Australia’s Defence Minister, Richard Marles, hints at forthcoming “safe harbour” legislation designed to encourage companies to collaborate more effectively with government cyber agencies during security incidents. The legislation aims to address corporate concerns about legal and regulatory repercussions, fostering increased cooperation with the Australian Signals Directorate (ASD) during cyber attacks. Marles underscores the importance of building confidence for companies to engage with ASD in real-time during security incidents.
ASD Report Emphasizes Need for Safe Harbour and Improved Network Security
The ASD’s Cyber Threat Report 2022-2023 highlights key challenges in the cyber threat landscape, prompting Australia to consider “safe harbour” legislation. The report emphasizes persistent issues like inadequate patching and the insecurities in the separation of IT and operational technology (OT) networks. Marles stresses that the safe harbour concept will play a crucial role in the government’s upcoming cyber strategy, offering protection to companies collaborating with ASD during cyber attacks.
Urgent Patching and OT Network Security in Focus
The ASD’s report underscores the urgency of prompt patching, revealing that one in five newly-disclosed vulnerabilities is exploited within 48 hours of release. The report also highlights the risk of compromised OT through poorly separated IT and OT networks, especially in critical infrastructure. The prevalence of old vulnerabilities, including Log4Shell and ProxyLogon, remains a concern, with the ASD urging the need for a comprehensive approach to cybersecurity to mitigate evolving threats.

