The government did take some action, but the moves were modest and there was no headline initiative that might provide timely reassurance to that it was outraged and on the warpath against all hackers.
However it did announce that the Australian Information Commissioner will receive a $5.5m funding boost over two years to investigate and respond to the Optus data breach. The new spending, comprised of $3m in this financial year and $2.5m in 2023-24, will be specifically used to probe this month’s breach, which has affected millions and engulfed one of the nation’s largest telecommunications companies.
There were only a scattering of other cyber initiatives, including $31.3m to extend the cyber hubs pilot to improve the cyber defences of government agencies. Then there was another $2m — hardly a robust investment — to help scam victims recover their identities as “part of fulfilling the government’s election commitment to combat scams and online frauds”.
Labor is still formulating its cyber security policy and has vowed to reset the Morrison’s government $1.7b, 10-year strategy so we weren’t expecting screaming headlines on cyber security in this budget. But the job of government is to reassure people it’s taking the growing threat of cyber security deadly seriously, and a budget that is bereft of any significant new initiative in this space — when the community is reeling from the Optus and Medibank hacks — was poorly timed.
Labor is planning to recast its cyber security strategy to boost sovereign capability and build a frontline cyber workforce to combat escalating threats from malicious state-based actors and criminal gangs. It will also focus on building closer links with Quad partners the US, Japan and India to accelerate the shift from relying on China for critical technologies.
Much of the government’s anger in the Optus and Medibank hacks was directed at the companies themselves, with Anthony Albanese saying they were “a huge wake-up call’ for the corporate sector. Companies like Optus who suffer large-scale privacy breaches could be fined $50m under new laws proposed by the federal government.
For those customers of Optus or Medibank Private who have had their personal details stolen by hackers, there wasn’t a lot of reassurance to be found in this budget on cyber security.