Viw Magazine

Business Coach

.

  • Written by Greg Austin, Professor, Australian Centre for Cyber Security, UNSW
The Australian National University has been working with intelligence agencies to minimise the impact of a cyber attack on its systems. Mark爱生活/Flickr, CC BY-NC-ND

The cyber security practices of Australian universities are in the spotlight after the Australian National University (ANU) reported last week it had been the target of a serious attack. Hackers – reportedly based in China – infiltrated ANU’s networks some time last year and have proven difficult to remove.

According to the Australian Cyber Security Centre’s 2017 Threat Report:

Targeting of the networks of Australian universities continues to increase. Universities are an attractive target given their research across a range of fields and the intellectual property this research is likely to generate.

Anecdotal information suggests university performance in cyber security is quite weak. The problem is not widely studied by scholars. But there are things they can do to improve.

It’s important that they do because university networks hold important intellectual property data; sensitive political, business, and social data from background interviews and surveys; and valuable personal information about students who go on to become political, business and national security leaders.


Read more: Is counter-attack justified against a state-sponsored cyber attack? It's a legal grey area


This is a global problem

Cyber attacks targeting universities aren’t limited to Australia.

Chinese universities were among the major victims of a global ransomware attack involving the Wannacry malware in 2017. The attack, which locked up user files and demanded a ransom, came just on the eve of submission of final theses for the academic year in Chinese universities. Social media reporting suggests the disruption was serious.

Indeed, universities figure rather prominently as victims of cyber attacks in China. In 2016, according to a Chinese study, the country’s universities accounted for the highest proportion (40%) of targets of the most serious form of threat.

Known as Advanced Persistent Threat (APT), this form of attack is usually associated with government intelligence or military agencies. My own work suggests that in general the institutions targeted had bad security practices – either by not installing software updates on the day of issue or by using pirated software.

Better reporting is required

So how good are Australian universities at cyber security?

There is scant public evidence assessing the cyber security practices of Australian universities so it’s hard to say. According to a senior official of a small regional university who I spoke to last month, his institution simply has not been equipped, staffed or funded in the past to engage with the challenge.

What about the country’s top universities?

To answer this, some consistent and public reporting on security incidents would be required. If we had information on the size of security staffs, the type of outsourced security arrangements, and the total annual budget for cyber security in our universities we could make a reasonable judgement. These types of data are difficult to find, but we can make judgements in other ways.

First and most simply, do universities utilise two-factor authentication? Do they prohibit staff and visitors from bringing their own devices and USBs? Most Australian universities probably fail these two basic tests.


Read more: How suppliers of everyday devices make you vulnerable to cyber attack – and what to do about it


Second, since most Australian universities don’t insist on mandatory training in simple security measures, such as how to avoid “phishing” emails that carry malware, we can assume serious vulnerabilities exist.

In 2018, the University of New England released a comprehensive three-year information security plan. It is an impressive assessment of the threats, risks and challenges for the university – and it updated a previous plan for 2015-17. The scale of the challenge is well captured by one sentence in its executive summary:

…yesterday’s security defenses are not effective against today’s rapidly evolving threats.

Not all Australian universities have such an easily accessible and comprehensive plan.

What is to be done?

Mature organisations in the corporate world do not leave cyber security management in the hands of the information technology managers. Rather they place responsibility in the department of risk management, directly under the CEO or Board of Directors. One reason is that cyber security is a socio-technical problem, not just a technology problem.

There is an additional option uniquely available to universities: to ensure that those who manage security of networks and data work closely with those who research and study the same problem.

This happens in Oxford University, where the academic staff in the field are seen as part of the solution. Oxford convenes a monthly meeting of its Information Security Special Interest Group (SIG) and its members help manage the university’s annual baseline cyber security assessment.


Read more: Deterring cyber attacks: old problems, new solutions


Oxford also has its own Computer Emergency Response Team (CERT), a type of organisation used globally, though often only at the national level, to manage certain aspects of cyber security. The CERT is developing the university’s own security analytics platform (SAVANT).

In December, the Canadian universities and colleges association issued a workshop report on what their member institutions needed to do to address this problem. It advocated, among many other steps, a national university-based cyber security network.

Participation in a shared Australian network of this kind will be the only solution available to Australia’s smaller universities with low security capability, but also an essential component of the cyber security work for our largest.

Greg Austin does not work for, consult, own shares in or receive funding from any company or organisation that would benefit from this article, and has disclosed no relevant affiliations beyond their academic appointment.

Authors: Greg Austin, Professor, Australian Centre for Cyber Security, UNSW

Read more http://theconversation.com/how-australian-universities-can-get-better-at-cyber-security-99587

Revolutionizing Manufacturing: Unleashing the Full Potential of Stereolithography SLA 3D Printing

3D printing is changing how we make things, and Stereolithography (SLA) 3D printing is at the center of this change. Making models or prot...

Impact of Early Intervention on Hearing-Impaired Children

Early intervention plays a crucial role in shaping the lives of children with hearing impairments, providing them with the necessary suppo...

The Role of a Mortgage Broker in Handling Your Reverse Mortgage

Choosing the right reverse mortgage can be a daunting task, especially given the multitude of options and complex terms involved. A mortga...

Showcasing Craftsmanship in Sydney's Furniture Outlets

Seeking an appropriate furnishing is the first step towards accomplishing perfect interior layout in Sydney, a colourful city where styl...

Blue Stars FX Review – The Benefits of Using an Advanced Online Brokerage Firm

If you are a seasoned trader in the dynamic world of crypto trading, then you understand that it is crucial to have a trading platform by ...

Maxon365 Review - (maxon365.com) Is Maxon 365 Scam or a Proper Broker?

The crypto trading arena is considered to be highly volatile and unpredictable. Hence, to keep up with the changing dynamics of the market...

Scrap Copper Secrets: Unlocking Melbourne's Pricing Patterns

In the heart of Melbourne's bustling urban landscape lies a hidden world of scrap metal, where discarded treasures await their chance at r...

Setting Up The Home Game Room Of Your Dreams

Everybody likes to play games, for some, it's a pleasant occasional pass time, for some, it's a regular good-natured competition with frie...

What is the best Ethernet Cable to satisfy your networking needs?

Whether you are a seasoned IT professional or a novice enthusiast, understanding something about ethernet cables can significantly impact ...

The Top 10 Reasons to Purchase a Makeup Mirror

Investing in a quality makeup mirror is a game-changer for anyone who applies makeup, grooms, or simply wants a better view when taking ca...

Understanding TPD Claims: Navigating the Process and Securing Your Entitlements

Total and Permanent Disability (TPD) claims serve as a vital resource for individuals facing significant injuries or illnesses that hinder...

Brisbane Personal Injury Lawyers: Advocates for Your Rights and Compensation

When you've suffered a personal injury in Brisbane, navigating the legal landscape can be daunting. That's where Brisbane personal injury ...

How Does Salary Sacrificing Save Money?

By strategically sacrificing salary, you save money through tax benefits and boosted take-home pay. Lower taxable income means less tax ...

Tips for Reducing Mould in Your Caravan

To prevent mould in your caravan, ensure good ventilation by opening windows and using fans. Keep airflow constant, especially when cookin...

Navigating the Aftermath: What to Do When You're in a Car Accident

Car accidents can be unsettling and chaotic experiences, often leaving individuals overwhelmed and unsure of what steps to take next. Howe...

Smart Mirrors: Revolutionizing Your Morning Routine with High-Tech Features

In today’s fast-paced world, technology seamlessly integrates into every aspect of our daily lives, aiming to enhance convenience and ef...

Brisbane to Face Another Gribbly Winter

Queensland has experienced another wet, hot summer, and in Brisbane, this means populations of pest species will be booming. For many pest...

Common Household Electrical Problems

Ever had a rough day just because you had an electrical problem at your residential property?  Imagine a fine morning, when you are read...

Important Instructions for Australians Living in Camper Trailers

Living in a camper trailer offers Australians a unique way to embrace adventure and freedom while exploring the vast and beautiful landsca...

Maintaining Your Mini Digger: Tips for Longevity and Performance

If you're a proud owner or operator of a mini digger in Australia, you understand the importance of keeping your equipment in top-notch co...

Tomorrow Business Growth