Australia faces a $15 billion bill to replace old government computer systems at risk from artificial intelligence (AI), a national security leader has warned, but departments will need to squeeze the cost into existing budgets over time and "wargame" cyber protections until they go offline.
Subscribe now for unlimited access.
or signup to continue reading
Save $100 + Bonus Tote
All articles from our website
& app
The digital version of
Today's
Paper
Crosswords, Sudoku and Trivia
All other
in your area
Home Affairs leaders are urging government departments to 'wargame' cyber security solutions as they wage a long, expensive retirement campaign for the government's legacy tech. Pictures The Canberra Times, Shutterstock
Australia's cyber security culture also needs a seismic shift, a digital security conference in Canberra heard Wednesday, moving beyond rules-based compliance to live drills that test how systems and staff handle an attack.
Public servants need to become "explainers in chief" for government on AI and cyber security, and take a stronger leadership role building defences for critical national systems, senior Home Affairs official Hamish Hansford told the conference.
Replacing legacy tech and building cyber security preparedness would be a "defining challenge" of the next five years, Mr Hansford said, with a wholesale overhaul of the government's legacy tech estate representing a "15, 16, $17 billion proposition".
A staged retirement across departments backed by a "wargame and test" cyber protection strategy was "a much more powerful proposition", Mr Hansford told the protective security and government conference.
He urged public servants to lay out risks and costs "in concrete terms to decision-makers" while justifying what legacy tech to replace first, and to avoid "add-ons" that would patch rather than strengthen cyber defences.
But departments would need to wear the cost of the overhaul, Home Affairs assistant secretary Commonwealth security policy Craig Bickell later told the conference.
"It's up to accountable authorities within the allocated budget to ... deliver their capability in accordance with their own priorities," he said.
Mr Bickell said a directive issued to agencies under the Protective Security Policy Framework last week to stocktake and plan replacements for legacy tech represented "a statement of intent" by the government for a cyber uplift.
The Protective Security and Government conference is hosted annually in Canberra by the Australian Security Research Centre and the Department of Home Affairs' protective security policy division, attracting some of Australia's top government cyber leaders.
Mr Hansford and Mr Bickell told the conference Australia's cyber security culture needed to change, warning adherence to rules needed to be backed with hands-on preparation for real-world breaches.
"Compliance tells us what should happen. Capability tells us what will happen. And in an incident or crisis, it's that distinction that matters," Mr Bickell said.
AI culture
AI had the ability to "super charge" cyber incidents, Mr Hansford told the conference, "finding vulnerabilities in record time that then targets our operational technology".
"I think the cultural question that we've got to ask ourselves is have we developed a tick-and-flick compliance regime, or have we embedded deeply a culture of change," Mr Hansford said.
Mr Hansford said Home Affairs would issue fewer cyber security directives in future, warning the department could no longer keep pace with the volume of risks, and instead focus on where its advice could improve defences.
"We've got to balance the ability of the system ... with the ability of people to actually pick it up and change," he said.
"The last thing we want to do is create a paper tiger, that people recognise the change, or recognise the need for change and then do nothing about it."
He said public and private sector organisations would also need to proactively prepare for cyber attacks to test the effectiveness of compliance and security measures.
"Some of the worst phone calls I get are from people in the middle of a [cyber] crisis," Mr Hansford told the conference.
"I would have loved to have had that discussion and simulation, in war games and exercises months and months before."
Mr Bickell said the test for government tech systems and processes would be how they operated while facing a cyber attack, and for public servants, how they responded under pressure.
"[Cyber security capability] is tested at 2 o'clock in the morning when a major incident hits," Mr Bickell said.
"In those moments, the expectation is not to stop operating until everything is perfect again. It's to keep operating securely, making informed risk decisions, putting alternative mitigations in place where needed, and documenting the decisions made under pressure," he said.
Defence Minister Richard Marles Thursday said protections for sensitive government data and critical national infrastructure were "being constantly probed", and required "constant attention", but said he had "a high degree of confidence" in cyber security agency the Australian Signals Directorate.
"Australia should have that confidence as well," Mr Marles said.
Head of the Australian Cyber Security Centre Stephanie Crowe later told the conference updates to the government's Essential Eight cyber security standards - mandatory for government agencies and many of its chief contractors and suppliers - would be released later this month.
The government's AI Safety Institute on Wednesday released new research with national science agency the CSIRO on AI oversight, including a new measurement tool to evaluate if an AI model's output is correct and if it is influencing its human users.
More from Federal politics
As it happens
Breaking news alert
Be the first to know when news breaks.
