Select Page

Audit: Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses | ABC News (Australia)

Audit: Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses | ABC News (Australia)

Australian Utility Audit Report November 11 2021

Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses in the security of information systems.

Sunwater has acknowledge it was the organisation reported breached in the report.

Queensland Audit Office: Water 2021 Audit Report
Related: Queensland water supplier Sunwater targeted by hackers in months-long undetected cyber security breach
Reported in: Queensland water supplier Sunwater targeted by hackers in months-long undetected cyber security breach | ABC News (Australia)

Read more Queensland Audit Office Reports and more general Queensland Incidents

Six water authorities including Seqwater, Sunwater, Urban utilities, Unitywater, Gladstone Area Water Board and the Mount Isa Water board were examined in the report, which warned of vulnerability in information systems.

Deficiencies in internal controls including relating to funds transfer payment information, were also highlighted.

The 36-page report called for immediate action to fix “ongoing security weaknesses in information systems”.

The report said despite the audit office last year recommending that entities strengthen the security of their information systems, not all had acted to address the issue.

QAO Overview of internal control issues

The researchers observed that public entities have already implemented some security measures following the recommendations given last year, however, there are still security aspects that need to be covered. For instance, reporting systems and security threat detection should be implemented, every external system where the public has access should have MFA enabled, the minimum eight-character password length requirement should be applied.

The experts also noticed that there is a need for security awareness pieces of training and the implementation of processes that have the role to identify critical security vulnerabilities.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Origin Energy blackmailed over massive data breach | 7NEWS

Origin Energy, Australia's biggest power provider, is investigating a suspected cyber attack affecting up to 5 million Australians. A hacker calling himself John Doe claims to have stolen personal data [...]

Australia's second biggest energy provider is investigating a potential hack | The Business

Origin Energy says an investigation has been launched into a potential hacking incident with reports two million customers could have been affected. The company has 4.8 million customers. The nation's [...]

Origin Energy investigating 'potential' customer data breach

One of Australia's largest energy companies, Origin Energy, says it is investigating a security breach that "may have" affected customer data. "Origin … [...]

‘A matter of urgency’: Major energy retailer Origin hit by suspected hack

Origin Energy is investigating a potential cyber hack that may have compromised the data of some customers. In a statement, the major energy provider … [...]

Exclusive: NSW accounting and advisory firm allegedly hit by SafePay ransomware

Threat actors have claimed a cyber attack on an NSW-based accounting and advisory firm and are threatening to leak allegedly stolen data in just a … [...]

Reynella East College updates parents, carers following June data breach

Parents were told a court order has been issued “prohibiting the publication, disclosure, transmission, use, or further dissemination of data … [...]

GO2 Health medical clinic in Brisbane waited almost three months to alert patients it was hacked

Another medical clinic has revealed it has been targeted by hackers, less than a week after Partnered Health announced a major data breach. GO2 Health … [...]

Businesses hit with almost $1 billion in fines amid record-setting watchdog crackdown

Australians have got $644 million back from major banks and financial companies as the industry watchdog cracks down on failures. The Australian … [...]

Federal government to tighten rules around use of AI in departmental decision-making

Australia will tighten oversight of artificial intelligence in automated government decision-making and strengthen privacy safeguards as part of a … [...]

Feds move to regulate automated decision-making

The federal government will move to tighten regulation of automated decision making (ADM) as a result of a new set of safety priorities for adoption … [...]

Vic Labor moots workplace AI and biometrics surveillance curbs

Victoria's Labor government is looking to restrict the use of AI and biometrics for workplace surveillance under proposed laws. Premier Jacinta Allan … [...]

Nationwide AusAlert Test is coming

Published on 17 July 2026 The Australian Government is launching AusAlert, a new national warning system that can send emergency messages to … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading