WeekendTimes.com.au



Men's Weekly

.

Forgiveness or punishment? The government's proposed 'safe harbour' laws send mixed messages on cyber security

  • Written by Greg Austin, Adjunct Professor, Australia-China Relations Institute, University of Technology Sydney
Forgiveness or punishment? The government's proposed 'safe harbour' laws send mixed messages on cyber security

Should companies experiencing cyber attacks be forgiven if they cooperate with the government to stop such attacks? That’s the idea the federal government is considering with its possible “safe harbour” laws.

Last week, the defence minister, Richard Marles, floated the idea[1] of introducing a legally binding exemption from punitive government litigation if a company self-reports to the Australian Signals Directorate (the national signals intelligence agency) and invites its help.

The aim would be to drive more effective collaboration between the private sector and the directorate in dealing with cyber attacks, resolving them faster or preventing them altogether.

But the plan risks undermining the government’s attempts to crack down on corporations that don’t do enough to keep their clients’ data safe.

Read more: Major cyberattack on Australian ports suggests sabotage by a 'foreign state actor'[2]

Reluctance to work together

The government says it’s struggling[3] to overcome resistance by many Australian companies facing a cyber attack to work with the directorate to help defeat intrusions.

Companies are afraid to suffer the inevitable reputation loss if news of the breach leaks out.

They also fear exposing themselves to government fines or customer litigation of the sort being pursued[4] by victims of data breaches at Medibank and Optus.

On the government side, the Australian Signals Directorate has complained[5] their efforts to help companies under attack are being hampered by lawyers concerned mostly with minimising the risk of the company being sued in the future.

This is in direct contrast to the practice of leading US tech companies[6] who prefer lawyers to be the first people involved in the response.

A woman in a bright print blazer sits and looks to an audience
Director-General of the Australian Signals Directorate, Rachel Noble, sees value in safe harbour laws. Bianca De Marchi/AAP

A so-called ‘safe harbour’

The government’s safe harbour offer would involve legislation.

The safe harbour principle is an exemption that can be granted for actions that might otherwise break the law if there’s a larger public good at play.

This is used in other areas of regulation, such as bankruptcy law[7] and tax law.[8] It provides legal protections for administrators or accountants who have to take on risky business decisions in order to do their jobs.

Richard Marles claimed a safe harbour regime for self-reporting companies affected by a cyber attack would do two main things.

Firstly, he said, it would deliver the world-class capabilities of the Australian Signals Directorate to the affected company.

Secondly, Marles said it would help drive trust between the government and reticent private sector businesses.

Read more: The $500 million ATO fraud highlights flaws in the myGov ID system. Here's how to keep your data safe[9]

The government has proposed that complying with the cyber safe harbour requirements would shield companies from further legal action by the government.

In its cyber security strategy, released today[10], the government committed to consultations with industry on a legislated measure to help build the sort of trust outlined in Marles’ discussion of safe harbour.

But we don’t have any other detail about how this version of safe harbour law would work.

And for most corporations, the government may be the least of their worries in cases of large-scale data breaches or breaches of sensitive intellectual property information.

They will be concerned about the reputational damage first and foremost.

For listed companies, this can lead to a sustained drop in share price and open a pathway to costly law suits from seriously affected clients or business partners.

Safe harbour laws don’t do much to help with that.

Would laws like this work?

In cyber security, the concept of safe harbour is complicated and fraught with definitional and regulatory challenges[11].

Such laws for cyber security are used in several US states[12] mainly for promoting stronger compliance with industry standards. This is done by promising companies a degree of protection from various types of litigation if they are certified by the government to be reasonably compliant with the standards.

An Australian study[13] throws some doubt on the value of that process.

The research shows such standards are seen as a low bar, or even inappropriate in some situations.

Technology always moves more quickly than standards. For example, in May 2023 an intergovernmental working group found[14] the security standards for 5G were “incomplete” and did not cover all security requirements. Australia has been using 5G technology since 2019.The safe harbour laws may also be too weak to achieve what they set out to do.

A US study[15] warns a safe harbour law for the US health sector “only offers some protection in certain circumstances”.

Read more: A cancer centre is the latest victim of cyber attacks. Why health data hacks keep happening[16]

Forgiveness or punishment?

The new Australian proposal, coming from the defence department in 2023, and raised in Senate Estimates in 2022[17] by an opposition senator, appears to support the defence portfolio’s interest in better national security.

But there is a reasonable risk it will undermine the mission of the home affairs minister, Clare O’Neil.

She has staked much on the need to punish corporations who may have acted irresponsibly in allowing serious data breaches.

A blonde woman in a white blazer addresses a media conference Home affairs minister Clare O'Neil has pushed hard for tougher penalties for companies that don’t protect themselves against data breaches. James Ross/AAP

Corporations will remember her statement[18] in September 2022 that fines of hundreds of millions of dollars for large privacy breaches might be more appropriate than the existing cap of $2.2 million.

By December, new legislation imposing penalties up to $50 million had come into force.[19]

The moves were designed in part to dampen community outrage over the data breaches.

But the safe harbour idea might increase the consumer concerns O'Neil has been working to allay.

Not all cyber attacks involve a risk of exposing large amounts of personal data, so there would be instances where the safe harbour option would not affect a person’s rights to seek redress.

But by its very nature, the proposal will impact the rights of businesses and consumers to know if they have suffered damage or loss from a cyber attack.

The government has a moral obligation[20] to inform victims of cyber crime.

At a time of escalating cyber uncertainties, increasing ransomware attacks[21], and stepped up Russian and Chinese cyber attacks, the safe harbour proposal will need careful consideration.

The government will want to avoid antagonising public sentiment by limiting the rights of consumers.

So a solution that promises protection only against government litigation, but not civil litigation, may not be worth the political balancing act.

References

  1. ^ floated the idea (www.minister.defence.gov.au)
  2. ^ Major cyberattack on Australian ports suggests sabotage by a 'foreign state actor' (theconversation.com)
  3. ^ it’s struggling (www.minister.defence.gov.au)
  4. ^ the sort being pursued (www.allens.com.au)
  5. ^ has complained (www.afr.com)
  6. ^ US tech companies (www.keystonelaw.com)
  7. ^ bankruptcy law (www.hallchadwick.com.au)
  8. ^ tax law. (www.tpb.gov.au)
  9. ^ The $500 million ATO fraud highlights flaws in the myGov ID system. Here's how to keep your data safe (theconversation.com)
  10. ^ released today (www.abc.net.au)
  11. ^ definitional and regulatory challenges (www.reliasmedia.com)
  12. ^ in several US states (www.tenfold-security.com)
  13. ^ An Australian study (about.unimelb.edu.au)
  14. ^ an intergovernmental working group found (www.business-standard.com)
  15. ^ A US study (www.reliasmedia.com)
  16. ^ A cancer centre is the latest victim of cyber attacks. Why health data hacks keep happening (theconversation.com)
  17. ^ raised in Senate Estimates in 2022 (www.innovationaus.com)
  18. ^ her statement (www.theguardian.com)
  19. ^ had come into force. (www.ashurst.com)
  20. ^ moral obligation (theconversation.com)
  21. ^ increasing ransomware attacks (www.cyber.gov.au)

Authors: Greg Austin, Adjunct Professor, Australia-China Relations Institute, University of Technology Sydney

Read more https://theconversation.com/forgiveness-or-punishment-the-governments-proposed-safe-harbour-laws-send-mixed-messages-on-cyber-security-218025

The Weekend Times Magazine

The Psychology of Your Floor Plan: How Layout Shapes the Way You Live

When most people think about designing a new home, they focus on finishes, colours, or even the kitchen benchtop. But the quiet hero of liveability is the floor plan. A...

Does Sydney Australia Have a Good Nightlife Scene?

In the last several years, Sydney's nightlife has changed dramatically. The New South Wales state government adopted Draconian lockout regulations in 2014, forcing city center venues to close their doors...

A Fantastic Trip To Melbourne, Australia With Minimal Spending? Here’s How?

Famed for the iconic Melbourne cup horse race, Melbourne, Australia ranks as one of the best travel destinations worldwide. It offers tourists an escape from the hustle and bustle of...

Experienced Accident Lawyers Brisbane and Accident Compensation Claims

When a serious accident disrupts your life it can feel like everything changes overnight. Injuries often mean hospital visits ongoing medical treatment and weeks or even months off work. On...

How Custom Made Inflatables Can Turn Your Backyard into a Kids' Wonderland

If you're planning an event for your kids at home, transforming your backyard into a magical wonderland is easier than you think. Custom made inflatables offer a versatile and fun...

A Modern Approach to Superannuation: SMSF Setup Online

For Australians seeking greater control over their retirement savings, self-managed superannuation funds (SMSFs) remain an attractive option. Today, advances in digital platforms have streamlined the process, making SMSF setup online faster...

Meet Untamed Natural Beauty! Breathtaking Journeys Await You in Komodo Island

Designed by Freepik Komodo Island, part of Indonesia’s Komodo National Park, offers a truly remarkable escape into nature. Known for its rugged beauty, pristine beaches, crystal-clear waters, and unique wildlife, it...

A Complete Guide to Hiring Shipping Containers

Shipping containers are used for transferring various types of products over long distances, usually from one country to another. They are also used as storage containers. But people who hire...

Box Mixers launches at home cocktail mixers

Box Mixers has announced its new range of zero alcohol cocktail mixers, made from all natural flavours, crafted to make drinking cocktails at home simple and convenient. Designed to appeal to...

hacklink hack forum hacklink film izle hacklink หวยออนไลน์jojobetPusulabetสล็อตเว็บตรงgamdom girişpadişahbetMostbetcarros usadoskn777pradabetcocktail glassessahabetpusulabet girişcasibomjojobet girişultrabetbetofficeBets10jojobetholiganbet色情 film izlecasibomYakabet1xbet girişjojobetGrandpashabetgobahiskingroyaljojobetultrabet girişmatadorbetbets10palacebetmamibetselçuksportscasibommadridbetbetciougwin288sekabetjojobetcasibomJojobetmeritkingcasibomcasibom girişdeneme bonusucryptobetSekabetCasibomcasibom girişsekabetDinamobetparmabetVdcasinobetpuanMarsbahisultrabet girişpaşacasinoselçuksportspaşacasinokingroyalmavibetçanakkale tırnakkalebetrinabetsahabetmr pachocasibomcasibomvbetsahabetmeritbet girişkralbet girişultrabet girişultrabet girişcasibomdeneme bonusu veren sitelermeritbetonwintimebetantalya escortgrandbettinggrandbettingqueenbetqueenbetbahiscasinobahiscasinoultrabetbets10matbet girişnorabahisKayseri Escortjojobet girişbettiltcasibom girişCasibomaviator gamebahislioncasibomcasibomcrown155 casinohb88aussuper96 loginholiganbetpadişahbet주소모음 주소모아spin2u loginneoaus96 casino loginCasibomStreameastholiganbetmarsbahismatbetbets10 girişff29 casinobets10best e-wallet pokies 2025holiganbetmatbetsahabetNo Deposit Bonus Casinos 2025casibomcasibom