The U.S. has charged Ukrainian national Volodymyr Tymoshchuk for his role in the LockerGoga, MegaCortex, and Nefilim ransomware attacks that targeted over 250 American companies and hundreds more worldwide. The State Department is offering a $10 million reward for information leading to his arrest.
Australia has gone all-in on quantum, betting billions on PsiQuantum’s Brisbane facility while building alliances and spin-outs from Sydney to Chicago. With defence contracts, investor momentum and Five Eyes strategy at stake, Canberra’s gamble is to lead, not follow, in the quantum race.
A software misconfiguration in a Texas government online grant system has exposed the personal data of over 44,000 natural disaster victims. The breach, discovered in late July, revealed names, Social Security numbers, and financial information, highlighting ongoing security gaps in state systems.
Cybersecurity in Corporate Australia: ASIC's Strategic Push
ASIC's Cyber Pulse Survey 2023 shows a low cyber maturity score of 1.66/4, highlighting reactive approaches to cyber risks. ASIC calls for improved resilience, aligning with the SIX Shields Cyber Strategy 2030 and global trends for stronger cybersecurity practices.
The Australian Securities and Investments Commission (ASIC) unveiled the Cyber Pulse Survey 2023 in November, providing a critical evaluation of Australia's corporate cybersecurity posture. The survey revealed a concerning trend: with an average cyber maturity score of 1.66 out of 4, most organisations are reacting to cyber risks rather than proactively managing them. This assessment, derived from measures of governance, risk management, information asset protection, and incident responsiveness, signals a pressing need for enhanced cyber resilience.
ASIC's Focus on Practical Cyber Resilience
ASIC Chair Joseph Longo stressed the importance of resilience, advocating for regular and rigorous testing of cybersecurity plans. This stance is part of ASIC's larger mission to pinpoint and address industry-specific cyber vulnerabilities, guiding an overall improvement in cyber resilience. The survey's individual reports, received by 95% of participants, provide valuable insights for organisations to gauge their cybersecurity standing against industry benchmarks.
The SIX Shields Cyber Strategy 2030 and Regulatory Policy Evolution
The findings from the survey are pivotal in shaping both ASIC's and the Federal Government's strategic policies, particularly in light of the SIX Shields Cyber Strategy 2030. Endorsed by key figures like Clair O'Neill, this comprehensive strategy aims to enhance the security and handling of financial institutions, addressing emerging concerns in corporate Australia highlighted in the latest regulatory reports.
Guidance and Recommendations from ASIC
ASIC's report offers tailored guidelines for organisations, establishing a baseline standard for cybersecurity practices. These standards are expected to influence ASIC's future regulatory actions. Key recommendations include conducting risk assessments, establishing contractual obligations with third parties, identifying critical business services, and implementing advanced encryption and email security practices. The report, useful for both technology experts and leadership teams, outlines red flags and provides practical guidance for meeting minimum standards.
ASIC's and the U.S. Securities and Exchange Commission Parallel Regulatory Tightening
ASIC's regulatory expansion into cybersecurity was notably exemplified in 2020 with action against RI Advice for inadequate cyber protections, a case that set a precedent for future regulation. This expansion aligns with global trends, paralleling initiatives in the U.S. and emphasising the proactive management of cyber risks.
ASIC's ASIC's approach parallels regulatory tightenings seen in the U.S., underscoring a global trend towards heightened cybersecurity vigilance. Like its American counterpart, ASIC is placing increased emphasis on directors' responsibilities to proactively mitigate cyber risks.
In his address at the Australian Financial Review Cyber Summit, Longo warned of potential enforcement actions against boards and directors who neglect cybersecurity and cyber resilience. This stance highlights ASIC's commitment to an "active approach" in managing cyber risks, particularly concerning third-party dependencies.
Editor outlook
The Cyber Pulse Survey 2023 and the alignment with the SIX Shields Cyber Strategy 2030 mark a critical juncture in corporate Australia's approach to cybersecurity. This shift towards a more resilient, proactive stance is in line with global trends and reflects a deeper understanding of cybersecurity's importance in the corporate sector.
As regulatory bodies evolve their strategies, companies are encouraged to bolster their cyber defences and align with these new standards, ensuring protection against the dynamic and challenging landscape of cyber threats.
Microsoft 365 remains healthcare’s weakest security link, with breaches rising from 43% in 2024 to 52% in mid-2025. Patient data exposure, soaring costs, and AI-driven cyberattacks in Australia highlight urgent gaps. Policymakers face mounting pressure to safeguard data sovereignty.
Cyber incidents in the Asia-Pacific have surged 29% in the past year, with Australia facing major breaches at the University of Western Australia and Qantas. Manufacturing is the top target, deepfakes are on the rise, and experts warn the region is in a digital arms race demanding urgent action.
ASIO’s $12.5 billion espionage warning is more than a tally of stolen secrets. It reveals a national digital crisis. With 24 major spy operations disrupted and identity systems exposed, Australia’s critical infrastructure and social services face a growing risk of collapse from unseen cyber threats.
Singapore is responding to a cyberattack by UNC3886, a China-linked espionage group targeting critical infrastructure. Minister K. Shanmugam confirmed the threat is serious and ongoing, as the CSA leads investigations to protect national services from long-term disruption.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!