EPISODE 47 – Cyber and the AI Threat with Michael Connory of Aphore Technology

In this episode of the Trusted Adviser Podcast, Rob Pyne sits down with Michael Connory, CEO of Aphore Technology, to explore one of the biggest risks facing financial advice businesses today. They discuss why cybersecurity has become a board-level issue, how artificial intelligence is reshaping both cyber attacks and cyber defence, and why many advice firms remain dangerously underprepared. Michael shares practical strategies for improving cyber resilience, explains why governance and staff training matter as much as technology, and outlines the steps every advice business should take before a cyber incident occurs.

 

LISTEN

SHOW NOTES

Topics Discussed

  • Cybersecurity for financial advice firms
  • Industry standards and frameworks (NIST, Essential Eight)
  • Impact of AI on cyber threats
  • Incident response planning and testing
  • Human factor in cybersecurity (phishing, passwords)
  • Why cybersecurity is now one of the biggest risks facing financial advice firms.
  • The gap between perceived cyber readiness and actual cyber maturity.
  • Why credential theft has overtaken software vulnerabilities as the leading cause of cyber breaches.
  • The Cyber Assurance Risk Rating (CAR) Program and the NIST cybersecurity framework.
  • Moving beyond the Essential Eight toward modern cyber governance.
  • The importance of policies, incident response plans, staff training, and governance.
  • Why phishing-resistant MFA is becoming essential.
  • Common cybersecurity weaknesses across financial advice practices.
  • How AI is changing both cyber attacks and cyber defence.
  • The role of Security Operations Centres (SOC) in real-time monitoring.
  • What happens during the first 48 hours after a cyber breach.
  • Regulatory expectations from ASIC, the OAIC, and the Australian Signals Directorate.
  • Cyber insurance, legal privilege, and digital forensics during incident response.
  • Preparing advice firms for the increasing volume of AI-driven cyber attacks.

 

Episode Highlights

(Timestamps are  approximate)

  • [00:00] – Introduction to Michael Connory and Aphore Technology
  • [01:49] – The three pillars of Aphore Technology’s cybersecurity approach
  • [03:50] – Why most Australian SMEs are far less prepared than they believe
  • [06:20] – Why phishing and credential theft now drive most cyber breaches
  • [11:46] – Understanding the Cyber Assurance Risk Rating (CAR) Program
  • [14:30] – Why cybersecurity assessments must be reviewed annually
  • [18:40] – AI-driven cyber threats and why the risk is accelerating
  • [20:20] – Should financial advice have an industry cybersecurity standard?
  • [21:30] – Why NIST is replacing the Essential Eight as best practice
  • [26:45] – The most common cybersecurity gaps found in advice firms
  • [30:55] – What phishing-resistant multi-factor authentication actually means
  • [39:20] – When ASIC becomes involved after a cyber incident
  • [41:00] – Managing the critical first 48 hours after a breach
  • [49:00] – Reporting obligations and digital forensics
  • [54:30] – How AI is transforming both attackers and defenders
  • [01:01:40] – How quickly firms can improve their cyber maturity
  • [01:02:40] – Practical actions every advice business should implement immediately

 

Quotes

  • “The core of who we are is a technology firm, but that foundation is based on cybersecurity.” – Michael Connory
  • “You’re more likely to get compromised by somebody sending you an email than through a software vulnerability.” – Michael Connory
  • “If in doubt, validate.” – Michael Connory
  • “People, process and technology all need to work together. You can have the best technology in the world and still get breached.” – Michael Connory
  • “The cyber community is moving so quickly that if you haven’t reviewed your systems within a year, you’re going to be in trouble.” – Michael Connory
  • “We prefer to ask for forgiveness rather than allow a hacker to get through.” – Michael Connory
  • “Do the forensics before you make assumptions about what has happened.” – Rob Pyne
  • “Policies, incident response plans, passwords and phishing-resistant MFA will put you well on your way to doing the right thing.” – Michael Connory

 

Key Takeaways

  • Most breaches (80%) come from credential compromise, not software vulnerabilities.
  • Annual cyber assessments are crucial due to rapidly evolving threats.
  • Having a real-time monitoring and alert system can prevent major damage.
  • Cybersecurity is now a governance issue rather than simply an IT issue.
  • Most cyber breaches occur through compromised user credentials instead of software vulnerabilities.
  • Staff awareness and structured cybersecurity training remain essential first lines of defence.
  • Annual cyber maturity assessments are necessary because threats evolve rapidly.
  • Moving to NIST framework provides a more comprehensive approach than Essential Eight.
  • Financial advice firms need documented policies, governance processes, and tested incident response plans.
  • Phishing-resistant multi-factor authentication significantly reduces credential theft.
  • Phishing and human error are the leading causes of breaches.
  • Real-time monitoring through a Security Operations Centre can identify and stop attacks before major damage occurs.
  • Digital forensics should always be completed before reporting the full scope of a cyber incident.
  • Legal privilege and specialist cyber lawyers play an important role during breach response.
  • AI is making cyber attacks more sophisticated, more personalised, and far more scalable.
  • Advice firms that improve their cyber maturity now will be better positioned for increasing regulatory expectations and the next wave of AI-enabled cyber threats.

 

Resources & Links

 

TRANSCRIPT

Rob (00:01.218)

Welcome Michael Connory to the Trusted Adviser Podcast.

 

Michael (00:04.949)

That’s Rob, excited to be here.

 

Rob (00:07.374)

Excited to have this chat, Michael. It’s not every day people would say they’re excited to have a chat about cybersecurity. but I am because I think most people listening would recognize it’s probably the greatest risk we face as a business. We’re all got our we’ve all got a compliance officer checking in on our AFSL compliance to see if we’re staying within the guardrails of Chapter Seven Corps Act and all the regulatory guides. But I think this one here, people do acknowledge is probably the biggest sneaky risk. And in fact, the risk is not plateauing, it’s actually accelerating. And we’ll talk about that today. So I’m keen to get into this chat. For a full disclosure, we work with you at Four Technology. You are our IT managed service provider and our cybersecurity specialist firm. So I just want to say that up front. But we really chose to work with you because of your deep expertise in this space and the work that you’re doing with other big AFSLs. So you’ve got domain experience that we really wanted to leverage for our own benefit. And so I’m really pleased that you’re joining me today. So we’ll share a lot about cyber and how to keep ourselves safe and for everyone listening, this is going to be a really meaningful episode with a lot of action items to take away. So before we kick off, for revisors that haven’t come across four technologies before. You work across cybersecurity, managed IT services and the Cyber Assurance Risk Rating Program, which you developed, with something like two hundred and fifty AFSLs. How do those pieces fit together in your business and what does a fall actually do for a financial advice firm day to day?

 

Michael (01:49.109)

Okay, great question. the first thing that we do, the core of who we are, we are a technology firm, but that foundation is based on cybersecurity. So assessment, insurance, incident response, understanding the existing framework and cyber training. The second component is that technical com area, the IT managed services, because we found that so many firms didn’t have the necessary expertise and a lot of the managed service providers, whilst they said that they understood cybersecurity every time we went in and had a look, we found that there was a significant gap. And the third one, as you said, is the the CAR program, the cyber assurance risk rating, which grew out of research work, which grew out of a requirement for AFSLs and other businesses to be able to understand where their cyber maturity is at any particular point of time.

 

Rob (02:49.058)

Yeah. We have like I said earlier, we have AFS or compliance officers that would check and do an audit on our ability to stay within the guardrails. But you’re really in this space of assessing how cyber secure a firm is. So it’s actually got parallels there, but more on the cyber side. And for listeners, excuse my throat this morning, I’ve got a bit of a scratchy throat. So I’m drinking a cup of hot tea. It’s a tea brand. I’m not sure what the brand was, but it was called Defence. It’s got Echinacea and Lemon and all sorts of things in it. So I’ll solder on and see how we go. Early on when you did your research you talked about having done research to see where businesses were at with their cyber security posture. It painted a very different picture to the official numbers that you were seeing published. The Australian Signals Directorate suggested around eighty seven percent of Australian businesses were prepared for a cyber incident, but when you surveyed roughly eight hundred companies, you found it was closer to two percent. What did that gap tell you? And how did that shape the way a four approaches this work?

 

Michael (03:51.197)

Yeah. Well, this was back in twenty eighteen. So it’s eight years ago now when we first started to do the research and we’ve done the research every year since. What we found was that a lot of organizations, big organizations focused on looking at the cyber maturity of enterprise businesses or large governments. So when we had a look at the Australian Signals Directorate research, a lot of it was ANZ, Australia Post, you know, these big organizations, these big enterprise organizations. That understood cybersecurity and really focused a lot of resources back at that time on cybersecurity and cyber maturity. When we actually had a look at Australia as an example, you know, there’s two million businesses across Australia. We had to look at 800 of those businesses. And out of those 800 small to medium businesses, and we really focused on the small to medium business. Nobody had an incident response plan. Those that did have an incident response plan had basically downloaded something small from the internet and never actually understood how to use it. And when we asked them what would be the first thing that you did when a cyber incident happened, they had no real understanding, no real concept of how to be prepared or what to do. so the research, and we saw this from, you know, back in the days from Telstra, from Essentia, from the Australian government, from other IBM, all of the research was focused on these enterprise organisations and their cyber maturity. And it never really looked at small and medium businesses across Australia or around the world.

 

Rob (05:36.653)

Yeah. Yeah, it was so the research just wasn’t the market we’re operating in. It was at the top end of town and you found something very different to what was being published by the Australian Signals Directorate at the time. So hence you stepped into this space and said, We need to, you know, build out our capability here and work in the small to medium enterprise space which is just so underprepared. And you’ve long argued from our previous conversations that the industry over indexes on this idea of patching, you know, patching on your Windows d instances and as vulnerabilities are discovered, the vendors of software send patches through for us to update. But the reality you said is that eighty percent of breaches actually come from credential compromise. Someone clicking on a link, handing over the username and password. Why do you think the messaging has been so misaligned and what should firms be focusing on instead?

 

Michael (06:21.896)

Yeah. It’s a really good question again, because when you talk to technology businesses, the biggest vulnerability within the software is their software itself. You know, can that software be exploited? All software is written by people. Well, these days, you know, AI is starting to write software, but historically software is written by people and people make mistakes and there are inherent vulnerabilities within those software products. What occurs then is that their technology partners are going, you need to update, you need to patch, you need to make sure that this is occurring. The other part about this was state-based actors and big cyber crime gangs, they would go after the large enterprises around the world. And also government, health, all of these organizations. And the easiest way for these state-based actors or big cyber gangs to get into these big businesses was to exploit the vulnerabilities in the software. So you could spend three months, six months targeting a business and getting in, and then you have full access to the system. That’s how it works. So again, everything was focused on big enterprise, everything was focused on how to manage and secure large organizations. But small organizations, they were sort of like, you need to patch, you need to patch, you need to patch. Now in 2026. Most organizations of our size, anything from one person up to let’s say three hundred people, most organizations have purely cloud based these days. Their finance systems are in the cloud, Microsoft Office is in the cloud, their productivity, you know, all their tools are cloud based. There’s a few that still have on-prem solutions, but most are cloud based. What happens here is that a lot of this software is managed in the back end by the technology providers anyway and they do update the infrastructures around the data centers to protect it. But for a hacker to come in, they’re not they’re they’re thinking, okay, Rob, we want to target you. They’re not going to look for a vulnerability in your system. What they want to do is they know that you’ve got, let’s say, you know, 60 staff, 100 staff, and they’re going to say, well if we send a phishing email to your 60 staff, we know one of them is going to click on it, regardless of the systems and structures and processes you put in place, one of them is likely to click on it. at the best end, we know it’s about five percent, at the worst end it’s about thirty percent of people click. And these days the phishing emails are like that. Again, some stats. The Australian Cybersecurity Centre last year received 47,000 calls from organisations needing help. Now, out of those only four percent had areas where patching was a major problem. And they were big issues. Don’t get me wrong, they were big, big cyber incidents. With the Office of the Australian Information Commissioner and the mandatory data breaching, again it’s four percent of all of the organizations that get breached through a software vulnerability. So everybody talks about patching, but you’re more likely to get compromised by somebody sending you an email because it’s easier for the hacker to have some of your staff members clicking on it and handing over their credentials and then the hacker just simply logging in.

 

Rob (10:03.916)

Yeah. I think people can relate to that too, because as you say, the it’s the the weakest link is really a human just who’s rushed, who’s busy, that’s kind of just trying to work through all their inbox and sometimes they’ll just click on a link without thinking for a second, hang on, this doesn’t look legit. and and the hackers are getting better.

 

Michael (10:20.212)

Just on that, the biggest challenge that we find it’s usually the senior executives that are more likely to click on the link, primarily because they get so many emails coming through. and a lot of it’s on their phone and so they’ll see the email that their iPhone or their s or their Android has made really pretty. So it looks legitimate, it looks pretty, it looks all okay, and then and because they’ve got so many, they just click on it, they authenticate in thinking that they’re doing the right thing. And within twenty four hours, their account has been complicated.

 

Rob (10:53.526)

Yeah, I have heard of other firms where that situation has been the case, where it’s the phone that catches people out. They’re in they’ve jumped in an Uber, they’re on their way from appointment to appointment, they check their emails quickly and they’re actually just, as you say, looking on their phone rather than sort of that stop sort of more measured response they might make if they’re sitting at their desktop. They’re actually just taking action on their phone. And I can relate to that because it’s gotta stop and give yourself time to think about whether this is legit when you and as you see if in doubt probably don’t take any action until you’ve got time to sit down and properly check it.

 

Michael (11:30.748)

Yeah, if in doubt, validate. But again, most people they’ll I’ll have a look at it, they’ll get a Docu sign or they’ll get a Microsoft link and they’ll think, Yep, this looks legitimate. It might even come from somebody you know because they’ve been hacked and you just click on it and away you go and you’re compromised.

 

Rob (11:46.947)

Yeah, indeed. Now, as I mentioned a moment ago, you now work with something like two hundred and fifty AFSLs and have close to two thousand practices a year at your peak. Walk us through the cyber assurance risk rating program, this the CAR Program. What does it actually involve and why would it be an annual cycle rather than one off assessment and why?

 

Michael (12:10.356)

Well, we think we believe it needs to be an annual cycle for a whole range of reasons. but essentially the CAR program is based around reviewing your organization through the lens of a global cybersecurity framework known as NIST, which is the US National Institute of Standards and Technology. It’s also, by the way, the same framework that ASEC really focuses on that the Australian Signals Directorate right now. If you have a look at their information security manual, it’s all focused on NIST. So we look at an organisation through this cyber framework. And there’s six areas there, you know, govern, identify, protect, detect, respond and recover. So when we have a look at the process, we don’t want to just look at your technology because you can have the greatest technology but still be breached quite easily. There’s three three areas that sort of cover that off people, process, and technology. And you can have the greatest technology, and if your people and your processes aren’t working, you’re still going to be breached. You can have great people and your technology’s there, you’re still going to be breached. If you miss out on the processes, you become very vulnerable as well, which is one of the whole governance pieces, which is one of the significant components. So the CAR Program is also about validating things in a live environment, in a real environment. So if we’re working with you, for example, we will take you through and have a look at your policies and procedures. Now, we’re not just looking for the document, which is easy to find. You could download a document. We’ve seen perfect policies and procedures. You know, somebody’s just literally downloaded them off the net, put them on the system and said, look. And we’re saying, okay, so who created these? Where are these? How have these been shared? How are these integrated across your business? If it’s just a standard document without any context, it’s not worth anything. It needs to flow through your organization. So we have a look at that in real time and we talk about that with the director because there’s always we always need to have a director you know a business owner within the review and their IT so we have a look at how it integrates the processes and and the IT.

 

Rob (14:32.13)

So the annual cycle, because things change, is that’s ’cause it’s you can do a one off assessment but…

 

Michael (14:36.732)

The annual cycle’s really Yeah, the annual cycle’s really important because things change. So two years ago, as a perfect example, we would be saying essentially you need to have multi factor authentication and you need to, you know, have strong password management. From a technical side, that’s the easiest two things to do. Right now, what’s occurring is hackers can now hack MFA and it’s very, very easy to hack MFA. So where so what you had two years ago or even a year ago is no longer valid now from a cyber threat perspective. You want to be able to have MFA that is phishing resistant, that is that your token, that little token that you put in that is released, is secure. Today, the other component is that because the threats are becoming more and more significant, more and more prevalent. One of the things that we are looking at and we’re recommending is utilizing your technology to be able to alert you in real time. Now, historically, Mike you know, if you had a Microsoft environment and something happened, there would be an alert that goes off, but nobody would ever look at it. The IT teams, you know, the business owners, nobody would ever look at it. It would just sit there until somebody comes in and says, we got hacked, and then you go, yeah, there was an alert. These days what we’re looking for is, and this is different from last year, we’re saying, okay, so if something happens at two AM in the morning, what systems and processes do you have in place to fix that or to communicate that immediately? Because a story we’ve seen, for example, a CEO sat down on a Sunday evening, opened up his email to be able to have a look at what’s occurring in the coming week, type in this particular instance, they had they were using Microsoft Teams calling. They had a Team’s voicemail on their system. They clicked on it. They had to authenticate into the Microsoft environment to read, hear it. There was no message. They thought, yep, somebody’s just called, left no message, and deleted it, shut down their laptop, and went to bed. Monday morning, the CEOs getting calls from a number of people saying, I think you’ve been hacked. And what occurred was that that voicemail wasn’t legitimate. It was actually a phishing email that was disguised as a legitimate email. And what occurred was when the CEO put in their username, their password, and MFA, that went straight through to the hacker, and the hacker then used all of that to be able to log in. And in this instance, the hacker then scraped all of the email addresses from the CEO’s outlook from their email. And then sent invoices to every single one. Now there were over a thousand in this instance. What occurs is that 990 of those individuals are going to say, yeah, no, we figured it out that it was a phishing email, not a problem. But 10 paid. and that’s the challenge, you know, 10 paid. And you know, if there’s a couple of thousand dollars, because some people, you know, they’re just focused. I get an email from a trusted source from a trusted place. It must be legitimate. So…

 

Rob (18:00.589)

Yeah. Yeah, it’s it’s I mean people can relate, I’m sure, that are listening that have actually had their own issue issues or have heard others that have gone through it and there are another couple of examples that are a bit bit scary. So I was actually reading an article

 

Michael (18:15.73)

Yeah. That’s that’s part of sorry, that’s part of the CAR Program. We actually look at it in real time. And if you’re not doing this annually, if you’re not having a look at your systems on that annual basis, the cyber community, the cyber threats are moving so quickly, especially with AI, that if you haven’t looked at it within, you know, that one year period, you’re gonna be in trouble. Right now, as an example, we’re a partner with the Australian Signals Directorate.

 

Rob (18:33.826)

Yeah.

 

Michael (18:44.466)

And a number of other intelligence agencies. We’re getting messages from the Australian government, from the Australian Signals Directorate saying in the next six months, because of AI, the cyber threats are going to increase exponentially. The number of cyber attacks are going to increase exponentially. This is one of the reasons why CAR is there to be able to not compromise cybersecurity, but we can help enhance the environment so as to protect against these upcoming threats.

 

Rob (19:14.092)

Yeah, I think that’s something that people can understand that AI with agentic capabilities, automation, there’s actually some the the threat profile is increasing and and I think this is something you flagged with us as well, to think that if you’re not getting ahead of this now, it don’t don’t assume you’re too small to be of concern or of interest to hackers because they’ll just not even have to think about you, they’ll just have the agents do it for them. So they’re pretty sophisticated. And I was actually reading an article by a professional planner. Simon Hoyle published an article in Professional Planner this week, and he was commenting on the discussion that was had at the Professional Planner Licensee Summit. It was over in the Blue Mounds, I think. And Matt Lawler, the CEO at Acumen, was calling for an industry-wide cybersecurity standard for financial advice firms developed alongside the regulator.You’ve said a fores approach effectively is the standard, you know, given the volume of your route and the CAR program you’ve developed. Do you support the idea of the formal industry standard and and your process w is what you think good would look like?

 

Michael (20:23.346)

I think that’s what good looks like. I think you need to have a cybersecurity standard across the industry. One of the challenges with ASIC, whilst they won’t ASIC have been very clear, they don’t want to endorse a standard at all because what happens is that once you endorse a standard and time changes, things move on. It becomes weaker, it becomes watered down, it’s not as strong. So they want to be able to ensure that the AFSLs in particular are consistently moving towards better, you know, having responsibility, having updated technology rather than, you know, sitting on a standard that might be two, three, four years old and is no longer valid in today’s technology environment.

 

Rob (21:12.15)

It’s something you said to me when we were first started chatting, as you said everyone’s focused on the essential eight, but the government’s recently announced it’s retiring the essential eight over the next two years and they’re moving towards NIST, which you prefer, and it’s exactly what you’ve been advocating for a decade. What is a shift to NIST change in practice as against the essential eight for a financial planning firm?

 

Michael (21:33.941)

Well the Essential 8 initially was based around an on-prem solution for more of an enterprise-based organization. And it is in one way focused, it was able to protect you. The stats were that it was able to improve your cyber protection by about 80%. Now we saw that as really weak. and we also saw that when we did research we had a look at and we did the research across the AFSLs and the practices and this was a couple of thousand. And we saw that based on where two thousand practices were, not one practice would reach the level one maturity level, which is the bottom of the essential eight, simply because it was too hard, too complicated. The language was far too technical, there was no real focus on being able to understand the maturity levels. People talked about it. Primarily because the Australian government said the essential eight is important. We must use it. If the government’s doing it, then we must use it. ASIC even saw that the essential eight wasn’t enough. You had to do more than have the essential eight or go down the essential eight path. NIST, on the other hand, and the other one is ISO 27001, which comes from, you know, British Standards, and the ISO standards. They’re both relatively the same. NIST is just easier from a language perspective. It’s easier from a business perspective to be able to understand and measure. The thing about NIST and moving from the essential aid to NIST is it’s all encompassing, encompasses those three different areas that we’re talking about. It focuses on process, it focuses on people, and it focuses on technology. And when you have a look at the actual framework, it’ll say it’ll ask you, and this goes into other conversations about risk management. It’ll say, okay, so what are your key assets? And it’s not what hardware you’ve got or what software you’ve got or you know, how many desks you’ve got. It’ll it’s, you know, how many, how many people do you have in X Plan? Or, you know, how big is your financial database? How big is your CRM system that you’re currently using? What information is there? And if you think about it from an AFSL perspective, the databases can hold tax file numbers, bank account details, you know, dates of birth, all of the contact details, all of the financial information of an individual. So though those databases are a considerable asset of the business. And NIST asks, okay, so you’ve identified this. The question is, how are you going to protect it? What risks? Okay, what risks from external, say from a hacker, what risks internally? You know, from somebody who might be malicious. Now, you know, people will say, yeah, but we don’t ever see malicious staff members. But we’ve actually over the last couple of years, we’ve seen a number of AFSLs come to us and say, Can you do a digital forensics on this staff member’s account for us? Because we think they’ve taken our entire database. so it is possible and it does happen. Against the hacker getting in and doing it. So how do you protect that? You know, you make sure that only the right people have access, you make sure that you’ve got great passwords, you make sure that you’ve got MFA if necessary, you make sure that it’s reviewed, the audit logs are reviewed, or you’ve got alerts if something happens. And that becomes your structure. These are the policies. Only the right people can have access to this. Only you have to use strong passwords. You have to have an MFA. And that protects your key asset. And then on top of that, it’s like how do you monitor this? What are you doing to monitor this? How are you, you know, what’s your what’s your risk threshold? Are you satisfied with this? Is this okay? And this goes back to the board. So ASIC right now we’re saying every board, every executive needs to go through this process and understand the risk of their business at a cyber level and be able to determine this and NIST enables that process.

 

Rob (25:52.045)

Yeah, I think that people listening would be probably surprised to hear it because everyone’s been talking about the Essential Eight for a long time. But that’s as you say, it was built for a different time and a different circumstance really and the NIST framework is much more relevant today. So, I think that’s a really useful bit of information that I think listeners will actually need to grab a hold of because certainly we were oriented towards getting that maturity level for the essential eight, but yeah, I think it was a bit of an eye opener when we spoke about that with you and and I’m sure it will be for listeners as well. But when you walk into an advice firm for the first time, what are the most common gaps you find? You’ve mentioned firms often see risk purely through the asset compliance lens rather than whole of business risks. what do you see most commonly the gaps in this cyberspace?

 

Michael (26:49.192)

The first gap is that there are no policies and procedures around cybersecurity that’s the first thing we see at that governance level and there’s no incident response plan. Now that’s improved dramatically. We’ve done a lot of work with AFSLs around the country. You know, we know that there’s two thousand AFSLs approximately around the country and we communicate with as many of those as we possibly can. Not all of them use us, but we share the data with as many of them as we can. So that’s a big one. Incident response and policies and procedures at that governance level. The next one is training. A lot of AFSLs, a lot of practices, they’ll say that we’ve done cybersecurity training, but they might only be the advisors, not the entire team. And a lot of the time the training can be a discussion around a board table, you know, hey look, phishing attacks occur, don’t click on a link. You know, don’t open it. If it occurs, please tell us. That’s not really training. That’s not structured understanding the threats, where they’re coming from, how to identify them, how to manage them effectively. That’s the people and process side and from a technology side, it’s almost it’s it’s really poor from our perspective and we’ve got to be very careful how we communicate this when we come up and work with somebody for the first time. Because when we have a look at password management, for example, almost I would say 92% of the time, 95% of the time, password management, everybody’s reusing passwords. everybody’s and we get a lot of feedback. Yeah, you know, the financial services firm that we have access to only provides us one user account, and therefore everybody has to have access. Here’s the one username, and here’s the password that everybody uses to access this one user account. We’ve seen, for example, X-Plan. I have a joke that X-Plan is the most loved, careful, you know, cherished application in the financial services industry, that people truly think that it’s you know the best thing that’s ever happened, and that it’s the most cost-effective, which it’s not. It’s very, very expensive for a small business. And what happens there is you might have a person who’s working in the business for three hours that needs to have access to X Plan three hours a week, and the cost of that license is seven thousand to ten thousand dollars a year. It’s just not a good return on investment. So individuals will share passwords and access because you know somebody only needs to use X-Plan for three hours, this person needs to use X-Plan for a couple of days. So suddenly, you know, usernames and passwords are shared across major critical assets. We hear it all the time and we understand it, but it’s not good practice. Because once somebody’s once you’ve given away the password, in a way you’ve given away the keys to the kingdom. The other part about it is that and this is the scary bit, right now, and this is not just across the AFSL industry, this is across all of Australia, that hackers can hack MFA.

 

Rob (29:50.946)

Yeah.

 

Michael (30:09.702)

And you need to be able to put in place appropriate technical controls to protect your business from that. And it’s not hard to do, but it is a technical solution. 99% of businesses across Australia, so out of the two million businesses across Australia, 99% do not have MFA enforced or use fishing resistant MFA structures. They simply don’t.

 

Rob (30:33.974)

Talk about that phishing resistant MFA because I think most people would be familiar with the need to have MFA and if they haven’t done that across their software then that’s a low hanging fruit that everyone should be doing. Almost all software these days has that capability to actually install MFA. but you talked about phishing resistant MFA earlier and just again then. Talk to me about what that looks like.

 

Michael (30:58.878)

Okay, so at the very, very top end, what you’re doing is you’re buying a little token like a UB key, like a USB device. You’re plugging it in and saying, okay, because I’ve got this device and I’m plugging it into my computer and I can authenticate through a fingerprint or whatever, the system will recognize it’s me and allow me in. you can use what’s known as conditional access policies. So you can actually set rules up within the Microsoft environment to be able to say, okay, so Rob, if you’re in Perth and suddenly somebody’s logging in as Rob in London, something’s wrong there at and therefore, let’s create an alert and let’s reset everything to make sure that if it is you, you might be using a VPN to to watch a soccer game or something like that or cricket. I heard from one person the reason I say London and this is one CEO who I was talking to who loves Snooker and actually said that they do use this solution to watch Snooker because the commentary in London is much better than the commentary in Australia. So they get around it, they use a VPN and away and away they go. But you can put in a conditional access policy. So you can say we don’t want anybody outside of Australia logging in. And if they are logging in then they have to

 

Rob (32:06.894)

Right, so they’re geo blocked from watching it on BBC Sky or something, so they use a VPN.

 

Michael (32:26.632)

Then they have to go through this process. so you can set this up. It doesn’t take long, it takes about 10 minutes for a conditional access policy to be set up. And in the Microsoft environment, a lot of them are already pre-done anyway. The challenge is that you have to have the right software to begin with. If you’re using Microsoft Basic or Microsoft Standard, there is no such thing as conditional access policies to be able to protect you. So you need to have business premium or the E3 or the E5 licenses that are to go down that path. And to become and that phishing resistant component, which is a which is frustrating for businesses, you need to have what’s known as entra P2 license. So it’s about $14 per user per month. So there is a cost there. But the reality behind it is if we go back, the biggest risk to businesses is credential compromise. And if you haven’t got phishing resistant software, you know, available, if you haven’t got phishing resistant MFA, you’re very vulnerable. And to give you an idea, we spoke to a hospital that has 10,000 staff. And we said to them, you know, they asked us to come in and have a look, and we said, You’re really good, except, you know, you can get hacked this way. And they said, We know. but if you have a look at ten thousand staff by fourteen dollars per person per month. For to protect us this way, we can get another hospital bed, we can get another MRI, we can hire another couple of nurses. so we’re prepared to take that risk. but most most industries, most organizations don’t think about it at that

 

Rob (34:07.842)

Yeah. So I just wanna just dig into this a bit further. So we’ve got a password manager and I can go into a security dashboard that shows me I have all of my passwords that none are reused and it gives me obviously a positive risk rating and we use that same password manager. It’s got the ability to go in and and it gives you the rolling six digit code when you’re logging into anything it’s referring you to go to a your password manager to get your rolling six digit code and that’s obviously just what most people would be using unless using Microsoft because they’d be using the dedicated app for that, the actual s Microsoft security app, similar with Salesforce, we use that and that’s it’s got our own dedicated app as well. What’s deficient there? In what way can a hacker access that password manager rolling six digit code that I’m actually using to authenticate myself when I’m logging into a platform.

 

Michael (35:09.204)

So that six digit code, what happens there is that even though it changes every 45 seconds or every minute, what it does is it basically tells Microsoft or DocuSign or Salesforce or whatever that, yep, you’ve got this code. This is your one time password, so it’s something special to you. And you can therefore release the cookie that says you’re authenticated in. So basically it’s saying. Because you’ve got this, release a cookie that sits on your system that says, we trust you. What’s happening here is that the hackers, when you’re doing that, they’re sitting in the middle. So it’s known as an attack in the middle or a man in the middle attack. And you’re putting your information into their system, and their system is putting the information into Microsoft. So because there is this middle layer that the information’s flowing through, if you put in that six digit code into that system, it still flows through to Microsoft or Salesforce. But then Microsoft and Salesforce will then open up everything and say, yep, we trust you, but they’re trusting the hacker and they’re trusting you at the same time. So you then get logged out or you get access to it. You might see that nothing’s there because you’ve clicked on a link and it doesn’t look like anything exciting. So you just shut the link down. But at that moment, the hacker has got that cookie. They’ve captured that cookie. They’ve captured that little bit of code that’s been released. Now, what you want to be able to do is you want to be able to say, okay, so this code that has to be released can only be released under these circumstances, that it’s attached to a specific device. Or it’s it attached to your IP address, your computer’s IP address, or your business’s IP address, that it’s, you know, that it’s attached to…

 

Rob (36:54.072)

Right.

 

Michael (37:04.078)

… you know, you’re in Australia at this particular point of time. And if all of these conditions are met, then yeah, it will release it. But if the conditions are not met, then it won’t release that cookie, that token that six digit code won’t release. And that’s where fishing resistance comes in because most organizations don’t use it. Microsoft is going down that path and our Salesforce is going down that path right now. There are ways of being able to do it. There is a small cost.

 

Rob (37:17.645)

Yeah.

 

Michael (37:32.625)

There is a technical solution, but if you think about your 60 staff that you’ve got right now and you are and all of them get sent a phishing email and one of them clicks on it and then they do the right thing by having MFA and an individual password, it can still get hacked. So these are the password management and an MFA are the two big things that c organizations are missing. The other bit that’s missing and it’s not a hard thing. Once upon a time, two years ago it was very expensive. These days it’s not. Let’s say that somebody does access your system, they do get access to your system at two AM in the morning. Who’s reviewing this access and what occurs? You’re asleep, everybody’s asleep in the business, your IT team’s probably asleep, you know. So who is actually going to be monitoring this access at two AM in the morning? When a hacker over in, you know, India or Ukraine or Russia or Korea or China tries to log in because it’s their business hours. You want a system in place that alerts you in real time and not only alerts you, but if necessary, can put a block on that account until everything is validated and verified. And that’s not a hard c solution these days. It’s a Secure Operations Centre, we’ve got a secure operation centre, we’ve got one for you. So twenty four by seven, everything is being monitored. Somebody logs in at two AM and it doesn’t and it doesn’t look right under any circumstances, you’re automatically blocked. We prefer to ask for forgiveness than allow a hacker to get through.

 

Rob (39:18.476)

Yeah. Yeah, absolutely. No, for sure, especially if it’s two AM in the morning. A lot of smaller firms tell themselves they’re too small for ASIC to bother with them because, you know, ASIC’s l looking at the bigger AFSLs in the market. Is that a dangerous assumption? And when does ASIC actually come knocking on the door of a firm? Do they come in proactively or are they only coming when something’s gone wrong and all of a sudden ASIC’s at your door?

 

Michael (39:48.947)

It’s generally reactive from what we’ve seen. So what occurs there is that if you have been breached and you have a legal obligation to notify and ASIC gets wind of what’s occurring here and there is an occurrence and ASIC begins to investigate, ASIC will come in. The investigation doesn’t matter what size you are, doesn’t matter who you are. ASIC, and not only ASIC, but there’s the Office of the Australian Information Commissioner. The OAIC that they can come in and investigate as well. and the investigation can take up to 12 months, and can take longer. and it’s a significant drain on resources. It’s emotionally taxing. It’s financially challenging when you’re under investigation. Because the first thing that these regulators will ask, they want to see all your governance, they want to see your policies and procedures, your risk, all of these things that they’re gone out, as I said, on May the eighth and said, You need to do, they’re going to ask for you to be able to demonstrate that. And if you can’t, then ASIC are going to suggest that, you know, you or allege that you haven’t followed appropriate cyber maturity or business processes and therefore you’re in breach of the corporations.

 

Rob (41:06.456)

Okay, so take us inside that first forty eight hours of a real incident. You’ve been there with firms. But at the beginning, or maybe called in because they’ve got a problem. You said the instinct is to treat it as a technical problem, that there’s been some sort of breach, maybe

 

Michael (41:19.774)

The first instinct is that there’s a technical problem. So the first thing that somebody might do is that they’ll call up, you know, they might get a phone call. You’re driving to work, you get a phone call and somebody says, I think you’ve been hacked. And you go, What do you mean? It goes, I’ve just received an email from you. Did you send an email? And you go, No, never send an email for this invoice. Yeah, don’t pay for it, I’ll have a look. So you’re driving to work, you call your IT team and you say, somebody’s just said that I’ve received an email. Can you check this? your IT team goes in and has a look and says, Yep, okay, we’ve been breached. Now, the first thing that tends to occur there is that the IT team wants to take over completely. And I understand that, and it’s natural for an IT team to want to be able to take over there. But more often than not, what the IT team does is they think of how best to manage this. And the way they think is let’s get rid of the hacker, let’s kick him out of the system and let’s remove any malicious links that are there. So they can do that and suddenly the hacker has gone from your system and all malicious links are out of your s you know, the software or whatever’s been installed there is out of your system. So your system is clean and fine again. And you think, great, that’s all handled, but what has been forgotten here is that you’ve got a legal obligation to report it to the OARC and maybe to ASIC. You’ve got a legal obligation to help and report it to individuals who might have been targeted. You’ve got an obligation to report it to the Australian Cybersecurity Center to be able to help them understand what’s going on in the world of cyber so they can help other organizations if it’s a larger attack. There’s a whole range of things that need to be done. And IT teams, they’ll kick people out, they’ll delete all of the evidence because it’s malicious, and then they’ll move ahead. Then you get investigated, and what occurs is the first thing will be, how did this occur? We don’t know because everything’s been deleted. You know, these are the things that occur. Now, the first thing that should occur is that yes, you block the account. Right? So you block the account, you make sure that the account can’t send invoices or malicious files to anybody or the hacker can’t come in and access it. But the reality behind it is the hackers have already been in your system. The hackers already probably scanned all of your emails and looked for keywords and took off and scraped all of the email addresses from your Outlook. So how do you find that out? How do you know what’s occurred? Who do you need to contact? You know, if you’ve got a thousand clients or ten thousand clients or forty thousand clients, you know, do you have to contact every single one of them now? Now an IT team will say, your email has been accessed, yes, you need to contact everybody. That’s not necessarily true. Right? You know, what email addresses, what emails have been opened, what has been downloaded, what has been looked at. If you can avoid sending out, you know, if you can avoid having to communicate that you’ve been breached to a thousand clients and those thousand clients believe that they’ve had all of their financial information compromised and they haven’t, you don’t want to do that. Right? You absolutely don’t want to do that. And we’ve seen that, you know, IT teams tend to want to communicate to everybody. You have to communicate to everybody because they don’t necessarily understand the laws, the reporting, the requirements, and they’ve never done digital forensics in their life.

 

Rob (44:55.085)

Yeah, of course.

 

Michael (45:13.372)

So you know we

 

Rob (45:14.222)

So someone has an issue. Okay, you’re the first person I call, so I call you first.

 

Michael (45:19.176)

So we’re we’re the first person you call and we then say what we want you to do is we want you to lawyer up. First thing we say, we want you to lawyer up. We don’t care who hears this, we want everything under privilege. Right? So anything that we find, anything that we discover, anything that we do, anything that happens is all under privilege because we want to be able to have a criminal if we want to be able to investigate this appropriately, securely in a safe environment without the world having to understand what’s available.

 

Rob (45:49.39)

And that would need to be a lawyer we engage, not necessarily our cyber insurance company who would have their own lawyers, who would represent the cyber insurer.

 

Michael (45:56.341)

Yeah. It’s good to have both if you can afford it. If you’re a small business, if you’re a micro business, a five person practice, a ten person practice, sometimes that’s just too much. So the cyber you know, and the cyber insurance lawyers are very, very good. They are exceptional. They’re at the top end of town, they’ve they know what they’re doing, they’ve been through this hundreds of times, if not thousands of times. So they know

 

Rob (46:22.957)

Yeah.

 

Michael (46:25.34)

All of the ins and outs are better than most people. And most lawyers that organizations have available don’t necessarily understand the cyber law and the requirements so much. So if you can afford it, great. Get your own to work in conjunction because you want to be able to protect the insurers will look after you most of the time unless you’ve done the wrong thing. And if you’ve done the wrong thing it’s sort of like driving drunk. If you’ve driving drunk and total your car. You’re not going to be insured. Same with cyber. If you, you know, if you’re completely lied to them about your cyber maturity and you’ve got nothing there and you’ve been hacked, they’re not going to, they’re not going to cover you. but a lawyer is critical because they will help make sure that everything’s done. To give you a couple of reasons why lawyers are really important. One of the things that we’ve seen in the past is like an individual being hacked and losing, and we’ve seen some horrific ones. So one was 350,000, one was 750,000. The largest one we’ve seen is 2 million. But let’s say they lose $350,000. They call up the financial advisor and say, I’ve been hacked, you’ve been hacked. I’ve been, I’ve lost this money because you’ve been hacked. Now you then have to investigate your entire environment to be able to ensure, to see if you’ve been hacked and to be able to look at it. And if you haven’t, you need a lawyer there to be able to also protect you. Because one of the things that people tend to do, and financial advisors are really big on this, is that they tend to say, I’m sorry, we will look into it. We’ll fix this. Let’s fix this for you. And inadvertently accepting responsibility when they shouldn’t. so the individual has lost $350,000, their financial advisor is saying, Sorry, we’ll look into this, we’ll fix this for you. And the individual says, Yep, it’s you who was responsible for this, give me my money back.

 

Rob (48:26.456)

Yeah. But until they really know. Until the forensics has been done.

 

Michael (48:30.324)

But until you really know it’s until you really know and it’s a really horrible thing, but again, and the lawyers will tell you this. The comment is this it w we will investigate. Until we investigate this and understand this fully, we can’t really comment. As soon as we know something, we’ll let you know.

 

Rob (48:48.172)

Yeah, for sure. And I think people who’ve been in the market with either Medibank Private or who else? Optus, there was a there was a bunch of cu

 

Michael (48:57.864)

Medibank, Optus, you know, lots of lots of organisations have been hacked. So

 

Rob (49:01.996)

have been hacked and so you’ve been on the receiving end of one of those emails, just just as you described. But on reporting as it stands, when we spoke earlier, you said a firm over three million dollars in revenue has thirty days to notify the office of the Australian Information Commissioner, the OAIC, where serious harm has occurred, and that’s a key distinction, where serious harm has occurred, with ASIC as a separate escalation, you mentioned the law is changing. What should advise firms be preparing for and is faster…

 

Michael (49:17.62)

That’s correct.

 

Rob (49:32.138)

Always better in terms of notifying.

 

Michael (49:37.287)

It’s a balancing act. It’s a really good question. It’s a real balancing act. So the Labour government wants to change the law so everybody has to report. So it doesn’t matter the size of the business. If you’ve been breached and somebody’s personally identifiable information has been stolen, you have an obligation to report that. That’s what the government is heading, that’s the path the government’s heading down. The legislation is due to hit late this year, early next year. So we don’t know if it will get through. We don’t know what the ramifications are at the moment, but it’s being proposed and it’s being put there. At the moment it’s 30 days. You don’t want to report immediately. I know the first instinct is to report, to be transparent, to be out there and to be honest and straightforward. The challenge with that is that you don’t know what you are until you’ve got a full picture, you really, you know, you might be blowing up everything. As my dad once said, you know, you’re boiling the ocean. don’t boil the ocean. it’s a spot trying to boil the ocean. and we’ve seen this again coming through the technology partners, the MSPs that are looking after somebody’s had their email hacked and they say, okay, so you need to report everything’s been compromised and then we find out, you know, a week later that…

 

Rob (50:38.55)

Or don’t try to boil the ocean.

 

Michael (50:59.782)

No, nothing was really you know, only two files were opened. Yes, all of these email addresses were seen and used, but it was used within the environment. Nothing was downloaded, nothing was synced outside of the environment. So you’ve got to be able to and under those circumstances, yes, you can send an email out to the thousand people that have received the email, please don’t open this, this is not appropriate. You know, we’ve had a cyber incident. If you’ve got any issues please, you know, contact your IT department. but if somebody if somebody, for example, downloaded SOAs or ROAs or, you know, a whole range of different documents and pieces of information that are in the system, then yeah, you have to look at it. And if you’ve got a thousand clients, you don’t want to tell a thousand people when only five of them have had issues. We had one where

 

Rob (51:51.416)

Yeah.

 

Michael (51:55.913)

We were on a New Year’s morning, so five o’clock on a New Year’s morning. I was really glad I was on call. I didn’t drink the night before, which was good. I got a call at five AM. somebody’s broken into the environment, somebody’s broken into our business, they’ve stolen the computer. It was a receptionist computer, there was a username and password on the computer because it was locked away. So we saw somebody trying to download all of the files. We’re able to stop that. We’re able to stop it in mid-action whilst it was occurring. and out of that, I think there were eight thousand or five thousand clients, out of that only five files got downloaded. And it’s much easier to deal with five files that were downloaded and five individuals than five thousand people.

 

Rob (52:43.874)

Just points to the fact that forensics is so important. Before you make any assumptions, do the forensics and find out exactly what has happened. So you’ve made that point well.

 

Michael (52:49.704)

Do the Yeah. And that’s and that’s the thing that the OAIC and ASIC will ask that you do the forensics. And one of the things that ASIC is communicating as well right now through the different court cases is that you need to have your audit logs or a seam in place. You need to have access to all of this information historically. So if something does happen, you can see and have a look at it. And if you don’t, that’s a challenge.

 

Rob (53:19.79)

Just clarify SEAM, you said audit logs or seam, what does SEAM stand for?

 

Michael (53:24.168)

can’t re I in all honesty I can’t remember the acronym but essentially essentially it’s all your audit logs it’s all every interaction that’s occurred put into it so a SIEM is a database of all your audit logs in one environment. So what occurs is that if you know it might come from your Microsoft, it might come from Salesforce, it might come from, you know, Zero and accessed into that environment under this one umbrella.

 

Rob (53:26.446)

Yeah. Right. Okay. How is AI changing the threat landscape? We talked about it a little bit earlier about how you can actually get agentic attackers now. It’s both a weapon for attackers but also potentially a defense as well. You raised the prospect of AI finding software vulnerabilities. When we spoke about it earlier, we talked about Claude’s mythos model that was released and then withdrawn, but the US government said no, you can’t release that. So because it actually had the potential to in fact I did, they didn’t release Mythos. Mythos was the one they didn’t release. It was actually just published to a range of sort of trusted organizations, whereas Fable was the released version to the public and Fable was withdrawn from the market. So what what’s AI doing to this threat landscape but also to the potential for us to protect ourselves?

 

Michael (54:41.67)

let me just check something here. So Fable, so Fable is now released again. Yeah. Yeah. So yeah, I’ve got access to Fable. so the reality behind it is that AI will enable a whole range of things to occur. It’ll enable people, individuals who don’t really have great skills to be able to be hackers very fast.

 

Rob (54:46.826)

It is. I know this.

 

Michael (55:08.776)

So people who don’t have real IT backgrounds will be able to write code and create code and create tools very quickly to be able to try to hack multiple organizations very quickly. So the Australian Signals Directorate have come out to us and not just us but to a whole range of partners across Australia and said within six months we’re gonna have a deluge of cyber attacks, not just from these new cyber attackers who can use the AI tools, but also the AI tools being used by cyber gangs and and more experienced to be able to refine their attacks much at a much more granular level. So they’ll be able to, for example, they’ll be able to go into an environment and say, they’ll, you know, something like ChatGPT, find the top 10 CEOs of AFSLs across the country. Provide me a biography of each of them and what they like and what they don’t like from their public statements and from their social media profiles and what’s on out there and then craft for me an email that they’re likely to open and click on that’s one. Another one is, and we did this not so long ago for an organization, this was a large enterprise organization. We said, okay, so using the AI tool, find every piece, find every job that this organization has done over the last five years and the technical requirements for every technical job that’s required, outlining the role, the technology that’s used. Also then go to the technology vendors, find out for me, you know, who’s made case studies of all of these that are publicly available and map the infrastructure for me. and then find for me the vulnerabilities, which we’re able to do as well within about two hours. 

 

Rob (57:11.478)

Yeah. You said you use the same tools that the hackers are using. You’re essentially operating in some ways you’re using what you know they’d be using against firms to actually test and help firms prevent those attacks. Is that right?

 

Michael (57:23.527)

Yeah. So we’re using a number of tools. and if anybody wants to check one of them out, I’ll give you one of them that we’re using. It’s called Evil Jinx, E V L G N X. and if you have a look and you Google Evil Jinx, you’ll see that it’s not available to organizations that could be using it for inappropriate measures but essentially it’s a very, very high level tool for red teaming for organizations around the world to be able to to hack anybody. And so we are so so we don’t simply just use Microsoft to send out a phishing email which will send you a phishing email and say, Yep, yeah, you’ve clicked on it. Here is a training course that you need to do. The tools that we use basically…

 

Rob (58:06.968)

Yeah. Okay. It’s

 

Michael (58:25.057)

… look at how we can make your organization compromised first and foremost? Can the email get through rather than Microsoft just sending it through? Can it get through? If it can get through, you know what are the systems in places that are where the systems are missing information to allow the email to get through. Once it’s clicked on, can we see the password, username and MFA? Are they working? If somebody’s clicked on it, what are the processes internally? So If somebody in your organization has clicked on a link, yep, if you know, has an alert gone off? you know, is it being reported to somebody? How quickly can your organization respond to this? Sending you a phishing email and saying, you know, it’s a you know, here’s a phishing email, learn from this, it’s not really looking at anything. It’s you know, and it doesn’t do anything. It doesn’t change the long-term outcome because people will still click. So do you have the processes and structures and tools around your people? Once again, people process technology to be able to ensure that you’re looked after.

 

Rob (59:35.085)

Yeah, you showed me this. You called it the Canary. The single pixel warning that appears if someone lands on a cloned Microsoft login portal. And that’s using that same tool. I I’ve just had a look at the website Evil Jinxia E V I L G I N X. Quick start guide for the people interested. But it’s helping businesses, as you say, put in place systems that even though you might teach them not to click that that could be in the car, they could be in their phone, they still go ahead and do it. So you’re putting in place systems to help the prevent…

 

Michael (59:42.716)

Yeah.

 

Rob (01:00:04.834)

… than from making that inadvertent click and releasing that information to a third party.

 

Michael (01:00:09.8)

Yeah. That’s one part of AI. The other part of AI is that the software vulnerabilities, the patching, that’s going to be significantly enhanced. Technology companies are now using it to protect their, you know, to enhance the security of their products faster. So people are using Mythos to make Microsoft better and to make Salesforce better and to make Oracle better and all of these pieces of technology. They’re using that techno AI tools to be able to do that. At the same time the hackers are using the AI tools to counteract that. So it’s like a game of chess. You know, one player does one, the other player does, you know, uses the next move to try to outmaneuver them. So it’s an ongoing thing. The problem with this, and it is an unfortunate side effect, is that IT companies and technology companies are going to ask individuals to reboot and update their systems more often…

 

Rob (01:01:09.122)

Yeah.

 

Michael (01:01:09.408)

… which is frustrating because if you come in and halfway through the day you get a message coming up saying, please please restart your system. A lot of people don’t do it in the middle of the day and then they forget about it later or they leave their system on and they don’t re they don’t update everything because it’s just it takes too long.

 

Rob (01:01:27.214)

Yeah. Yeah, people can relate to that I’m sure. I’ve got one more question for you, Michael, ’cause we’ve gone a good hour and it’s been great. I knew this chat would go for a while. One more question. For a firm that has an insurer but knows it hasn’t done enough on cyber, how quickly can they get to a level that ASIC would consider reasonably competent?

 

Michael (01:01:46.793)

We can do it depending upon the size of the business. So a small business you know, a micro business, one person to five to ten, we can help somebody get up and running and be fully compliant, so to speak, within a month without a problem. Act within a couple of weeks to be honest, for small businesses. Large organisations if you’re a hundred, two hundred, five hundred, thousand seat businesses, sometimes it’s like turning the Titanic. because you’ve got multiple you you’ve got potentially hundreds of applications across, you know, different business units and trying to pr look at what is the most significant it can take some time and in those instances three to six months to get things, you know, at that at the at the asset level that you would like them to be.

 

Rob (01:02:38.574)

As we’ve said a bit earlier, the Australian Signals Directorate has said if you’re not getting ahead of the curve now in six months’ time there’ll be a deluge of attacks because of the new AI capabilities that hackers have now got access to. So if this episode isn’t enough of a warning to take action, I’m not sure what would be. So do you have any final words of sort of wisdom to share with people to make sure they’re taking the right steps here, Michael?

 

Michael (01:02:54.206)

Yeah. The basic things are your policies, incident response plan. One of the things about incident response is that you need to test it. We haven’t covered that off. But ASIC and AICD, the Australian Institute of Company Directors, Australian Signals Directorate, they’re all saying and have communicated, if you don’t test your incident response plan, you are likely to be in breach of the Corporations Act because you haven’t done everything that you need to do. But it’s really more about making sure passwords, policies, MFA, and incident responses are in place. And if you’ve got those, you’re well on your way to doing the right thing.

 

Rob (01:03:51.767)

There’s some new things that I picked up in our conversation today and I’m glad we’re working with you to help us stay ahead of the threats that are emerging that are there now and continuing to to come at us. So I appreciate you taking the time, Michael Connory, for joining me here today on the Trusted Adviser Podcast.

 

Michael (01:04:10.302)

So I appreciate the opportunity.

 

Scroll to Top