Public sector organisations are regular attack targets


By Dylan Bushell-Embling
Monday, 11 March, 2019


Public sector organisations are regular attack targets

In the wake of the disclosure that the Parliament House email network was compromised by possible nation state attackers, new research has been published indicating 88% of public sector organisations have suffered at least one damaging cyber attack in the last two years.

A global study sponsored by cyber exposure management company Tenable and conducted by the Ponemon Institute surveyed public sector cybersecurity decision-makers from Australia, the US, UK, Germany, Mexico and Japan.

The survey found that 62% of public sector organisations in the six countries had suffered two or more cyber attacks in the past two years, with 23% suffering more than five.

These attacks have caused breaches and resulted in significant disruption and downtime for the targeted organisations, the report states.

The most common cyber incidents encountered include employees falling victim to phishing scams that resulted in credential theft (56%), attacks against operational technology infrastructure that resulted in downtime (55%), attacks involving Internet of Things or operational technology assets (46%), and significant disruptions in business processes caused by malware (39%).

In addition, public sector cybersecurity teams admit facing significant challenges managing cyber risk, with only 23% reporting having significant visibility into their attack surface and 62% stating that their organisation lacks adequate staff to scan for vulnerabilities in a timely manner.

While 63% of respondents want to improve their ability to detect and respond to stealthy attacks, 44% still prioritise threats based on the ease of remediation, rather than those threats that pose the greatest risk.

The vulnerability of public sector targets was highlighted last month after House Speaker Tony Smith and Senate President Scott Ryan revealed that Parliament House had fallen victim to a cyber attack that may have been conducted by a state-sponsored actor, affecting everybody with an Australian Parliament House email address.

While the MPs characterised the attack as using sophisticated methods, security experts have cast doubt on this claim, asserting that it appears the attack could have been avoided by using techniques such as multifactor authentication.

Image credit: ©stock.adobe.com/au/REDPIXEL

Please follow us and share on Twitter and Facebook. You can also subscribe for FREE to our weekly newsletter and quarterly magazine.

Related Articles

The benefits and risks of AI usage in the public sector

The coming year will see some fundamental changes in the way the public sector manages and works...

How surveillance cameras facilitate a smarter and safer world

As Australia's population continues to grow, surveillance technologies will be crucial to...

Adapting to new cybersecurity challenges: a roadmap for Australian government agencies

Given the rise in cyber threats against government networks and critical infrastructure sectors,...


  • All content Copyright © 2024 Westwick-Farrow Pty Ltd