Select Page

Audit: Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses | ABC News (Australia)

Audit: Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses | ABC News (Australia)

Australian Utility Audit Report November 11 2021

Queensland Audit Office (QAO) Water 2021 Report finds one breach and significant control weaknesses in the security of information systems.

Sunwater has acknowledge it was the organisation reported breached in the report.

Queensland Audit Office: Water 2021 Audit Report
Related: Queensland water supplier Sunwater targeted by hackers in months-long undetected cyber security breach
Reported in: Queensland water supplier Sunwater targeted by hackers in months-long undetected cyber security breach | ABC News (Australia)

Read more Queensland Audit Office Reports and more general Queensland Incidents

Six water authorities including Seqwater, Sunwater, Urban utilities, Unitywater, Gladstone Area Water Board and the Mount Isa Water board were examined in the report, which warned of vulnerability in information systems.

Deficiencies in internal controls including relating to funds transfer payment information, were also highlighted.

The 36-page report called for immediate action to fix “ongoing security weaknesses in information systems”.

The report said despite the audit office last year recommending that entities strengthen the security of their information systems, not all had acted to address the issue.

QAO Overview of internal control issues

The researchers observed that public entities have already implemented some security measures following the recommendations given last year, however, there are still security aspects that need to be covered. For instance, reporting systems and security threat detection should be implemented, every external system where the public has access should have MFA enabled, the minimum eight-character password length requirement should be applied.

The experts also noticed that there is a need for security awareness pieces of training and the implementation of processes that have the role to identify critical security vulnerabilities.

 


About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

OpenAI hacked Medicare portal, Prime Minister Anthony Albanese says

Prime Minister Anthony Albanese has revealed an AI agent hacked into an Australian Medicare data portal earlier this year. Speaking in New York, Mr … [...]

Quest Apartment Hotels tells customers to replace passports and licences after security breach

Quest Apartments has advised customers affected by a data breach in August to replace their passports and driver's licences after its investigation … [...]

Hacked? Qantas investigating WhatsApp phishing reports

The Flying Kangaroo and a Sydney hotel warn customers not to share payment details following suspicious messages targeting Qantas Hotels customers. • … [...]

Exclusive: Aussie not-for-profit Thorndale Foundation investigating Qilin breach claims

Hackers have targeted a local disability support organisation, with passports and confidentiality agreements already published on the dark web. • Mon, … [...]

Report: 44% of Australian cyber crime victims fail to report the incident

Nearly half of Australians who have experienced cyber crime did not report it, with researchers warning that serious offending is being missed by … [...]

Australia's security gap is a network problem

Networking and security teams are converging fast across APJ to meet a more complex threat landscape. Hear more at HPE Networking Day Sydney. For … [...]

Aussie mobile telcos face 'automatic' customer compensation for outages

Key points A senate committee reviewing outages that hit triple zero calls has recommended mandatory reliability and performance standards for telcos, … [...]

Hackers have published employee driver’s licenses, tax file numbers, and customer correspondence, with more data to come. • Fri, 18 Sep 2026 • Security … [...]

Australian government launches consultation period on the future of AI in the country

Canberra is looking for feedback on its approach to AI and its infrastructure in Australia, from data centre growth to consumer costs. • Fri, 18 Sep … [...]

Optus may ban smart glasses in stores, offices

Key points Optus is discussing cyber security policies that could regulate or even ban smart glasses in its stores and offices. • EGM security and risk … [...]

RentTech companies asking tenants for personal details ‘completely outside’ new Victorian laws

Some rental platforms encourage hopeful tenants to share ‘excessive’ amount of information, Consumer Policy Research Centre review finds [...]

Australia’s outdated technology is vulnerable to AI hacking attacks, signals chief says

Abigail Bradshaw says ‘enormous’ amounts of money required to update systems that people now expect to be constantly available [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading