The New South Wales state government assigned Cyber Security NSW with the responsibility of improving cybersecurity in the local government sector in 2020, but failed to provide the agency with the power to enforce cybersecurity measures on councils.
The NSW auditor general highlighted this discrepancy in a recent report. The agency was given general responsibilities to extend support and raise the capability of cybersecurity in the local government sector, which includes monitoring, intelligence, training and awareness.
The whole-of-government security agency has had mixed results in engaging with the local government sector, with a lack of a formal mandate and an engagement plan to guide their work with the sector.
The auditor-General noted that the services offered to councils are not well targeted and the councils are not aware of existing services.
The agency operates on an opt-in basis and has been criticized for not releasing the guidelines for the sector until December 19th of last year.
The auditor-General has recommended that the agency should create a comprehensive and accessible catalogue of services for agencies and councils, as well as develop an engagement strategy for the local government sector.
The auditor-General also criticized Cyber Security NSW for not auditing the self-assessments of state government agencies regarding their security maturity.


