Amazon Web Services (AWS) has encouraged the federal govt to wait until several other recent changes take effect before imposing any new cyber security laws on firms. The comments were made in response to a suggestion to enforce either optional or obligatory cyber security governance requirements on businesses.
In a contribution to the Ministry of Home Affairs consultation, AWS wrote, “We advise against the adoption of new measures before existing changes have been implemented properly, developed, and reviewed.” This procedure is necessary to ensure that any new policies are evidence-based, consistent, and complementary to current policies, and tackle true, current problems.”
The remarks, issued by AWS, The head of public policy Roger Somerville, come after a whirlwind year of cyber security reforms after the administration’s 2020 information security program. In the eight months since August 2020, the government has introduced and enacted contentious online account takeover powers, passed the Online Safety Act, and started a long-awaited review of the Privacy Act. This has also filed the Security Legislation Amendment Bill 2020, which again will give the federal government the contentious ability to protect critical infrastructure providers’ networks in the event of a cyber assault as a “last option.”
Many of the improvements, according to AWS, are “big and impactful” and will “significantly affect Australia’s information security and increase trust in the digitalization.” Last week, the Working Group on Intelligence and Security of Parliament urged that such last-resort measures be “swiftly legislated” while other parts of the bill are being delayed. However, before any new regulatory instruments or efforts are introduced, these changes need time to take effect – and impacted companies were given enough time to do so,” it added.
As a result, AWS has requested that “current reforms, frameworks, and programs be given room to be adopted, developed, and assessed before various regulatory measures are adopted. “It has also enabled the government to clarify and harmonize the regulatory environment to increase corporate and government awareness of cyber security standards. According to the discussion paper, at least 51 Commonwealth, state, and territory legislation constitute or may create some cyber security duty. As a result, there is a considerable possibility of ambiguity, contradictory, or overlapping rules,” Somerville added.
AWS was also one of several companies that opposed plans to make corporate directors liable for failing to handle cyber-attacks, which it thinks is already part of a director’s responsibilities.


