iTnews
  • Home
  • News
  • Digital Nation
  • Governance
Digital Nation

Australian organisations report $33b loss from cybercrime

By Staff Writers
Jan 10 2022 1:39PM
Follow google news

Organisational cybersecurity culture is critical to success

Australian organisations reported losses of more than $33 billion from cybercrime over the 2020-21 financial year, according to the Australian Cyber Security Centre (ACSC).

Consumer crediting reporting agency Equifax recently released a report based on a panel of cybersecurity experts from the business community to discuss the growing threat of cybercrime in Australia.

Australian organisations report $33b loss from cybercrime

Equifax is no stranger to cybercrime, in 2017, the company was the victim of a cyber attack where 143 million customers had personal information leaked. The company spent US$1.5 billion over the following two years building up its cybersecurity.

  • Subscribe to Digital Nation Australia's twice-weekly newsletter

The panel was moderated by James Turner, Founder, CISO Lens and featured Wayne Williamson, Chief Information and Security Officer (CISO), Equifax Australia & New Zealand; Jamil Farshchi, CISO, Equifax Group/Global; John Yates, Director of Security, Scentre Group; and Catherine Buhler, CISO, Energy Australia.

As Australia continues to see increasingly sophisticated cybercrime threats, Equifax’s newly released whitepaper highlights that organisations must also evolve their security culture and adapt reporting structures and levels of preparedness to prevent cybercrime-related losses.

Equifax's Williamson says cybersecurity preparedness is ever-evolving, and the responsibility lies with the entire organisation, not just CISOs, to address cyber risks head-on.

“Common themes emerged from our conversations with security leaders at the top of their field: namely, involving a business’ security culture driven from the top and conducting threat assessments on people and technology remain core principles to managing these risks.”

The Equifax report identified several common elements that help drive a change in the cybersecurity culture, which were armoury, remuneration and embedded culture.

Armoury

To win against cybercrime, employees must be trained. The panellists say training must do more than just tell staff what to do, it should be training that effectively changes behaviour.

“At Equifax, every employee gets security training with a monthly benchmarking scorecard that measures their security behaviours and compares that to averages across their peers and the organisations they’re working with.

The combination of training, remuneration incentives and tech-enabled communication against KPIs means all staff members – across Equifax’s global operations – feel accountable for cybersecurity.

Organisations that seek to drive cultural change using the measures outlined above
will move the cybersecurity dial. But real success comes from a holistic approach to
the risk.

Jamil Farshchi says, “It’s not just the cybersecurity scorecard. It’s not just the bonus. It’s not just the reporting lines. It’s not just the board exposure. But when you bring them together, and you work at it together, it really does make a big difference.”

Remuneration

One other key tool in driving a cultural shift is reporting lines. At retail property giant Scentre Group,  for instance, John Yates reports directly to the CEO. A 2021 CISO Lens report suggests that the number of CISOs reporting directly to the CEO was around 3 per cent in 2020 – but increased rapidly to 8 per cent this year.

Reporting lines alone however don’t guarantee cultural change, according to the whitepapet. John Yates says it highlights the seriousness with which security is treated at an organisation.

Yates says, “At Scentre Group, we’ve come on a very fast journey in terms of cyber over the last five years. We now have a pretty mature outlook really led by the CEO.

“We drive a very lean business model. Everything you do, you’ve got to make a case for it. We have a very sensible board. They see that an existential threat is emerging, and they know responsible boards should be delivering a proportionate response to that threat.”

Embedded Culture

While cybersecurity may only be the role for a handful of employees, it is up to the whole organisation to instil it.

In Australia, there has been a dramatic increase in the number of CISOs brought on board by businesses, according to the panel.

Williamson says, “Companies need to ensure that the CISO doesn’t fight the battle alone. If you’ve set up your program in such a way that the CISOs are the arbiters of all things good, then you haven’t done it right.

“You want a cybersecurity mindset built into the DNA of the company at large, and one that can be carried by the masses versus just one individual,” he ends.

 

Got a news tip for our journalists? Share it with us anonymously here.
Digital Nation

You just read a Digital Nation story.

There are many others like it. Subscribe to our new weekly Digital Nation e-newsletter for more HR, finance, marketing, risk and emerging technology news and discussions.

SUBSCRIBE
© Digital Nation
Tags:
cybercrimecybersecurityequinoxgovernance

Related Articles

  • Fair Work Commission bogged down by AI filings Fair Work Commission bogged down by AI filings
  • CBA sets up dedicated AI risk committee for governance CBA sets up dedicated AI risk committee for governance
  • NSW gov to make AI risk assessments less "subjective" NSW gov to make AI risk assessments less "subjective"
  • Audit Office of NSW and Data61 explore AI for gov auditing Audit Office of NSW and Data61 explore AI for gov auditing
Join our WhatsApp Channel

Partner Content

AI Goals for 2026: What Every Organisation Should Prioritise
Promoted Content AI Goals for 2026: What Every Organisation Should Prioritise
Local Technology Infrastructure Is Key to Australia’s Artificial Intelligence-Enabled Future
Promoted Content Local Technology Infrastructure Is Key to Australia’s Artificial Intelligence-Enabled Future
From hype to value: The AI trends set to shape 2026
Partner Content From hype to value: The AI trends set to shape 2026
Beyond Compliance: How Australia's Aged Care Reforms Create an Innovation Imperative
Partner Content Beyond Compliance: How Australia's Aged Care Reforms Create an Innovation Imperative

Sponsored Whitepapers

Uncomplicate IT Service Delivery with AI Agents
Uncomplicate IT Service Delivery with AI Agents
Getting ahead of the tech: what’s next for Australian organisations in digital transformation
Getting ahead of the tech: what’s next for Australian organisations in digital transformation
Fintech compliance made fast and secure
Fintech compliance made fast and secure
How to evaluate SIEM solutions Safeguarding your future Get a demo Download guide
How to evaluate SIEM solutions Safeguarding your future Get a demo Download guide
2025 Security operations insights: Three-quarters of security leaders need something new in SIEM
2025 Security operations insights: Three-quarters of security leaders need something new in SIEM

Events

  • iTnews Executive Retreat - Security Leaders Edition iTnews Executive Retreat - Security Leaders Edition
  • iTnews Cloud Covered Breakfast Summit iTnews Cloud Covered Breakfast Summit
  • The 2026 iAwards The 2026 iAwards
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Fair Work Commission bogged down by AI filings

Fair Work Commission bogged down by AI filings

CBA sets up dedicated AI risk committee for governance

CBA sets up dedicated AI risk committee for governance

In a post-digital era, governments should continue investing in tech: Gartner

In a post-digital era, governments should continue investing in tech: Gartner

NSW gov to make AI risk assessments less "subjective"

NSW gov to make AI risk assessments less "subjective"

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.