Tech Insights with Alisha Christian
In today's rapidly evolving tech landscape, staying informed is more important than ever. "Tech Insights" by Mercury IT is your go-to podcast for expert analysis, industry trends, and actionable insights from top technology professionals.
Whether you're interested in cybersecurity, IT infrastructure, emerging technologies, or digital transformation, this podcast covers it all. Tune in to stay ahead of the curve and navigate the complexities of the tech world with confidence.
Tech Insights with Alisha Christian
Privacy Act Changes You Can't Ignore
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Privacy risk is no longer just a "big business" problem. Alisha sits down with Chris Haigh to unpack the Australian Privacy Act changes pulling thousands of small and medium businesses into scope including reforms linked to anti-money laundering changes, and the growing expectation that every organisation knows exactly what personal data it holds and why.
We also cover what's coming around children's privacy protections and automated decision-making — and why the simplest first step is updating your privacy policy to reflect what you actually do, since regulators are now auditing policy against practice.
From there, we get tactical: the first hour after a breach, why panic causes expensive delays, and how tabletop exercises expose gaps before a real incident hits. We also look at why cyber insurance only helps if your declared security measures are genuinely in place, plus supply chain risk — the due diligence questions to ask suppliers, and what security certifications like ISO 27001 and SOC 2 actually tell you.
If you found this useful, subscribe, share it with a business owner who needs it, and leave us a review.
Welcome And Quick Updates
Alisha ChristianSo, Chris, we're back here again on the Tech Insides podcast.
SPEAKER_03Yes.
Alisha ChristianPlenty to discuss today.
SPEAKER_03Absolutely.
Alisha ChristianBefore we get into the topic though, I just I know you've had a busy few weeks. You've had lots happening.
SPEAKER_03Yeah.
Alisha ChristianAnd uh a few highlights for you.
SPEAKER_03Yeah, absolutely.
Alisha ChristianBeen appointed on a not-for-profit board, is it?
SPEAKER_03Yeah, so non-executive director of a not-for-profit uh on the Gold Coast. So that's good.
Alisha ChristianWell that's lucky them.
SPEAKER_03Yeah, absolutely. I I think it's gonna be good. Um obviously I can lend my expertise uh into that into that area of risk.
Alisha ChristianSo yeah, we certainly have plenty of experience in the not-for-profit sector. So yeah, that's something to uh yeah, to look forward to being on that, I'm sure.
SPEAKER_02Yes.
Alisha ChristianAnd also you have been appointed to speak at Cybersecurity Event down in Melbourne.
SPEAKER_03Melbourne, yeah. So it's the largest cybersecurity uh event uh held by ASA. Uh so happens every year. So this will be the first year that I'm uh speaking on stage. And uh we'll be speaking uh very much around the topics we normally speak about, uh around risk and from that director perspective and the board and what we need in place.
Alisha ChristianThat's pretty exciting.
SPEAKER_03Yeah, it's gonna be great.
Alisha ChristianYeah, nervous?
SPEAKER_03No, not yet.
Alisha ChristianI'm sure I'm brilliant.
SPEAKER_03I kind of get nervous like walking up, and then as soon as I start talking, then you're so nervous.
Alisha ChristianYeah, exactly, exactly. We're lucky probably to have got you here today, then, because obviously the next few months are gonna be pretty full on.
SPEAKER_03I'd literally have two board meetings today.
Alisha ChristianWell, we better get into it then.
Privacy Act Shifts Hitting SMBs
Alisha ChristianSo today we're um talking, well, we have plenty to cover actually, but we're talking about the changes to the Privacy Act to start with.
SPEAKER_03Absolutely. So there's been quite a few changes, uh, not just with the Privacy Act, various elements that we have to keep across. So yeah, so we'll get into a few of them, I think.
Alisha ChristianSo, what would you say is the most important thing for business owners to know about the changes coming?
SPEAKER_03Look, uh the main there's there's been a few changes and they keep updating it, which is absolutely fantastic. Um it's good for consumers, it's good for all of us. Um, but essentially one of the big changes actually happened about a year ago, uh, where a uh private citizens can actually sue a large business for a large breach uh of data. So that's been in for a year now. Uh July 1 uh came another change, and it's around the money laundering um changes. Um and what's actually happened there is where a lot of businesses thought that they are not uh kind of uh taken up into that uh privacy change, they are now. So uh the government um actually expected or estimated about a hundred thousand small businesses would actually be caught by these new changes.
Alisha ChristianOkay, well, that actually my next question was going to be that a lot of SMBs assume that they're not caught up in that um particular privacy act.
SPEAKER_03Absolutely. So that uh is probably quite a dangerous thought process now. You need to change that a little bit. Um obviously look at the data that you're holding, etc., and see whether you are caught up. But that initial thought was around the three million dollar turnover and whether I was under that threshold and therefore the privacy act did did not apply or these changes didn't apply. Um, they do now. So, and they have just a note, they have also uh said that they're going to remove any kind of threshold. Oh now that hasn't happened yet, but I'd certainly any business, I'd I'd be looking at it and making sure that we are actually doing the right thing with regards to the Privacy Act and and what what it actually means for our business. Do not lean on the oh, we're not caught under that yet. There's there's so many that have been caught out, uh caught under the new one. So estate agents and etc. for that three million turnover is is not a thing anymore.
Alisha ChristianSo basically all SMBs need to have it on the radar.
SPEAKER_03Pretty much, yeah.
Automated Decisions And Child Privacy
Alisha ChristianYeah, okay. Uh and there's also some changes coming in December around AI and automated decision making.
SPEAKER_03Yeah, there's uh two two things coming on the 10th of September, uh, 10th of December, sorry, uh this year, and that is around uh child uh protections uh under the privacy laws uh for children specifically. And the other one is, as you said, automated decision making. So not necessarily AI, it's anything. So if you've got an algorithm, a calculation, or anything that you do, that think of things like um whether people are going to get a loan, uh tenants, which tenants get selected, etc. So any system whereby there's an automated ranking or something like that. Now, it's important to note that the government's not saying that you can't use this, they're saying you need to be transparent about its use.
Alisha ChristianOkay.
SPEAKER_03Yeah.
Alisha ChristianBecause yes, I saw like even for jobs resumes and that sort of thing. It's yeah, and I guess we're just gonna probably see more and more of it.
SPEAKER_03So what you'll see, or what businesses need to do if you are using any of these, uh, specifically AI, because it's quite difficult to then say how it's working, because it's difficult with AI. Um, but you do need to then uh disclose that the best place to do that is in your privacy policy. So update your privacy policy. That's where it needs to be.
Alisha ChristianOkay, well, that's some good advice there because that should be not too difficult to do.
SPEAKER_03It shouldn't.
Alisha ChristianYeah. Uh what do you think is the biggest mistake that uh small to medium businesses are making around um privacy these days?
Data Hygiene And Privacy Policy Reality
SPEAKER_03Um biggest. You could tell there's a few. Um the biggest one actually is probably still holding on to data that they shouldn't.
Alisha ChristianI thought you were gonna say that actually.
SPEAKER_03That's probably the biggest one because you know there's gonna be. I can guarantee you it business owners are gonna go away and look when I say this, right? There'll be a 2019 spreadsheet for a marketing campaign. No, yes, and it's gonna have details on it, and it's gonna be sitting somewhere random or in multiple places. So yeah, don't keep data longer than you need to. And it kind of goes into that whole fact of uh do you know what data you have and where is it, and etc. Like we've discussed it before, absolutely data hygiene. I'll I'll add I'll add one more to that, just as a bonus, yeah, because it's important, and that is um a lot of smaller businesses don't have time for all the stuff that doesn't relate to their business, so to speak. It's not making direct money like privacy, like uh policy. So what they'll do is they'll go and find a privacy policy, change the name on it, right? Won't read it because it's six pages long, and then put it on their website. The problem with that is whatever that privacy policy says you do with the data, if you're not doing it, that's gonna become a problem. So the information commissioner is actively going and auditing businesses against what they do, against their policy. This is already happening, it started last year.
Alisha ChristianWow.
SPEAKER_03Yeah.
Alisha ChristianUh it kind of does lead me on to I was going to say, um, you know, what could business owners do today?
SPEAKER_03And you've kind of already answered that question. I will I will rephrase it. So go and do a data audit. So grab your heads of department or whoever you need to, and actually just go, right, the data that we collect. So especially if you a uh business to consumer, you you're probably gonna hold a lot more uh personal data, but even business to business, when you when it's business to business, a lot of the time business owners will go, Well, I'm not holding a lot of personal data, it's about another business, and that's a fair statement. So, what you need to think about then is your staff. So if I've got you know uh 180 staff, but I'm a B2B, business to business, I've got to worry about where my staff data is then. And again, this starts going into what about staff that have left? Yes, do you still hold their Medicare cards and a copy of their passport and their driver's license and and bank account detail? There's so many things, tax file numbers, where is it kept? Is it safe? If you've got it in a SAS-based thing, fine. Can you remove anything you don't need? Uh is an important one. So data cleansing. But to wrap it up, it's essentially what data do we have, where's it kept? Who has access to it, right? And do we need it?
Alisha ChristianFour things. Okay, well, that's four good reminders there. So that's something most business owners could go away and look into.
SPEAKER_03It it's not hard to do. I think it's more a case of it's there's it it kind of just feels like a okay, that's that's not making me money. I need to focus on getting new customers. I totally get it. And that is why you know you you do sometimes need to bring in experts, run an audit, do it. There are tools that can do it. Unfortunately, they are relatively expensive to be able to do those sort of scans, uh, but very useful, very, very useful, especially um legal firms, uh accountants, things like that, where they do collect a lot of that sort of data uh and it becomes a massive target, is you can actually get a system that will scan using AI and actually pick up driver's license, tax file numbers, etc., and actually give you a dashboard of how many you have and where it is. It's it's very impressive.
Alisha ChristianFor some businesses, it probably would be worth spending the money.
SPEAKER_03Absolutely. Agreed. Yeah.
The First Hour After A Breach
Alisha ChristianUm, well, with all that data, um, it probably leads me into you know an incident response. So if a business does discover a breach, yeah, um, are you able to just walk us through what the first hour actually looks like? I know we've covered probably the whole data beach for breach before, but just really around that first hour. Yeah. Yeah, apart from breaking out into a cold sweat.
SPEAKER_03Exactly. So step one, don't panic, remain calm. Um, so your very, very first steps obviously uh around the not panicking and remaining calm, but the first actual step is containment. So if it is something that's uh common, a common one would be an account breach, right? Uh someone will get a phishing email, they've given their username and password away, a bad uh threat actor has now come onto the onto the system using that uh username and password, and now they're sitting in that environment, right? And it gets discovered somehow. Now that could be you've got an alerting system that's managed to pick that up, uh, or they've sent a fake invoice to one of your customers, which is common. So that's your business email compromise, is what that's referred to. Um, and then it's picked up. Like maybe the customer calls and you go, Hold on, I I didn't send an invoice, and then you discover what's going on. This is the first hour. And you can understand the panic that sets in at that point, right? Yes. But containment, right? So like uh immediately resetting that account, logging off all sessions, right? Kicking those sessions off, resetting the password, checking for like sneaky rules across the mailbox because they've been in the mail for so long. It's like have they put redirections on to go to an external mail so they've still can see it once they get kicked out. So this is what a professional will do. They'll come in an expert and they'll go through it. Because there's about eight different ways of managing rules and where to put those rules, and they need to be checked very carefully.
Alisha ChristianI never even would have thought about the rules set up in there.
SPEAKER_03That is why you get an expert. Yeah, yeah. Because they know they know they'll be like, right, there's there's eight different, they'll have what's called a runbook, and they'll literally run through essentially a playbook of what they need to go and check to make sure that that uh account is sanitized. So, you know, often there'll be rules that will auto-delete things that's basically covering their tracks. So we're looking for those sort of rules and we're trying to fix all of that stuff up. The next part of it is the investigation. Um, and the investigation part is trying to then find out what what have they had access to. Because if someone's got access to email, the biggest problem I've seen in this country is whether it's legal, professional services, etc. They're like, oh, okay, you need a loan. Uh, you we need a copy of your uh driver's license or passport or whatever, and it's like email it through. Like, excuse me.
SPEAKER_02And it's it's common, it's very, very, very common.
SPEAKER_03And and they and businesses still do it. And email is not secure uh for the exact reason I'm just telling you, right? So breach occurs. Now you've got a threat actor in the mailbox, or the first things they do is they'll run a number of searches on the mailbox, they'll look for data patterns that match driver's licenses that will look for uh tax file numbers, that looks for account information, that looks for password reset emails, etc. So they get access to more things, right? So generally they've they're picking out um, you know, the these poor people that have sent their driver's license and et cetera, because the person gets the driver's license, they like great, they copy it onto their system, tick, but it's still sitting in their email.
SPEAKER_00Yes, that's right.
SPEAKER_03Right, and that's the problem. So you need to understand what has it touched as a data perspective, right? So um personal identifiable information like those bits that I've just mentioned, those are going to be important because who do you need to notify, right? Yes, and that brings us to the third point, which is notification. And notification is then notifying potentially the information commissioner, so um the um Australian Information Uh Privacy Commissioner if there's a uh harm caused, right? Yes. Now that is generally a legal term. I I if you've got insurance, definitely call the insurance, call them early because they'll have access to legal teams and forensics teams that can actually help with this sort of thing. Otherwise, you searching through your mailbox trying to determine what they found, right? If I can get a forensics team to run it, right, they'll have within a few hours, they'll have a they'll produce a spreadsheet that tells you exactly what it's touched. This bit of information, these are the people, etc. Because those are the people that you're gonna need to notify directly.
Alisha ChristianSo definitely sounds like it's worth bringing the experts.
SPEAKER_03Absolutely, agreed.
Alisha ChristianAnd time saving too, I'm sure.
SPEAKER_03Agreed. So otherwise, yeah, you'll be stuck quite a while looking for
Incident Plans And Tabletop Practice
SPEAKER_03stuff.
Alisha ChristianSo, what would you say the difference between a business that handles a breach like this well and a business that maybe not so much?
SPEAKER_03Um like for me, I I think it's around uh preparation. So having a documented incident plan, so response plan, that that's one part of it. The second part of it is actually running through the plan, actually testing it.
SPEAKER_00Yes.
SPEAKER_03So it's not, you know, uh 3 p.m. on a Thursday afternoon, people are trying to make a decision in a half-panicked state of what they're supposed to be doing. Who do they call? What are they trying to look for? What and they a lot of the time businesses freeze, and what they often get wrong is the notification goes backwards. And what I mean by that is the investigation hasn't uh begun yet, and they're notifying, right? Like one of the mistakes I see is they notify the entire organization that there's a breach. Don't do that, okay. Okay, that that you hold while you're trying to work out what's going on. Um, if anybody's got a direct query, fine, you can respond to them. You don't need to lie. I'm talking internal to your organization. You don't want a situation where it's going out to all staff and then they calling their aunts and uncles about, and then it ends up on Facebook. Like that you need to control the narrative. So it's keep it tight. You've got a response team, work through the plan step, step, step, step. The the more controlled and um exercised that plan is, uh, the more you're gonna win. Because essentially you're gonna mitigate the amount of damage. You know, if you send that out to all staff uh when you don't need to, and then it spreads somehow, you're causing more reputational damage before you've had a chance to even know what's going on, right? For that matter. The other problem is is coming out to the public too early as well. Before you sort of know what we have seen, which is frustrating for people, is they'll come out and go, Okay, uh, there has been a breach, but no data has been taken. And then four days later, the same person, unfortunately, normally the CEO, like comes back and goes, They've taken a lot of data. And then you know what I mean? And it kind of and it it feels like concealment when it's not, they're trying to do the right thing, but too quickly.
SPEAKER_00Yeah.
SPEAKER_03So yeah, your notification and speed of that response is important, but don't do it without the relevant information first. Yes. So the information commissioner gives you 30 days to do the investigation and notification. Well, that's uh it doesn't mean you should take 30 days to do that.
Alisha ChristianNo, no, I was gonna say that seems like a fair amount of time.
SPEAKER_03You need to work quickly and methodically and notify as soon as you can with the right information.
SPEAKER_00Yes, okay.
SPEAKER_03This is where your insurance will help again because your legal teams, etc., they will all the they will coach you and guide you with that information.
Alisha ChristianYeah. Um well that's good actually, because I was wondering whether or not you notify first or investigate first, or so that's kind of yeah, definitely cleared that up. Um would do you have any uh examples of uh a business, don't have to name them, of where you've had to run through this sort of situation with?
SPEAKER_03Uh through an actual breach or um there's there's been there's there's a few um because breaches happen all the time. So when there's a a very large uh breach that takes place, uh we did deal with one uh for a legal firm um a couple of years ago now, um, whereby it was a ransomware event. So they're locked up, uh, encrypted the files, so they couldn't work. Luckily, this was on a Sunday, so we had them back up and running on the Monday, uh, that kind of thing. So, and it is, and it then it's just a cycle of events from there of uh you know containment, uh restoring them, uh getting your cyber insurance involved, that investigation taking place, forensics, etc. So you gotta you just gotta step step through it. Yeah, keep it keep it cool, and and as for account breaches, because those those are common, uh, we dealt with one uh not last week, week before. Uh happens almost most weeks. Uh, but we've got a 24 by 7 um uh security operations center. So that picked it picked up the breach within about 12 minutes of them accessing the account. So we had it that was him. That's it. We had it locked down within 15 and kind of cleaned everything up. So in about 27 to 30 minutes from start to finish, it it was dealt with.
Alisha ChristianSo that is pretty impressive. It's useful. Yes, very exactly better than having to be there a couple of days. For sure. Um, what would you say um the biggest mistake that businesses would make um around like if they're breached, would it just be just not acting, just ignoring it?
SPEAKER_03Yeah, look, honestly, that's probably the biggest one is that panic sets and and so there's no response.
SPEAKER_00Yeah.
SPEAKER_03And I think that is the biggest thing. Even if it's no response for an hour, well trying to uh like then you you've lost that hour. And whether if it's like a business email compromise and they've done that invoice fraud, uh that money could be long gone. And if you had picked up within the hour, called the bank, you might have been able to reverse the funds, uh, all those sort of things. So speed is important, but you get speed out of practice.
Alisha ChristianYes, that's right, exactly. Yeah, and I know you um often talk about table topics and that sort of thing. Uh absolutely. Yeah.
SPEAKER_03So our tabletop exercises are exactly that. It's get the breach response, gather the team. It normally takes around two hours. It can go longer, it depends. But generally a two-hour decent sit-down around a table and actually run through a scenario. Yeah. So you basically pick a scenario not quite random. There's scenarios that you had run that are more common than others, so you'd run them through. It's like if we do a uh a ransomware uh response, uh, then the next time it won't be a ransomware response, we'll do something else. So we could test a little bit of a different dynamic because sometimes it brings in different teams of who's doing communication or et cetera.
Alisha ChristianYeah, and I guess it um it's good for the team because they probably feel reassured that if something does happen
SPEAKER_03They're kind of like semi-equipped to be the idea of the of that uh the tabletop exercise is also to find any gaps.
SPEAKER_02Yes.
SPEAKER_03So they go, Oh, okay, well, we'll need to do this. And it's like, oh, well, we don't even have that person on the and there should be because this would come in. So we were like, okay, so there's a gap there in communication. Add add that in. So that that's the idea is to try and pick out any gaps on the day. Because you don't want to be dealing with unknowns on the day.
SPEAKER_00No, you definitely.
SPEAKER_03So it's like who and we'll ask questions like, you know, they'll go, Oh, well, we'll just call Ben. Ben will handle uh this. And we're like, so we obvious question is so Ben's not available. He's sick.
SPEAKER_02Yeah.
SPEAKER_03Now now who are you calling? And then you yeah, hopefully, then at that table top, if it's missed, then it's okay, we we need the this this person, you know. So yeah.
Alisha ChristianWould you say that more businesses are starting to understand like the importance of table topics and you know, basically running through these scenarios um more so than you would say like five years ago?
SPEAKER_03Uh definitely more than five years ago. Yeah, absolutely. So I th I think that's coming more to the to the forefront.
Alisha ChristianSo I guess too, we're definitely hearing more and more about breaches and that sort of thing. So I think people are definitely becoming a bit more aware and uh it's a bit more on the radar.
SPEAKER_03Yeah, definitely.
Director Pressure And What To Prioritise
SPEAKER_03And look, a lot of a lot of pressure is coming down from the government to directors.
SPEAKER_00Yes.
SPEAKER_03Yeah, so your board is now kind of very much more responsible uh for certain things happening. And and the reason for that is there's been legal cases where we've had Australian clinical labs uh getting a $5.8 million fine uh last year. Uh there was uh the uh the next ones that came up with regards to finance uh type uh breaches as well. So that and that was um um ASIC that uh did that. So you had the information commissioner uh doing fines, but you've had ASIC doing fines as well. So there's two two different kind of branches of government, let's say, that are coming after uh directors and businesses if you're not doing the right thing, right? And I think often the problem becomes going, well, what is the right thing? Yes, and that is what I tend to talk about. I will get in front of the board and say, right, these are the things that are being expected. This is what the costs are, this is and prioritize and what do we actually put in first? What are we looking at? Like, should we be doing an audit? Do I need to do ISO 27001? What about this SMB 1001 I've heard about? You know, do I do what about essential eight? Everybody's talking about essential eight. So it's there's a lot of information there. So it's like, well, what do I prioritize and what do I actually do? What do I actually need so that if I'm ever standing in front of a judge, I can go, I've done the right thing. This is the information I got, this is what I understood, this is what we put in place.
Alisha ChristianYeah, because it'd be very overwhelming. Like you say, there's absolutely so many different avenues to take, and finding the right fit is important.
SPEAKER_03Agreed. And and that is literally the basis of my talk uh in October, uh, is is around that because it is complicated.
SPEAKER_00Yes. Right?
SPEAKER_03And and it doesn't need to be, but like you definitely need an expert to understand a little bit about your business and what what you need to put in place.
Alisha ChristianPut the right steps in place, yeah, for sure.
Cyber Insurance Does Not Replace Controls
Alisha ChristianUh so you did mention cyber insurance before. Um, so I mean, a lot of businesses probably have cybersecurity insurance or a cybersecurity insurance policy, and probably thinking, well, that's it. Um sorted. Which I mean, sounds good. Is that the case?
SPEAKER_03I I I suppose if you do an analogy of like going, okay, you've got car insurance, right? So you're sorted. Like you can drive however you want, right? You don't need to change your tires, you don't need to service your car. Yeah, you see where I'm going. So, no, you can't. Because the idea then is if you have an accident in that car and you've got four bald tires, insurance is not paying out. Like you, you have a problem, right? Because you haven't done the right thing, right? So, yeah, so again, it comes back to your responsibility and what you should be doing. So, insurance is always there to help when something goes bad, right? So, it's that kind of a bit of a catch-all, it's that kind of idea of going if it goes bad, and it generally will at some point, that you have some extra expertise and money to help you deal with it, that you don't need to keep your yourself aside. And very large businesses would self-insure, for instance. So they've got three million in the bank, so they're like, Yeah, we can deal with it, and that's fine. But a lot of businesses don't.
Alisha ChristianNo, that's right.
SPEAKER_03So that's where the insurance comes in, and uh, so you still need to be doing the right things. Also, on top of that, um, it's uh cheaper in the long run to put in your uh your pre type items than post. Yes, it's it's that simple. Uh, in fact, the the one of the uh cases I was talking about that was actually in the court documents as well, where it would have cost them um like 1.1 million to uh do the pre-items that they needed to do, update servers, whatever it was, right? New firewall, I I can't remember exactly what they were, um, versus having to do all of that plus audit controls plus the fine, etc. with that came out at two and a half.
SPEAKER_02Oh.
SPEAKER_03So it's like spend one or spend two and a half. It's up to you. No, I'd rather do. So that so so no, you can't just get cyber insurance, like it in in place of good cyber hygiene. You have to do the good cyber hygiene, yes, and then have insurance. And then a lot of people go, okay, so I'll only get the insurance then once I get all these things in place. They're like, no, you you probably need to run them in parallel, right? So look at the cyber insurance and then make sure that you get the the bits and pieces in that you need.
Alisha ChristianBecause it would there be sort of like some sort of checklist or something like that where you have to go through and absolutely.
SPEAKER_03There's there's gonna be a minimum that a insurance company is gonna expect. So, you know, three, four years ago that it used to be like a one-pager, like tick, tick, tick, tick, tick, insurance. Now I'm seeing those documents like getting to about 20 pages. It's like an audit, right? So it's it's kind of becoming this audit. And um if you do have an IT uh firm, if you outsource your IT, generally what you can do is grab that, send it to your IT provider and go, can you help me fill this in? Um I do have a caution around that though, which is it kind of sounds obvious, but I'm gonna say it anyway. Um don't tick a box that says you're doing something, like you've got EDR, right? So endpoint uh protection and response type setup, right? Um if you don't. Because if something goes wrong and then they check, right, and you didn't, and you said you did, they won't pay out.
SPEAKER_00Yeah.
SPEAKER_03Right. I think everybody knows that though, from an insurance perspective, right? So I guess it's the same event works.
Alisha ChristianYeah, yeah, exactly.
SPEAKER_03Right. It's like, yes, I've got window locks, and it's like, okay, your burglary came through this window that didn't have a lock.
SPEAKER_00Yeah.
SPEAKER_03And it's gonna invalidate the insurance. So you do need to be very, very careful with that. I mean, uh, like I said, it's kind of obvious. It's it's it's illegal to lie on the documents anyway.
Alisha ChristianStill worth, you know, but highlighting.
SPEAKER_03Well, let's put it okay, I'll put it in a different way. I think what happens there though is the business owner genuinely thinks that they have the thing that they've ticked, right? So they've spoken about to their um their IT service provider. Uh, we need MFA everywhere. Like I've watched the podcast, they keep talking about MFA. It's been burnt into my brain. So I go and speak to my IT provider and I get MFAs in. So when I get that document and it says, you have MFA enabled, right? Everywhere, you go, tick. I've discussed this with my IT person. I paid money for a project to get MFA rolled out to everywhere. Done. Then they get breached through an old admin account that has no MFA, and the forensics picks that up, goes to the insurance provider, and they go, You tick the box that you have MFA. But there was this account that does not have MFA. Again, they're not gonna pay. Yeah, but now where does the responsibility lie? As far as the the the business owner is concerned, they have MFA, they've paid for it, yes, right? So where's the where's it falling down, right? And quite often this is where it starts coming out to auditing and making sure that you have whatever you think you have actually in place, and that's also important.
Alisha ChristianSo yeah, it's a lot for businesses to kind of absorb and agreed.
SPEAKER_03And that's why I uh honestly, probably the best way to do it is probably outsourced. It's just finding a provider that can do all these things that's not like horrendously expensive because it's a lot of work, yeah. Right?
Alisha ChristianSo but important to get it right.
SPEAKER_03Correct, yeah.
Avoiding Denied Claims And Reading Clauses
Alisha ChristianUm, what would you say with um claims that are put in, what would you say is the biggest reason for getting knocked back?
SPEAKER_03Like rejected? Yeah. It is, it is exactly what I just said. Yeah. It's where you've you've ticked a box because you th you think you have it and it's not. Um one I saw a couple of years ago was um they would they uh said that they did uh cybersecurity awareness training with staff and they didn't. And it was an easy thing for the insurance to check, right? They just interview one of the staff members and go, when last did you have? And they go, Oh, I've never had that. So yeah, the insurance didn't didn't pay.
Alisha ChristianLTM would be like, oh, we have too much of it.
SPEAKER_03Yeah, well, yeah. It's like it's horrendous. Um, but yeah, and in that case, that only cost them 40,000. So it was $80,000 lost for a weekly pay run. Uh, they managed to hack and get into the payroll system, they changed everybody's accounts over to their accounts. Then the weekly pay run went on the on the Tuesday, and I think on the Wednesday morning they started getting queries going, Where's where's my pay?
SPEAKER_00Yeah.
SPEAKER_03Um, so they managed to get to the bank, and the bank reversed half of it from 80. So they got 40 back. So they were out of pocket by 40. They did have cyber insurance, but then failed on the uh cyber awareness training.
Alisha ChristianVery disappointing.
SPEAKER_03Which had nothing to do with the uh breach, by the way.
Alisha ChristianNo, well that's it exactly.
SPEAKER_03It didn't matter. It's just a case of you said you did this, you didn't, we're not paying.
Alisha ChristianYeah, it'll be very disappointing, that's for sure.
SPEAKER_03Yeah.
Alisha ChristianSo uh is there a bit of a gap between what people think that they're covered for with cybersecurity insurance as opposed to what they actually are? Or does it sort of vary depending on policy to policy?
SPEAKER_03I I I I don't know. Uh uh, but there definitely can be gaps. So whether that's common or not, I I don't know. Uh, but I've certainly seen when these forms come through, for instance, uh our help our clients, what do we fill in? What do we say we do and we don't do, and all those things. Uh there are quite a few potentially gotchas from clauses that you do need to be aware of, right? So uh number one, if you're using a broker, which I think a lot of people do, it's probably good to just say to the broker, Hey, can I grab 15 minutes, sit down on a phone call, and actually run through two scenarios. Yeah. So that he can walk you through, uh he or she can walk you through the clauses of when they pay out and when they don't, right? And what do you need to do? Yeah. Because it's actually important. So uh the first one I'd do is actually ransomware. So say, okay, everything's been locked. What happens? Do I call you first? Can I can I spend any money to fix the problem that I have before calling you? Or do I need to call you first and get authorization? Otherwise, you won't reimburse me. So there's things like that. And get him to walk through the clauses of where the issues are with that. Once you understood that, then run another scenario and say an account gets breached, they re-invoice one of our clients, uh, we've lost a hundred grand.
SPEAKER_02Yeah.
SPEAKER_03Right. Can we get that money back? What does that look like? And have them run through that scenario. And the reason for that is there's often clauses where they'll exclude things like social engineering, right? But the problem is, what does social engineering mean? Is it an email that tricks someone into giving their username and password or phishing? Is that also social engineering? Or is social engineering only if they call and convince someone over a phone call to make the bank account change? Like, what do they mean?
SPEAKER_00Yes, well, that's it exactly.
SPEAKER_03So the definitions are important. Um and and luckily today we do have AI. AI is obviously not a lawyer, but it's not bad at reading through documentation and working out certain clauses. You could ask the same questions of your preferred AI tool, and it would give you probably a half decent answer. Um, it might not be right. I would definitely go to the broker if I've got access to the broker.
Alisha ChristianI have actually used it for that too, not for not for something quite as serious as uh cybersecurity uh insurance, but I have when I've been you know strapped for time and I'm like, I just want to see if there's any red flags. Absolutely miss. And it's not bad. Yeah, it's not bad. But like you say, I mean, you do still need to do your own thing.
SPEAKER_03Again, you have to think it's like they are not good or whatever. No. Like you we get this, right? The responsibility is still yours. Yes, exactly.
Alisha ChristianBut it definitely pulled out some red flags.
SPEAKER_03So it might pull out a few things that you could take to the broker and query.
SPEAKER_00Yes, exactly.
SPEAKER_03Ah, I noticed blah. I mean, you didn't. Claude did or whatever you're using, but it doesn't matter, right? The point is it's so that we get a little bit better at actually understanding what we're signing and what it's going to cover.
Alisha ChristianYeah, because sometimes those terms and conditions can be pressed.
SPEAKER_03Absolutely. And if you don't quite understand it, and then it's like something happens and you go to them and they go, Oh no, that's social engineering, and you're like, okay. And it's like, oh, you see this tick box here, you didn't tick the social engineering box.
Alisha ChristianYeah.
SPEAKER_03And then you don't have it.
Alisha ChristianYeah, it's definitely some good points to look out for there, for sure.
Supply Chain Risk And Supplier Due Diligence
Alisha ChristianAnd uh, would you say, um, just moving away from that, but still around risk, like third-party supply risk, is that something that's probably you know worth highlighting?
SPEAKER_03Absolutely. This is this is uh another one. Like when we started this, we said, oh, there's been a few changes. And it's it's not necessarily changes, it's um kind of awareness levels, let's say, are changing, which is great, right? And one of the big ones that have come in, uh, mostly through our governments as well, which is great uh to see, uh, but they are concerned around critical infrastructure, right? And where the um what they started looking at is going, okay, the supply chain for critical infrastructure is also important. Example, um a company that's looking after water in some way, distributing the water, putting chemicals in the water, whatever it is, right, is a critical infrastructure component. But what about the business downstream that provides widgets to this business so that they can open and close valves for water, right? If they get ransomware over here and can't supply said widgets, where maybe in this business they've identified they need 100 widgets per month, otherwise services stop. Now it becomes a critical path. Yes, right? So that's supply chain risk. So the problem is downstream, right? You have suppliers, whatever their security is, you are inherenting. So if they terrible at their cybersecurity, right, and they're getting ransomware, it's going to affect you. Similar, you are downstream from uh your consumers. So that's why they talk about supply chain risk. And it's understanding what is upstream and what is downstream from you, understanding what the risks are, and then from a cybersecurity perspective, you are essentially inheriting parts of that risk up and down.
Alisha ChristianYeah.
SPEAKER_03So that that's where that comes from.
Alisha ChristianAnd I mean, that's even trickier to. I mean, it's hard enough looking after your own cybersecurity and then having to yeah, investigate what everyone else is doing as well.
SPEAKER_03Absolutely. And look, larger providers have kind of been sending a spreadsheet with questions to the to generally smaller suppliers because they've got their cybersecurity handled. They're large. Let's say it's like Woolworths. They've got lots of suppliers. And they just send a spreadsheet that's got a thousand questions on, and unfortunately, what that becomes is a tick box exercise. It's like, yep, but I do all these things.
Alisha ChristianBecause that was going to be my question, actually. If you're signing up with a new supplier or like software provider or something like that, what would be the best questions to ask? But it sounds like there would be many.
SPEAKER_03Look, there there are quite a few, and obviously uh uh uh again, if you can outsource it, great. If you can't, then you do want to know it cover some of the basics. And there are some shortcuts to this in that you could um so an international certification around these sort of things uh that people may recognize is ISO 9001. 9001 is quality control, right? And it's well understood globally, it's an international standard, um, and it's often used for manufacturers and things like that. But it can be used anywhere. The idea is you provide a consistent quality service, right? Now, ISO 27001 is that same sort of concept, but for security. So if you have a new supplier, you could ask, right, what cybersecurity controls do you have in place? They might come back and go, Oh, we are ISO 27,001 standard. Okay, that gives you a little bit of confidence that they take it seriously, a peace of mind, and they're doing something about it. Doesn't necessarily mean they're doing everything that they need to, but it's certainly a step in the right direction. Always remember security is not black and white, yes, uh, nothing is 100% secure, so it's always about security in depth, right? So, yes, they've got ISO 27001, great. Do they host your data, right? And a lot of the time for suppliers, software they do, right? So do they have SOC 2 compliance? Now I'm just kind of rattling off a bunch of acronyms.
Alisha ChristianLove an acronym.
SPEAKER_03But the idea is a lot of these businesses. So keep it simple for yourself and actually just ask, what do you do around cybersecurity? How do you keep our data safe? Where is our data? Who has access to it? It's that same sort of question you asked about your own data. Where is it? Who has access to it? Right? Um, so same. Where is it kept? Who has access to it? Um, etc. So and things like um, you know, is MFA enabled for users getting access to that data? You know, if it's a SAS, so this software as a service, uh, and you storing personal information in there and they do not have MFA, I am not using them.
SPEAKER_00Yes.
SPEAKER_03End of story. So it's like going like uh we use Xero for accounting. Awesome. Do they have MFA? Yes, they actually forced MFA a couple of years ago. No questions, you will be using MFA. Fantastic. Go use Xero.
Alisha ChristianAnd I guess if they do have those things in place, you have peace of mind and know that they do take cybersecurity seriously. And if they don't, well, it's potentially not someone you really want to do business with anyway.
SPEAKER_03Correct. And certainly I'd be asking these questions before signing a contract.
Alisha ChristianYes, definitely.
SPEAKER_03So quite often these businesses will have uh what's called a trust center on their website, and they will put all the relevant documentation around their security, privacy, etc., all under this trust center, which I think is a great idea. I think uh more businesses should actually have a dedicated web page that's called trust center and put all their stuff there. So it's too if we could, yeah, that would be a lot to my list. I do like it. Yeah, because it's then it's easier. A customer uh or potential customer looks at it, looks through it, and go, okay, they they've thought about it, they've put it in. Again, not a guarantee, but it's steps in the right direction so you have a better understanding of where they're coming from.
Alisha ChristianWell, it definitely shows that there's initiative there to keep it.
SPEAKER_03And it's also due diligence from our perspective. So if I'm a director, right, uh it does sit on me to make sure that I've done the due diligence about my suppliers.
SPEAKER_00Yes.
SPEAKER_03So if I can go, I have cited their SOC 2 report and their ISO 20. 27,000 report as an it's not expired as an example, right? I can go cool. Um, and on that note, obviously a larger company has got generally more suppliers that they have to deal with. So trying to do this um kind of risk assessment across that many suppliers, now that's starting to get cumbersome. Yes, right, and that there are again, there are tools for this sort of thing. So you can actually get a system that actually goes and gathers this information for you, puts it all in one place, right? And it can actually give you a risk heat map of your suppliers. So if anything changes as well, right, you doing a review, I don't know, quarterly, or you get alerted that something's changed. So, like maybe you use Cisco, for instance, and then Cisco's had a breach on one of their firewalls, uh, or there's a vulnerability, it will feed back into the system and comes up red, and you're like, oh, what's up? And you know to go and do something or not. Yeah.
Alisha ChristianThat's okay, that's pretty handy.
SPEAKER_03That is for the larger side, it is expensive to obviously manage all of that, but that's definitely.
Alisha ChristianBut I guess if you're a larger business and you are dealing with that many suppliers, it's something worth correct.
SPEAKER_03If you're the smaller business, it's actually just running through a smaller due diligence checklist. Yeah. Do they take care of their cybersecurity? Like you want to see some evidence of it, you want to ask some questions, do you use MFA? Where's my data kept? Those are the type of questions you'd ask. And then store those responses somewhere. Yes. So if anything happens, you can always go, yeah, we did do our due diligence. This is what we checked, and they said they did these things.
Alisha ChristianYeah, I wonder how many smaller businesses are actually taking that initiative to do that.
SPEAKER_03This is relatively new. Yeah, I know.
Alisha ChristianI know exactly. Okay, we haven't talked about it before. It's absolutely why we talked about it. It's actually such a you know, great thing that you have brought it up today, especially for smaller businesses because I think a lot of the time, again, as we always go back to, we're not going to be targets, but yes, you obviously have to think about what's like having friends, you know, you associate with the wrong friends, it can get you in trouble, and you associate with the wrong suppliers. Don't take cybersecurity seriously. It could be your undoing. So yeah, I think those points that you've touched on are will be very beneficial for um smaller to medium businesses to take on
Practical Takeaways And Where To Follow
Alisha Christianboard. No, good. Well, we've certainly covered plenty of information. Uh is there any one particular thing that you'd like people to take away from today's episode? Or you've probably covered up plenty.
SPEAKER_03I I would, yeah. I and like the bits and pieces, like what do you go do now? You know, um a a big one is that that data cleansing. Go and do that exercise. That like take an afternoon, go right, we're gonna just go through that. Check that your privacy policy aligns to what you actually do. And I'm saying that because they're actually doing checks, they're doing audits, so you could be fined. Like, make sure you're doing what you say you're doing. I mean, so like you said, it's not particularly hard, right? It's just like document and do what you said you were gonna do. That's it. Um double check your cyber insurance, uh, make sure you haven't ticked any boxes that you're not doing. That's important because it will invalidate that insurance. So it's it's it's very important. Um, to get that done, start having a think about your supply chain. That that one is a little bit uh different, but certainly start having a little think about where that is. And then that other one is that incident response plan. Make sure it's documented, right? Yes, that is actually part of the privacy policy around a notifiable data breach scheme that came in in February 2018. You should have a documented plan. You should be testing that plan.
Alisha ChristianYes.
SPEAKER_03That's what I'd leave you with.
Alisha ChristianWell, thank you. Okay, and um, I mean, you're always sharing things on LinkedIn as well. You're very active on LinkedIn with um giving different scenarios and um tips information, likewise with the Mercury IT LinkedIn. So if people do want to sort of stay more up to date, um please follow.
SPEAKER_03Absolutely. Agreed.
Alisha ChristianSee you again soon.
SPEAKER_03Thanks.