Select Page

Audit: Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses | ABC News (Australia)

Audit: Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses | ABC News (Australia)

Australian Utility Audit Report November 11 2021

Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses in the security of information systems.

Sunwater has acknowledge it was the organisation reported breached in the report.

Queensland Audit Office: Water 2021 Audit Report
Related: Queensland water supplier Sunwater targeted by hackers in months-long undetected cyber security breach
Reported in: Queensland water supplier Sunwater targeted by hackers in months-long undetected cyber security breach | ABC News (Australia)

Read more Queensland Audit Office Reports and more general Queensland Incidents

Six water authorities including Seqwater, Sunwater, Urban utilities, Unitywater, Gladstone Area Water Board and the Mount Isa Water board were examined in the report, which warned of vulnerability in information systems.

Deficiencies in internal controls including relating to funds transfer payment information, were also highlighted.

The 36-page report called for immediate action to fix “ongoing security weaknesses in information systems”.

The report said despite the audit office last year recommending that entities strengthen the security of their information systems, not all had acted to address the issue.

QAO Overview of internal control issues

The researchers observed that public entities have already implemented some security measures following the recommendations given last year, however, there are still security aspects that need to be covered. For instance, reporting systems and security threat detection should be implemented, every external system where the public has access should have MFA enabled, the minimum eight-character password length requirement should be applied.

The experts also noticed that there is a need for security awareness pieces of training and the implementation of processes that have the role to identify critical security vulnerabilities.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Exclusive: Champion Homes confirms customer data compromised in ‘cyber event’

A Sydney-based home builder will contact impacted customers following the DragonForce ransomware attack. • Tue, 05 May 2026 • Security *]:clear-none … [...]

WA rental scam surge: Tenants targeted with fake $500 discount trap

Western Australia’s tight rental market has seen a rise in scams targeting tenants, putting more people at risk, with the state’s peak body urging … [...]

NSW Treasury cyber incident contained, impact no longer ‘significant’

The NSW government has lowered its classification of the alleged cyber attack on the state Treasury from last month. • Tue, 05 May 2026 • … [...]

Australia, Japan commit to partnership to meet cyber security challenges and strengthen cyber defences

Australia and Japan have agreed to establish a new partnership that will enable deeper cooperation on complex cyber security challenges. Robert … [...]

Australian Cyber Aware - As It Was 2604 - April 2026

This monthly review provides a curated summary of Australian and New Zealand cyber, privacy, and information security developments identified during … [...]

Australian government establishes new Cyber Incident Review Board

The seven-member board will conduct post-incident reviews of “significant cyber security incidents in Australia”. • Mon, 04 May 2026 • … [...]

Exclusive: Major Australian jewellery brand confirms cyber incident

Threat actors have claimed a cyber attack on an Australian fine jewellery retailer, claiming to have stolen over half a terabyte of data. • Mon, 04 … [...]

Unregistered branded text messages to be labelled ‘unverified’ from 1 July

The ACMA is urging Australian businesses to register now, ahead of new anti-scam rules coming into effect later this year. • Mon, 04 May 2026 • … [...]

NSW gov downgrades impact of alleged Treasury data breach

The impact of an alleged data breach at NSW Treasury has been “downgraded” after the incident response investigation found that “no project has been … [...]

Exclusive: Kiwi electrical contractor confirms cyber attack

Whangarei-based firm McKay confirms unauthorised access to a single device following ransomware claims by the Mnt6 hacking group. • Mon, 04 May 2026 • … [...]

University of Queensland aligns resilience approach across operations

The University of Queensland has bolstered its resilience to a range of incident types and threats with a coordinated and documented approach, … [...]

Exclusive: Prime Properties listed as breach victim by M3rx ransomware

Hackers are alleged to have stolen more than 80,000 documents totalling 100 gigabytes of data from a Sydney-based property investment firm. • Fri, 01 … [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading