02/08/2023
PRACTICAL STEPS TO REDUCE CYBERSECURITY RISKS FOR BUSINESSES
1. Review current cybersecurity policies and procedures to ascertain any weaknesses.
2. Consider potential cybersecurity risks facing your business, including:
(a) What kind of data is handled by the business
(b) What damages could arise from unauthorised use of, or loss of, that data
(c) How your products and services, supply chain and/or operations could be affected by the unauthorised use of, or loss of, that data.
3. Consider your work practices and procedures, including:
(a) Your IT environment
(b) Your service providers for customer service relationship management
(c) Your software
(d) Your hardware
(e) Your remote working practices
(d) Any outsourced cloud-based service providers
4. Consider your staff, their awareness of cybersecurity, resources available to them and implement regular training events for them, including refresher courses
5. Give particular thought to the level of knowledge and expertise of your management team and senior staff as well as their ability to effectively identify, respond and manage cybersecurity risks that may face your business and whether additional training or resources are required specifically for them
6. Consider the size of your business, resources available, specific risks in your business sector, your customer base, the data you handle and common practices in your sector to ascertain your ideal cybersecurity best practice
7. Assess how regularly management and/or senior staff discuss cybersecurity risks and ensure that regular discussions are held to address any concerns and/or new potential risks are identified
8. Consider involving experts in IT to assist you and your business - in ASIC v RI Advice, at [55] the Court acknowledged that “cyber risk management is a highly technical area of expertise”. An assessment of “adequate” protections for a particular business should involve experts.
The above steps will assist any business in fulfilling its obligations as well as ensure that it is better prepared for the every day cybersecurity threats it faces.
Ambry Legal specialises in taxation, GST and business law.