Australian Kaspersky ban triggered by detection in gov agency supply chain

By
Follow google news

Software also found in states, critical infrastructure.

A formal ban on the use of Kaspersky Lab software by the federal government last month was triggered by “a detection of its use in the supply chain of one government agency”, according to Home Affairs officials.

Australian Kaspersky ban triggered by detection in gov agency supply chain

Speaking at a budget estimates hearing late last week, officials said that agencies had been first directed not to use Kaspersky back in 2017 via a letter from Prime Minister and Cabinet.

“The letter effectively said for non-corporate Commonwealth entities to not use Kaspersky products,” Home Affairs deputy secretary of cyber and infrastructure security group Hamish Hansford said.

The detection of Kaspersky in the single government agency’s supply chain prompted a fresh email to chief security officers across government from Hansford, followed up by a “formal direction” in February this year.

It was noted that the power to issue a formal direction has only existed since 2023.

Assistant secretary of government cyber and protective security Tim Neal said that a “survey” of government entities conducted in “late 2024” also uncovered a “potential procurement” at the federal level contemplating Kaspersky software.

In addition, the survey - which requested federal, state and territory governments and critical infrastructure operators “to scan their environments and their policies around Kaspersky Lab” - found instances of the software in use outside of the federal sphere as well.

“There were multiple instances across the three [surveyed] cohorts, which [included] the Commonwealth government, the states and territories, and critical infrastructure,” Neal said.

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Poor WA gov M365 security led to $71k theft and children's data breached

Poor WA gov M365 security led to $71k theft and children's data breached

US medical device maker Stryker's Microsoft environment attacked

US medical device maker Stryker's Microsoft environment attacked

CBA chief impersonated in global investment fraud on Facebook

CBA chief impersonated in global investment fraud on Facebook

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Log In

  |  Forgot your password?