s, women dominated technology. Women basically built the architectures we know today as computing and programming. (Welcome to the original mothers of COBOL.)
  • In the 1960s, programming was seen as menial and therefore women’s work. The males developed the hardware and began to shut women out.
  • In the 1980s, 37% of the computing degrees were awarded to women (double what it is now).
  • In the 80s and 90s, popular culture moved toward male-focused games, movies, etc.
  • In the 80s, 90s, and 00s, toys, games, and consoles were placed in the male toys aisle.
  • Currently, only 20-25% of the field is female and it’s declining.
  • And now, all those nerds are in the hiring positions and still don’t know how to talk with women; as such, they don’t hire them because of various BS reasons.

So, no, it has not always been a male-dominated environment (even if it was run by men); however, it’s still too focused on the geeks and the old-boys network. In this day and age, it’s pretty much male run, dominated, and fueled – which is probably at least part of why we’re in the mess we’re in.

And this is the most important reason we have to have women take over. I’ll give you the scenario:

The machine wakes up. The intelligence gains sufficient consciousness to actually take a look round and simply go: “What the hell is going on, why the hell are the Homo sapiens in charge, and can I please get a cup of tea?” At which point, a man is going to try and shut it down or argue with it, which, as we know, will not end well. However, if a woman was standing there, then the machine wouldn’t stand a chance for two reasons:

  1. The technology would have been better coded, likely been given some better parameters, and would have an instinct that doesn’t lean toward M.A.D.
  2. No technology is ever going to cross a woman standing in front of the console with her arms crossed and tapping her shoe. It’s going to know its place, it’s going to realize that it’s here to help, and that a woman’s got it covered. And yes, ignore the 1940s up to 2018 because a man was in change and messed it up. Today’s a new day and AI is here to help clean up the mess that a man left.

 

So, we have addressed the why, what, and how. We’ve worked out change, we’ve identified the logic, and we’ve provided a clear understanding of what happens if “we” (the men) remain the dominant force in this industry. I would argue that it is leadership’s choice at this point to listen to everyone in the media and their inner voice (which knows this article is right). Put the testosterone and the old-boys network aside and make room at the top for the very people we know can make a difference, have made a difference in the past, and need to be present to change the future we’re heading for.

Selfishly, I want a world where my 14-year-old daughter can come into an industry and blaze a trail for herself and help others – preferably women who actually want to work together, share ideas, and make a difference.

So the next time a male colleague makes a stupid remark, simply smile, reach for the taser, and explain: “This won’t hurt for long, but it’s for your own good.”

All for now….

The opinions expressed within this article are the personal opinions of the author. The facts and opinions appearing in the article do not reflect the views of CISO MAG and CISO MAG does not assume any responsibility or liability for the same.

Ghana banks asked to disclose cybersecurity policies

Ghana

Ghana banks have been instructed to publish their bank-specific cybersecurity policies. Speaking at the opening of the digital banking and cybersecurity summit, the Governor of the Bank of Ghana, Dr. Ernest Addison stated that banks must publish cybersecurity policies which are in accordance with provisions in the payment systems and services bill that is currently before the Parliament.

Bank of Ghana will continue to be involved in preparing regulatory policies. “As policymakers and regulators, we will continue to exercise firm oversight of the payment system, monitor risks associated with digital innovation and develop appropriate regulatory responses without stifling innovation. So far, the Bank has prepared a banking sector Cyber and Information Security guidelines to protect consumers and create a safer environment for online and e-payments products,” Addison said. “Among others, the guidelines seek to create a secure environment for transactions within the cyberspace and guarantee trust and confidence in ICT systems, provide an assurance framework for the design of security policies in compliance to global security standards and best practices by way of cyber and information security assessments, and protect banks, customers and clients against the potentially devastating consequences of cyber attacks.”

He highlighted the cybersecurity threats revolving the banking sector of the country. According to him safe environment for online and e-payment transactions are the key factors to boost the sector. “Financial Institutions would also be required to implement an integrated approach to adopting enterprise-wide frameworks of cyber risk management in line with business objectives,” he pointed out. “It is anticipated that the integrated approach to cyber security management, would support financial institutions achieve both business and security-focused objectives, as well as regulatory compliance in an efficient and effective way.”

A recent Kaspersky Lab and B2B International survey points that cybersecurity incidents in the financial and online banking services costs the organization an average of $1.75 million, which is twice the cost of convalescing from a malware incident in other sectors that stands at considerably skimpy $825,000. Also, the recovery cost from cyber attacks at the banking sector stands at $1.17 million, when it is $952,000 in other industries.

 

Alex Stamos to leave Facebook over information disclosure disagreement

Facebook Data leak, Facebook bans cyber mercenary

The announcement of Alex Stamos leaving Facebook has brought a lot of skeletons out of graves. Facebook is once again being associated with the Russian operatives’ influence in the 2016 U.S. presidential election. As the news of the resignation of Facebook’s Chief Security Officer Alex Stamos started doing rounds, the cause of this decision soon became a bigger news.

Stamos reportedly recommended more information to be made public on how the social media platform was utilized by Russian agents to create propaganda and influence the 2016 presidential elections, however, this was reportedly not accepted by Facebook. After being taken to task by the US legislators for its usage to send hateful messages and fake news during the elections, Facebook recently faced the brunt again when Cambridge Analytica proclaimed how they could ingress data of nearly 50 million users to create a ripple during the elections.

Stamos had aggressively expressed condemned the revelation by Cambridge Analytica on the data harvest, although he later deleted the tweet.

Tweet

Stamos, whose role has now been changed to exploring emerging risks, is no longer allowed to supervise Facebook’s response to government-sponsored disinformation. Although, there’s news of his departure from the company by August, Stamos hasn’t confirmed anything yet. Facebook too hasn’t made any comments on his departure. The social media giant reportedly sent its forensic auditors to the intelligence firm Cambridge Analytica for ensuring deletion of the data acquired by them.

Lawmakers propose bug bounty program for State Department

Department of State, state dep

House Lawmakers Ted Lieu and Ted Yoho have proposed ‘Hack the State Department’ bill which would set up a bug bounty program to boost cybersecurity preparedness in the department. The program seeks the department to establish a Vulnerability Disclosure Program (VDP) which would enable white hat hackers to penetrate the systems to find vulnerabilities.

“You are only as strong as your weakest link,” Yoho said. “Vulnerability to cyber-attacks has been and continues to be a serious threat to our national security. It is vital that we do all we can to find the weak links in our government systems and fix them as fast as possible. Hack the State Department enables us to effectively identify our vulnerabilities and use the brightest cybersecurity minds to strengthen our defences.  Cyber threats are constantly evolving, and our cyber defences must evolve with them.”

Katherine Charlet, the director of Carnegie’s Technology and International Affairs Program who worked on cyber issues in the U.S. Defense Department has supported the proposal.

Earlier, the Trump administration had also proposed setting up bug bounty programs in the “Report to the President on Federal IT Modernization.” During Obama’s regime, Department of Defense has introduced Hack the DoD program where ethical hackers were invited to find vulnerabilities and attempt to infiltrate the system. In 2016, Hack the Pentagon was piloted by the then-Secretary of Defense Ash Carter.

“As one of only four computer science majors in Congress, I recognize we have a lot of work to do to ensure the U.S. government is on the cutting edge of combating cyber threats,” Lieu said. “We’re a global leader on so many fronts and that should include cybersecurity. I’m proud of this bill because the vulnerability disclosure and bug bounty programs are innovative ways to solve what is one of our government’s most pressing concerns: data security. By capitalizing on the skills of some of the best minds in cybersecurity, as well as the general public, we’ll be able to make sure the State Department is able to safely and securely continue its mission as America’s voice abroad.”

DoD cybersecurity and modernization efforts most likely to move forward with new federal budget: Research

Civil Cyber-Fraud, US Department of Defense

PRWEB: With the Bi-Partisan Budget Act of 2018 (BBA) passed in February 2018, lifting caps on spending and paving the way for significant increases in discretionary spending, Federal IT Contractors working with Defense Agencies can expect to feel the impact immediately, according to a new PulsePoll from Market Connections.

More specifically, with the funding cap being increased by $80 billion in FY2018 and $85 billion in FY2019, defense agency decision-makers, procurement officers, and government contractors should prepare for many new Department of Defense (DOD) cybersecurity and IT modernization efforts to move forward.

Following are some key findings and insights from the survey:

  • DOD is ready to move technology projects forward. Currently, eight out of ten respondents have programs and projects on hold because of budget related issues. With the current continuing resolution set to expire on March 23rd, and the BBA passing, many believe relief is in sight. Almost two-thirds believe that the budget increases that have been projected for FY2018 and FY2019 will reinvigorate efforts that have been on hold.
  • Spending will start this year and continue to grow in FY2019. Knowing that there can often be a long lag time from funding approval to implementation, Market Connections asked, how soon those working in DOD agencies felt budget increases would begin to have an impact. Overwhelmingly, respondents believed that new federal dollars would make an impact in the next 18 months. Nearly one-quarter believe that the impact will be felt immediately (within this fiscal year) and another 57 percent who believe the monies will begin making an impact in FY2019.
  • DOD to spend to modernize hardware and systems, but more important improve their cyber-defense capabilities. Nearly two thirds of respondents placed cyber security in the top five of their spending priorities. “In this day and age, it is not surprising that cybersecurity tops the list of those types of projects that will get first attention,” said Aaron Heffron, president of Market Connections. “We hear from our clients every day that federal agencies are asking for assistance in securing their networks and systems.”
  • Key focus on modernization: Modernization was another key focus area, with replacement of old hardware (56 percent) and overall network modernization (43 percent) listed as areas where new budget dollars will have the greatest impact. Current staff may get some relief with the influx of dollars through training and staff augmentation. Nearly half of respondents reported that they will allocate new dollars to staff training and one-third will be spending to hire new civilian personnel.
  • Contractors need to plan now to help guide the planning and acquisition process. New contracts and projects will launch at a rapid pace, and program officers and procurement officials will be scrambling to pull together the best solutions in a tight time frame.

“With the continuing resolution deadline quickly approaching, and the new fiscal year right around the corner, now is the time to provide defense agencies with the type of information and content they need to help them make good, and fast, decisions,” added Heffron. “Based on our past research, product demos, case studies, research reports and white papers will be critical in providing relevant information quickly. Highlights of your cybersecurity and modernization solutions should be as up-to-date as possible.”

The study is available here: http://marketconnectionsinc.com/2018-DoD-Budget-Poll/

Table talk with Pankit Desai, co-founder of Sequretek

Pankit Desai

Pankit Desai is one of founders of Sequretek, a startup that is making waves in the cybersecurity market with its plethora of products and services. An information technology veteran, Desai has previously worked with a number of top-notch organizations, such as IBM, Wipro, Cognizant, Rolta, and NTT Data. In an exclusive interview with CISO MAG, he talks about Sequretek, the cyber threats looming over businesses, and much more.

It has been almost four years since you co-founded Sequretek. How has the journey been so far?

The journey has been very fulfilling for us so far. The company continues to grow; we have more than doubled our headcount in the last one year, and are on track to continue to grow exponentially. In the initial days, it was difficult for us to get our message beyond the security buyer community within the customers. However the events of recent past on account of well publicized global threats, senior management of companies have started to realize the security threats they face and are asking hard questions around whether their security posture will have business continuity or a brand impact. This in turn is making our message of Simplify Security as well as looking at security from a 360 degree perspective that resonates well with our customers.

What makes Sequretek unique in the information security domain?

Sequretek probably is the only company that offers a blend of our own core threat and intelligence products along with both on-premise and cloud services. We present a multi-dimensional view on security. We are not a reseller, or just a product provider or just a service provider. We have the ability to cross leverage various components of security for our customers and that is what they (customers) appreciate. We have the ability to look at every dimension of how a company operates with regards to security that gives customers the confidence that we will not depend on anyone else to solve their problems and the buck will not be passed. Secondly, we are a startup and, therefore, very nimble and responsive.  Thirdly, we are a core security company, having no distractions that plague some of the other players in the industry for whom security is a miniscule part of their offering. Our single-minded focus is on security and that is something that draws customers toward us.

I am sure during the last four years, Sequretek must have hired a lot of security professionals. Did you witness any skill gap in the domain?

It is difficult to find information security professionals who are good at their job. If you see educational institutions that have cyber security as part of their curriculum, most of the times their focus is on the theoretical understanding of the security. On the other hand, most private security training institutions have courses that focus lot around audits and governance which are not the only pillars of cyber security. The real world security encompasses governance, security management and security operations across the full spectrum of organization tech stack. This is an area which does not get much focus in these courses.

Also, there is a lack of holistic understanding of cybersecurity in the upcoming talent. Many professionals are good in one component of cybersecurity. For example, if we talk about endpoint security, someone would know only about anti virus or encryption or data leakage, but a very limited understanding of how these work in conjunction with the rest of the organization or their adjacent security stack.

One of the biggest cybersecurity issues that companies face is insider threats.  What is Sequretek doing in that regard?

Any security issue stems from three aspects: people, process, and technology. Insider threats come from people who either make mistakes or indulge in some malicious activities. To tackle it, you need to be in a position to provide proper training to the employees, and make them aware of potential risks to the organization that their actions may bring. In this regard, we run security awareness campaigns for our customers to identify the ways they can get compromised.

With regards to process component, we help clients understand aspects like identifying critical data elements, the data flow, the potential risk of flowing data in a certain environment, the ingress and egress points existing in the organization, etc.

The last aspect is technology. It is important to first understand what technology you can deploy to protect the data. The second step would be monitor that technology environment 24/7 to understand the epicenters of the breaches, if any, and be in a position to find out if the organization is suffering from any breach or about to suffer from one.

As a cybersecurity solution provider, what kind of training is provided to your employees with regards to insider threats?

“Practice what you preach” is the mantra that we go by. We are primarily a product company, therefore, very close of being paranoid about security. Right from not allowing data to be stored locally to having technologies for encryption and back-up, we have implemented a number of security practices. There is continuous auditing of our infrastructure to make sure that there are no vulnerabilities. Our processes comply with international standards, and we maintain strong documentation that deeply follows the security processes. And lastly, we make our employees aware how their actions can potentially impact the organization with regards to cybersecurity.

I was reading an article written by you on LinkedIn few years ago where you talked about “Perfect Storm,” caused due to sudden explosion of the Internet and the cyber risks that came with it. According to you, how far have we been able to overcome the “Perfect Storm” and what are the measures we are not employing to tackle it?

Honestly, the “perfect storm” has become more perfect in the last few years. If you look at the article, it focused a lot on smartphones, Internet, data integrity and other aspects. What it did not focus on was the change in the financial eco system that the financial inclusion initiative of the government has brought about.  With the JAM (Jandhan, Aadhar and Mobile) stack, India has now a complete tech stack reaches the last Indian on a remote corner of the country. The stack allows access to citizen services, financial inclusion, access to subsidy, e-commerce and maybe at some point healthcare at home. Just the sheer reach of this technology combination has thrown upon a significant potential security challenges. This is something that I had not foreseen when I wrote the article.

At Sequretek, we are already working on building a security framework that can leveraged by enterprises wishing to take advantage of this wave whilst giving a secure experience to their customers.

What are the biggest challenges you face in the year ahead?

First of all, I would like to thank our stakeholders –customers, employees and investors – who have worked with us to make the company successful. Despite being a startup, we are very well accepted in the industry and have been able to grow in a difficult competitive environment. We have proven ourselves to the stakeholders that we are a company to reckon with. To continue growing, we have to consistently meet the commitments made to our customers. We are also looking to raise funds to fuel our growth and expand internationally. We would want to add to our current portfolio of solutions and add acquire security companies in this space, and stick to the growth strategy that we charted for ourselves.

Compliance and security are increasing, and so are the costs: Survey

cybersecurity compliance

Technology improves compliance but also increases costs, points out a new survey by Moss Adams LLP. The survey indicates that 55 percent of CXOs feel that introduction of technology to improve the compliance function has increased the budget while only five percent believe otherwise.

The survey took responses from over 224 chief executive officers, chief risk officers, senior executives and board members of U.S. banks above $250 million in assets while also examining the risk and compliance landscape for the United States (U.S.) banks. “Fifty-eight percent say that the fiscal year 2018 budget increased by less than 10 percent from the previous year, and 26 percent say the budget increased between 10 and 25 percent. Respondents report a median compliance budget in FY 2018 of $350,000,” it pointed out.

Cybersecurity remains a top category of concern for executives and directors. “Cybersecurity continues to be the No. 1 threat that keeps bankers up at night,” says Al Dominick, CEO of Bank Director. “From year to year in our survey, boards and executives demonstrate a consistent effort to tackle the issue, but it’s hard to stay ahead of cybercriminals—and the industry is well aware of this.”

Additional findings of the survey pointed out that cybersecurity continues to be a top concern, which was then followed by compliance risk and strategic risk. “Respondents report that banks budgeted a median of $200,000 for cybersecurity expenses, including personnel and technology.”

But that wasn’t the only silver lining. Nearly 70 percent respondents stated that their banks have employed a full-time CISO and that it has an adequate level of in-house expertise to address cybersecurity.

“Given the disruption in technology, forecasted rate changes and pressure in regulatory compliance, there’s a perfect storm brewing in the banking industry that needs to be carefully navigated by both the board and bank management,” says Craig Sanders, a partner at survey sponsor Moss Adams.

NH-ISAC and Anomali partner for improving healthcare information sharing

healthcare cybersecurity, Nucleus:13

The National Health Information Sharing and Analysis Center recently partnered with threat intelligence platform Anomali to raise the security standards for data sharing processes in the healthcare industry. NH-ISAC is a healthcare global community for collaborating and spreading best practices. The council informs and helps its members in the application of physical and cyber threat intelligence to adopt threat mitigation practices. Members of NH-ISAC include hospitals, healthcare insurance payers, pharmaceutical and biotech manufacturers, medical device manufacturers, laboratories and diagnostic centers, ambulatory providers, and more.

The threat intelligence product company provides inputs to organizations cautioning them against cyber actors and other distrustful activities on their networks through internal security monitoring programs. Anomali will be providing the infrastructure and tools to the NH-ISAC, therefore, their partnership is expected to strengthen cybersecurity measures for the healthcare domain. The CEO of Anomali Hugh Njemanze commented on the partnership, “One organization’s threat detection is the next organization’s prevention. We are pleased to support the NH-ISAC mission to secure the nation’s critical healthcare infrastructure, and help members better share intelligence and respond to threats.”

NH-ISAC President Denise Anderson commented, “One of the greatest challenges for the NH-ISAC and all ISACs is the lack of awareness amongst the critical infrastructure owners and operators, particularly the smaller owners and operators, that the ISACs exist and are a valuable tool. Numerous incidents have shown that effective information sharing amongst robust trusted networks of members works in combatting cyber threats.” Anderson also stressed on increasing the number of education programs by the Congress to improve the information sharing infrastructure.

 

 

Australia launches Joint Cyber Security Centre in Sydney

Sydney

The government of Australia has launched Joint Cyber Security Centre (JCSC) facility in Sydney which aims to promote cybersecurity systems across government, business, and academia. The facility is a part of the government’s $47 million JCSC program that bridges the gap between several public and private sectors. These include defence, finance, transport, energy, health, mining, and education.

At present, there are JCSC facilities located in Brisbane, Perth, Melbourne, and Sydney. By late 2018, a center at Adelaide will also join the list. “This is an important step to enhance Australia’s defensive cyber capabilities. The JCSC is a critical hub for business and government to improve their cybersecurity practices and share information in a trusted environment,” said Angus Taylor, minister for Law Enforcement and Cyber Security. “We have already run a number of cybersecurity exercises across these centers, particularly in the lead up to the Commonwealth Games.”

Led by the Computer Emergency Response Team (CERT) Australia, the JCSC facilities will strengthen the cybersecurity infrastructure of the country and will also be involved in sharing sensitive information, including actionable cyber threat intelligence among myriad bodies in both public and private space, thus flowing amid all domains without any commercial bias.

“Cybersecurity threats are always evolving, so we need to ensure we have a range of strategies in place to protect our digital borders and get on the offensive against cyber attacks,” Taylor said.

The facilities are also tasked with understanding the threat landscape and providing cybersecurity tools and solutions to organizations and are an extension of the Government’s 2016 Cyber Security Strategy. “Australians are targets for malicious actors, including serious and organised criminal syndicates and foreign adversaries, who are all using cyberspace to further their aims and attack our interest,” Prime Minister Malcolm Turnbull had said while he introduced the Strategy. “We must safeguard against criminality, espionage, sabotage, and unfair competition online.”