TNT 0.00% 13.0¢ tesserent limited

Cyber security in the media, page-156

  1. 6,572 Posts.
    lightbulb Created with Sketch. 2448
    in the SMH today ..
    I wonder if TNT is considering setting up an audit section to do this kind of work ? They would need to get highly skilled "auditors".

    APRA says banks and insurers need to improve cybersecurity

    By Tim Biggs

    Boards across the banking, insurance and superannuation industries will soon be required to engage an external firm to audit cyber resilience, with the Australian Prudential Regulation Authority aiming to close systemic gaps that leave Australia's financial systems open to damage from attack. APRA today unveiled its updated cyber security strategy, noting a lack of compliance with its CPS 234 minimum security standards which were put into effect last year.

    Outgoing Executive Board Member Geoff Summerhayes said that in the wake of COVID-19 the potential threat surface for cyber attacks was higher than ever, and the potential impact multiplied when financial institutions and other bodies weren't as secure as they should be.

    "It’s close to 18 months since CPS 234 came into effect, and we are still seeing too many basic cyber hygiene issues across the industry", he said in a livestreamed speech to the Financial Services Assurance Forum.

    "Our goals here are to eradicate unnecessary or careless cyber exposures, foster a community of cyber defenders that is greater than the sum of its individual parts, and make sure entities are battle ready for when breaches inevitably occur."

    Summerhayes said the once-off audits were being mandated because entities were reporting positively on their compliance, but reviews uncovered significant weaknesses in every instance.

    "At one level this exercise is about identifying compliance issues and ensuring they are rectified in the shortest period of time to protect companies and the wider system," he said.

    "At another level, it’s sending a message about the seriousness of this issue, and the need for greater accountability."

    CPS 234 requires companies to maintain security capabilities and evaluate the security of third parties, have policies and management plans in place, conduct regular tests, and have mechanisms to notify APRA and other bodies of incidents as they occur.


    All IMHO, DYOR
 
watchlist Created with Sketch. Add TNT (ASX) to my watchlist

Currently unlisted public company.

arrow-down-2 Created with Sketch. arrow-down-2 Created with Sketch.