Tag: Cyber security

  • Submission to the Inquiry into cyber security for small to medium sized businesses and organisations

    Australian small and medium businesses (SMBs) are widely seen as more vulnerable to cyber security incidents and crime. To better understand the issue and find directions for new solutions, the Australian House of Representatives voted to create a Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations.

    The Chair of this committee, Sally Sitou MP, described it as the first federal inquiry to specifically examine this issue for small businesses, noting that “small businesses are on the frontline of cyber risk but too often they’re expected to defend themselves without the time, tools or resources they need.”

    This committee received bipartisan support, with the Shadow Minister for the Digital Economy, Aaron Violi MP, calling it an “important committee” and putting forward a supportive proposal for a member of the Opposition to be deputy Chair, which was accepted by the Government.

    We provided a submission to the Committee to share what we’ve learnt about this problem in our work at Lumenas, and put forward a range of proposed actions for government, the business community and industry associations to address this issue systematically. Lumenas provides one part of broader solution through our tools for accidental IT leaders, but we think there’s more work to be done across the economy so small businesses are better supported.

    To read our full submission click here.

  • How MS Australia uses Lumenas

    How MS Australia uses Lumenas

    “Continuously strengthening our governance and operations helps MS Australia build resilience, protect our mission and maintain the
    trust of our members and the wider MS community.”

    – Sonya Blondinau, Head of Corporate Services and Company

    Secretary, MS Australia


    How MS Australia used Lumenas to strengthen technology governance

    “Technology supports our day-to-day work in research and advocacy and helps us inform, empower and champion people affected by MS, along with their communities and loves ones.”

    MS Australia used the Lumenas IT Check to undertake an independent assessment of their technology use against best practice.

    MS Australia’s Head of Corporate Services, Sonya Blondinau describes the output from the IT Check as “a strategic, business-focused approach that made next steps easy to implement.”

    About MS Australia

    MS Australia is the largest funder of MS research in Australia and manages national research initiatives including the MS Australia Brain Bank, the MS Australia Clinical Trials Network and the Australian MS Longitudinal Study. Through the Lived Experience Expert Panel, we bring lived experience into governance, research, policy, advocacy, education and awareness, while publishing trusted information and resources that inform, empower and champion the MS community.

    Lumenas gave them greater confidence and opportunities to improve

    “While it was good to hear we already had a strong approach, Lumenas’ independent oversight gave us greater confidence in our governance of outsourced IT and technology support, while identifying focused opportunities for continuous improvement.”

    Want to learn more? Book a demo here or email us at hello@lumenas.com

  • Ice Cream Shop or Military Base?

    Ice Cream Shop or Military Base?

    Cyber security can often feel like a game of absolutes — either we’re secure or we aren’t. But it’s more complicated than that. The answer is almost always that we’re somewhere in between.

    Cyber risk, like all other risk, exists on a spectrum. We have to decide how much risk we can tolerate, then apply treatments and other mitigations to close the gap. Determining that tolerance is one of the most important technology decisions boards and executives make — it informs the whole cyber security program.

    But how do we know what our risk appetite is?

    One discussion exercise I run with organisations helps find the answer. Everyone in the room gives a number from 1 to 5 describing the organisation’s ideal cyber risk posture. One is an ice cream shop. Five is a military base.

    The purpose isn’t to land on some point in between that describes us perfectly. The purpose is to have an open conversation about the kinds of risks we face, the ways we use technology, and how much tolerance the business has for disruption.

    Take the ice cream shop. We’re probably taking digital payments and using some systems for ordering ingredients and managing staff, but we aren’t storing sensitive customer data. If we go offline, we can keep operating on cash, or take payments from a backup mobile terminal. Cyber hygiene still matters, but security may not be a major area of investment. Even at the low end the basics are non-negotiable — the scale starts from one because no one is at zero.

    Now think about the military base. Security is top of mind. We’re storing extremely sensitive information, and we need assurance that it hasn’t been accessed without authorisation or altered. The success of our information systems can be a matter of life and death — we rely on them for far more than information storage, from accessing controlled stores to communicating time-sensitive orders and managing access by identity and clearance. Here there’s serious investment in a layered security program that is continuously monitored, reviewed, and improved.

    Most of the organisations I work with land somewhere in the middle. The exercise gives us a group conversation that can challenge assumptions and build a consensus on what our ideal posture looks like. Usually we start with a few different positions in the room — some say three, some say five — and over the course of the discussion we work out why those positions were chosen. I’m yet to work with a group that couldn’t reach a consensus to carry forward into the decisions that follow.

    From there, I most organisations benefit from formalising the output of that discussion in a risk appetite statement. That can be used alongside governance activities like reviewing cyber risk assessments, developing treatment plans, or shaping an organisational cyber security program. As leaders, we can direct investment more confidently and understand the trade-offs we’re making with risk because we’ve had a clear conversation about what it actually means for our organisation.


     This article was originally published here on Linkedin as part of the Leading Digital series from Longitude Advisory.

  • The one thing economists love and IT hates

    The one thing economists love and IT hates

    The IT department has often been my first stop in any new job. This is because I often do pretty niche jobs, which means I need a different tech setup to most of the organisation. This has variously delighted and haunted my IT colleagues.

    In one job, I requested different permissions on my laptop so that I could update my special data science software more easily. This kind of software needs lots of little updates (often in the middle of my work) to keep functioning.

    It’s kind of like staying at a hotel and asking housekeeping for a freshly laundered pillow frequently – but not every night – because it alleviates otherwise-debilitating neck pain. Faced with this request, IT has three options: send someone to give me a freshly laundered pillow frequently (but randomly) on short notice, give me the key to the pillow room or give me the keys to every room in the hotel in perpetuity. They chose the third option.

    Why did IT give me the forever-master key to the metaphorical hotel? I would argue it’s because they probably thought the benefits outweighed the costs. This option gives me lots of flexibility to solve my own problems. I could try every pillow in the hotel (I didn’t), check if other people had different pillows to me (I didn’t, I don’t care) or go get a new pillow from the pillow room when I needed one (which I did). Choosing this option also benefits IT because they don’t have to answer my frequent, random emails and deliver each pillow. I also thought less emails were excellent because I’m impatient and urgent requests for a single freshly laundered pillow feel a bit ridiculous, even if there’s a sensible reason.

    But this option has a cost: an unacceptably low level of cybersecurity. While I never went into anyone else’s metaphorical hotel room, it is best practice to not give out master keys to hotel guests at random.

    In this instance, IT could choose this option because we hadn’t explained our preferences regarding cybersecurity, growth or much else. But even if you don’t explain your preferences, they will be revealed to you. Revealed preferences, the practice of identifying preferences through observation is generally the best measure of economic value thus loved by economists, and the worst way of managing tech thus hated by IT.

    IT people viscerally hate learning about a client’s preferences via observation, in my experience. But it’s often challenging to get a clear statement of preferences from non-technical business leaders. So they make-do with the information they’re given and trudge along.

    Some IT providers are able to bridge this tech-business communication gap. Consistently closing this communication gap across our economies will require more IT providers to have hard conversations with their non-technical bosses and clients. Those conversations will need to be a genuine two-way exchange to be useful, with investment on both sides.

    So how do non-technical (or ‘accidental’) leaders figure out their preferences in IT? Right now, you have three options: do the hard translation work yourself, hire a consultant or fractional CTO to do it for you, or get a better MSP.  At Lumenas, we’re building tools to make this work easier for all IT leaders, whether technical or accidental.

    Let me know if you’ve got a story like mine or are worried you might be living one. I’d love to hear more about people’s challenges in managing IT so we can help solve them.


    This piece was originally published on Linkedin here.