The Australian federal government is set to conduct regular exercises to test the cybersecurity of organisations covered by the Security of Critical Infrastructure Act (SOCI). The announcement was made by Minister for Home Affairs and Cyber Security, Clare O’Neil, during a speech to the Australian Strategic Policy Institute in Sydney. The exercises will be sectoral and cross-sectoral, and led by the National Cyber Coordinator, aiming to build “muscle memory” in dealing with cyber attacks. O’Neil cited the potential impact of a single critical infrastructure attack on millions of Australians. The exercises will include scenarios not yet experienced on a national scale, such as critical data integrity attacks or a lock-up of critical infrastructure. The exercises will be launched as soon as possible, with O’Neil stressing the urgency of the matter.
The government is also planning to refresh the national strategy for identity resilience in collaboration with state and territory governments. This will include the work being led by Finance Minister Katy Gallagher on the national digital ID system, which aims to streamline transactions and reduce the need for companies to hold personal data. O’Neil emphasised the importance of protecting personal data and making Australian identities difficult to steal and easy to restore if compromised.
Overall, these measures aim to improve Australia’s cyber resilience in the face of increasing cyber threats. The government’s proactive approach to testing cybersecurity and identity resilience demonstrates its commitment to protecting critical infrastructure and personal data. The exercises will help organisations covered by SOCI to prepare for potential cyber attacks and enhance their cybersecurity posture. The refresh of the national strategy for identity resilience will also help to ensure that personal data is adequately protected, reducing the risk of identity theft and other cybercrime.


