Ashley BELL
Welcome everyone to our CyberSmart Town Hall. For those I haven't met, my name's Ash Bell and I am the Assistant Secretary of Cyber Policy and Programs here in Department of Home Affairs. And my team and I are the policy leads for cybersecurity, but particularly around the government's 2023 to 2030 Australian Cyber Security Strategy.
Today it is our absolute pleasure to be providing you with an overview of the CyberSmart Program, which was announced by the government as part of the launch of Horizon 2 of the strategy, and an initiative that the team and I are really proud of in terms of the work that we've done and the consultation we've done with industry, but also the work that we have ahead of us as we look to design this scheme.
I'm joined today by Dan Phillips, who's our Director of Cyber Resilience.
And we also have some colleagues, I think, from ASD on the line as well, who will be around for Q&A later in the session.
Before we begin our town hall, I would like to take a moment to acknowledge the traditional custodians of the land on which I'm joining you from today, and that is the Ngunnawal people, and I'd like to pay my respects to elders past and present, and also acknowledge and welcome any Aboriginal and Torres Strait Islander people on the call today.
A couple of things for housekeeping.
Today's session is being recorded and transcribed and will be made available on the Home Affairs website at a later date. To ensure that this is a smooth session, all attendees are muted and cameras are turned off. But we invite you to post questions on Slido throughout the event, and you can refer to the details that are on the screen and we will obviously get to as many of these as we can as part of the Q&A, but if we have more questions than we have time for, we'll certainly take those away and look to come back to you. Please only use the Microsoft Teams chat for any technical issues that arise during the presentation. We'd like to keep all the questions on Slido. And where you can, if you can put your name and contact information on that rather than posting anonymous, helps us to kind of direct questions in the right way.
So, we'll get started because we have heaps and heaps to cover. I'm going to be providing a bit of brief context on situating this program of work in Horizon Two, but I'll zip through that because you probably heard that from me or my team before, but just to help bring everyone up to speed, and then we're going to really dig into the details of the CyberSmart Program as we have it now, and Dan will take us through all of that.
So, as I mentioned, for anyone that's joining for the first time or you're catching up via recording, hello in the future. This was built under the 2023 Australian Cyber Security Strategy, which was released in November 2023. The vision is simple, but ambitious and it's to make Australia a world leader in cybersecurity by 2030. This is about ensuring our economy and society can prosper and recover quickly from cyber incidents. Importantly, what we do under the Strategy is through the three separate horizons is to look at how we can take whole of economy policy reforms, programs, initiatives to uplift our resilience for everyone, whether that's small business, not-for-profits, individuals, critical infrastructure, government. We take a whole of economy look at cyber because cyber is a whole economy challenge.
The strategy itself is built around 6 shields, which each represent a layer of defence that keep business, citizens and government safe. As I mentioned, across the three horizons of the strategy, the idea is that at the completion of each horizon, we're able to look backwards and look forwards and determine where do we need to put our focus and do we need to pivot our policy response. How are those initiatives going, and we have done a lot of work in that space around both considering and consulting.
We started that consultation over a year ago. We spoke to you, we listened to you, we had round tables, we had town halls like this, and one of the things that came through very strongly was the need for in Australia for us to focus on the small and medium businesses and how we can really move from guidance and awareness into something more structural and that's where we're going to go today.
Under Horizon One, with your partnership and support, we delivered all 60 initiatives and then with the development of Horizon Two, we have been looking at policy interventions for what's next.
For Horizon Two, this has been shaped hand in hand with industry. We've had a lot of consultation. We had over 170 submissions from all across Australia, and a number of town halls and roundtables. So, for those that contributed, I want to thank everyone that did that through your formal submissions. We're very conscious that the most precious thing you have is time, and that time is being spent in the public interest is something that we're really thankful for. So, on behalf of my team and I, thanks.
We launched the Horizon 2, that was launched by Minister Burke on 11th of June, with the focus of targeted practical measures to make a real difference. In Horizon 2, we have 64 initiatives across 19 action areas with a delivery scheduled through to end of 2028.
There's three key objectives that most of the work fits around.
The first is around strengthening our people. So, this is about how our workforce becomes the strongest line of defence, or what the minister calls the human firewall. This is also about looking at not just the community, but looking at those that need support in terms of lifting up their resilience, and that's a big part of what we're going to talk about today.
The second objective is around protecting our critical infrastructure and government systems. Naturally, the place for government in terms of this is the big public service facilities, this is critical infrastructure we all rely on is a cross-sectoral elements.
And a lot of that work is being taken forward by our colleagues in the Critical Infrastructure Security Centre, but also, I know there's a lot of consultation going on at the moment around that work, which is very exciting.
And thirdly, it's around shaping and securing the technologies that Australians rely on every day. And really that’s about looking at things like secure by design, looking at where we can extend or expand standards, and making sure that the technology that we buy and use in our businesses every day is a minimum baseline level of security. But it’s also about looking to the future. Looking at the impact of frontier AI on the cyber mission, looking at what quantum will mean for Australian infrastructure and government services. So, it’s really looking at technology in a holistic way but also very much from a retail perspective as well, so, from the macro to the micro.
I’m not going to go through all 64 initiatives today as much fun as that would be, but I did want to just quickly touch on a few that we are highlighting in the context of what are talking about today, which is how we are supporting small entities.
So, as I mentioned, the feedback we received was quite unanimous around significant challenges to small business and medium businesses in managing cyber risk, and that the existing cybersecurity measures or guidance or material that’s out there doesn’t always necessarily fit for smaller entities. And so, the challenge I think has been for us is, it is such a heterogeneous group, small businesses, everything. But it’s also such a major part of the economy, such a huge employer. And in terms of time poor, there’s no one more time poor that a small business owner that is trying to manage a bunch of risks, run their business. So, we wanted to think about ways that we could make cybersecurity much cheaper, more invisible, kind of part of the fabric of the ordinary business and regulatory approach that small business take forward.
So, some of the initiatives that we will be working through in Horizon 2 are about building cyber awareness in the Australian workforce through supply chains, and taking lessons from the Jaguar-Land Rover incident in the UK around the impact that cyber-attacks can have, not just on a big entity, but actually the ripple effect on the supply chain particular small businesses. That’s what they unfortunately found out in the UK where a lot of those small businesses who directly sourced to Jaguar-Land Rover were basically shutted. And so, understanding how we can empower the workforce to be part of our frontline of cyber defence is a critical one.
The next one is driving uplift for the not-for-profit sector through our new community of practice and other support mechanisms, and I’ll come back to that one later because we have a launch event tomorrow which I’m hoping you will all join us for as well.
Weve got co design with industry with the security standards for consumer grade edge devices for use in small businesses as well as our launching labelling scheme that we are working on, and a shout out to our connected technology site next week which we will be talking about those initiatives. That’s a big piece around the technology that we use in our businesses and making sure that comes secure, rather than needing to have businesses be cyber experts as well.
And of course, of CyberSmart initiative which is what we are all here for today. I know you’ve been very patient while Ive set the scene. So, now it’s time to hand over to Dan, the man with the CyberSmart plan, who is our Director for Cyber Resilience, and he and his team have been working incredibly hard in terms of the design of this work, and I know are busting at the seams to get into it. So, Dan, what is the CyberSmart program?
Daniel PHILLIPS
Thanks Ash, and yes, a huge thanks to my team for putting this event together today.
The new CyberSmart program will develop a simple cybersecurity certification framework for small and medium businesses and not-for-profit organisations to help uplift their cyber resilience.
Once certified, organisations will be able to display a Trust Mark in their communications with customers, suppliers and the community. By promoting CyberSmart uptake through government procurement and regulatory levers, this initiative will also help to strengthen supply chains while keeping white tape at a minimum, those kinds of obligations imposed by businesses and other organisation s on each other.
As we develop the CyberSmart initiative, our objective is to ensure that we deliver a program that is, first and foremost, accessible – making cybersecurity uplift and certification simple to access for smaller entities. Making sure its affordable – making it a low-cost program accessible to everyday small businesses and organisations. A highly credible program – underpinned by trusted systems of accreditation, and a program which can scale rapidly to a national level.
The CyberSmart program has six main components that will support the certification framework. I will run through each of these with you in a bit more detail, then we can open up to some questions.
So, central to the program is a conformity assessment scheme. Schemes are established governance mechanisms that are used to manage assessment frameworks, like CyberSmart. It includes all the rules and requirements to ensure the program is maintained appropriately. Schemes are used across a range of industry sectors already that manage standards and assurance requirements, including areas such as food safety or building codes and things like that. The scheme will be a central component of the program and will provide a credible, transparent and nationally recognised certification mechanism. The CyberSmart scheme will be established under the authority of the Joint Accreditation System of Australia and New Zealand, JASANZ.
This is the internationally recognised authority for conformity assessments in Australia. Establishing A scheme under JASANZ provides the highest level of assurance through an independent accreditation framework. And the scheme will include industry representatives in technical and advisory roles to ensure that it's practical, trusted and fit for purpose.
CyberSmart will establish a flexible, nationally consistent cybersecurity framework for small organisations. It will give smaller organisations an achievable starting point, a clear pathway to stronger cybersecurity, and a trusted way to demonstrate their cybersecurity practices.
Cybersecurity standards will provide organisations with published sets of rules, guidelines, and good practises for protecting their digital environments from cyber threats. By leveraging existing industry standards, CyberSmart will remain adaptable and practical and relevant as technology and cyber risks evolve. The particulars of the standards, including associated costs and requirements and accreditation frameworks and things like that, are still the subject of ongoing consideration and we would certainly welcome ongoing engagement as we continue the development of the CyberSmart program. We'll soon be commencing an approach to market, seeking potential delivery partners and cybersecurity standards that are designed for smaller entities. We'll be seeking to implement a tiered standard, providing organisations with an appropriate entry point, recognising that organisations will have different levels of cyber maturity and face different cyber risks.
The appropriate tier can be selected based on factors such as their size, operating environment, and the level of risk that they face. This will allow smaller organisations to begin with practical foundational measures without being required to immediately meet standards designed for larger or more complex entities. By tiering the cyber controls and the requirements, CyberSmart can also be used to support supply chain security outcomes, with certified and smaller suppliers becoming more attractive suppliers by providing greater confidence so they can support the security and resilience requirements of their customers. Over time, levers such as government procurement and critical infrastructure supply chain requirements could also be used to incentivise small businesses to meet specified levels of cyber maturity through the scheme.
The CyberSmart Trust Mark will be the identifiable indicator for organisations to show that they are CyberSmart certified. Its design will be informed by industry consultation and international experience to ensure that it provides meaningful assurance without exposing unnecessary information about an organization's cybersecurity vulnerabilities. The Trust Mark can support certified organisations to easily indicate their commitment to cybersecurity to support contractual requirements and also supply chain confidence.
The CyberSmart Hub will be the primary web platform for the program. We'll be providing a simple, accessible pathway for organisations seeking to improve their cybersecurity and achieve CyberSmart certification. The Hub will be designed around the needs of smaller entities, those that have limited cybersecurity expertise, and particularly small and medium businesses and not-for-profits that otherwise can struggle to navigate the existing guidance and platforms that we have available.
It will guide organisations through the CyberSmart certification process with tailored, plain English guidance, and will support access to accredited certification bodies to assist with the certification program.
It will also contain comprehensive guidance that will support organisations seeking CyberSmart certification to understand and meet the requirements that will be defined in the CyberSmart standards. Guidance will be tailored to smaller organisations, include the use of multimedia and other methods of communicating to make sure that we don't simply stick to the one-size-fits-all approaches and make it easier for different businesses to engage with the requirements and understand what they need to do to meet different levels of the standard.
The department is also looking to enhance the existing Cyber Health Check tool, which no doubt some of you will have seen before, which we launched under Horizon One. It was released in October last year to provide greater functionality and support for organisations seeking to start their journey towards building greater cyber maturity.
Under the Horizon 2 initiatives, we'll continue to provide free self-assessment options through the Cyber Health Check tool for all small and medium-sized businesses and other organisations. But we're looking to do some further integration with CyberSmart to encourage organisations to progress from more basic self-assessment activities towards more formal certification. This integration will provide practical and accessible entry points for organisations who are really just starting out in terms of trying to build their cyber resilience and provide them with actionable advice which is tailored to the responses that they give through the Cyber Health Check tool questions.
I think those are those are the key elements we wanted to discuss today, so I'll pass across to Steve to facilitate some of our Q&A.
Steven BOARDMAN
Thank you both, Ash and Dan, for your presentations and to our audience for listening and all your contributions on Slido that I can already see coming through.
My name is Steve Boardman, Assistant Director of Cyber Resilience, and I'll walk us through the questions that we've already received on Slido.
And there is time still if you'd like to jump on and add additional questions. As you can see there on the screen, you can use that QR code or the link as provided. All right, we jumped straight into it. Our first question from Slido:
Is CyberSmart going to be mandatory?
And I'll throw this one to you, please, if I can, Dan.
Daniel PHILLIPS
Thanks, Steve. No, CyberSmart is not going to be mandatory. The idea behind CyberSmart is to provide something which is accessible to people through a voluntary certification scheme. But we recognise that, you know, organisations increasingly need to be able to demonstrate their cybersecurity maturity, whether that's to their customers and suppliers, the service providers, and to government and other partners in various circumstances.
So, CyberSmart will provide a simple and consistent way for smaller organisations to demonstrate their cybersecurity maturity. In certain high-risk environments, there could be cyber assurance requirements, which become mandated. And so there could be ways in which CyberSmart can be integrated based on the circumstances of those particular things, but the scheme as a whole is not going to be mandatory.
Our goal is certainly not to impose new compliance burdens or anything like that on small businesses, which have enough of those things to do already. Our goal is to provide something which actually makes that easier. To provide something which is nationally recognised and hopes to hopefully streamlines the interactions between different mechanisms that are already there. So that once the CyberSmart certification has been attained, it can be used in different contexts by the business that has got it. So, rather than having to repeat cyber risk assessments or questionnaires or justify their cybersecurity controls in different contexts, if they have the CyberSmart certification, they're able to use that as a way to cut through some of that. So hopefully reducing the need for multiple and overlapping cyber assessments and turn that into something which actually makes it significantly easier for small business to meet those existing burdens.
Steven BOARDMAN
Great, thanks, Dan. Next question from Slido.
Why CyberSmart and how is this different to the ASD Essentials?
And for that, I might throw to you, Ash.
Ashley BELL
Sure. Thanks, Steve. Look, I think there's a few questions around the connection to Essential 8 or the Essentials. And so, I'll kind of sort of take some of those together. One of the things we heard a lot from stakeholders was when it comes to existing standards for small businesses and medium businesses as well, things like the Essential 8 has a number of controls that are incredibly valuable and useful. But for the bulk of small businesses, for the majority of that are starting out their journey towards improving their cyber maturity, they don't translate well to their business.
Now, ASD has done an incredible amount of work working with small businesses and looking at their publications and of course, as the questions premised, are looking at evolving their Essential 8 into the Essential series. And so, we've been working very, very closely with ASD around those elements. But the place where CyberSmart is looking is what we've kind of called the step ladder between, you know, absolutely no controls, no awareness of cyber, what do I do to protect my business, all the way up to some of these frameworks like Essential 8 or NIST or whatever. So, the idea is it's actually trying to fill a hole around getting people on that roadmap, on that journey towards these sophisticated frameworks.
Also, for the majority of small medium businesses, it may be that some basic controls are all that's needed for them. So, the intent is to kind of cater for what we've heard from industry as a sort of a missing part. Obviously, there's standards out there already in the industry that are being adopted to fill that part. And I think what, as Dan explained, what CyberSmart is looking to do is to provide a kind of government mechanism and framework that will help support, encourage and work with industry on that. So, I don't think it's in competition, but it's certainly one that we are working with ASD to make sure that we have good alignment across government around what we're trying to do. Thanks, Steve.
Steven BOARDMAN
Thanks, Ash. Okay, next question.
What does accreditation mean in practise for self-assessed responses?
Dan, can I throw that one to you?
Daniel PHILLIPS
Sure, thanks. I mean, we think that having self-attested tiers is an important part of this program, principally to keep costs down in some areas where having full independent audits for days on end is probably not necessary for some of the things which we're talking about for smaller businesses. And self-attested tiers exist in similar established standards worldwide. There's other things which are equivalent in other countries and provide, cost-effective entry into schemes like this.
The requirements of the self-attested tiers will still be in development, but we're certainly looking to have rigorous process around what that looks like. And I think the key principle is that organisations should be able to access this kind of cyber assurance at a cost which is proportionate to the risks that they face. If every organisation had to go through an intensive audit, I think many small businesses simply wouldn't be able to participate. And that would be obviously counter to what we're trying to achieve here.
So, we're making sure that we still have a rigorous and robust framework in terms of our conformity assessment scheme, and we'll be setting those guidelines and rules in collaboration with JASANZ and making sure that we have that independent accreditation framework over the top, but hopefully in a way which makes this accessible for many small organisations that would otherwise be locked out.
Steven BOARDMAN
Brilliant, thank you. Lots of great questions coming in, so, encourage everyone to jump into the Slido. I might stay with you, Dan, for the next one.
What is the time frame for launching CyberSmart?
Daniel PHILLIPS
Yeah, obviously this is a huge amount of work which we still have to do to make sure we get to where we want to be with CyberSmart. At the moment, we're looking to have a pilot of the program in the second-half of next year. So that's where we're working to at the moment, working through what the full level of scheme design and everything is going to be with JASANZ and with other industry stakeholders. I'm hoping to start with a pilot. We're looking at probably a six-month pilot in the back half of next year, and then we'll be looking at a full national rollout in the following year.
So, that's roughly what we're working to, and obviously, depending on how the development process goes, we might be able to bring some of those things forward. But we do want to try and get some further communication about this out as early as possible. So even ahead of the pilot, we'll be looking to put out some additional information about the direction that's going so that people can start to prepare and start to think about the path forward for their organisation once CyberSmart becomes available.
Ashley BELL
If I could jump on that, Dan, I think key message that we want you to take away today is this is really sort of the kick-off part, right? Consultation on something like this is going to need your input, your advice about what will work, what won't work. The small business sector, it's so large and it's so diverse that no doubt, we need to hear from you. We need to hear from actual small businesses that are in the market, from cyber professionals that service those small businesses, from industry associations, from everyone. And so, when it comes to the scheme design, we've obviously got a policy objective that the government's asked us to deliver, but the way that we get there is the piece that we really want to talk to you about. So, we'll have contact details later on the end, but as it was with the Horizon 2 consultation, and I hope the team and I have built up enough cred with you to know that we genuinely want to hear from you, and we are listening.
So, please don't take anything here as it's all locked in and, well, this is just going to happen to us. That's not the case. And these schemes to be successful, they must be built together. And that's what we're seeking to do. So, I know that you hear that a lot from government, but again, I think our kind of track record on this shows we are absolutely keen to build this together.
Steven BOARDMAN
Great, thank you both.
There are a number of questions that relate to the standard and if a standard has already been selected.
I might just pass back to you, Ash, on that one if that's all right.
Ashley BELL
No, so that's the whole design of this, right? So, when we were looking at this as a policy part, just to bring you on the inside a little bit about how we developed this, but also the thinking.
The challenge we have is that there are existing small business tailored standards out in the market. There's a range of these, whether just as examples, you know, the ACE open case, SMB 1001, I think is mentioned in some of the questions as well. There are already those standards. And what we heard from stakeholders when we were asking this question about, well, would a government sort of backed standard for small businesses actually help? The thing we heard a lot was, yes, but we don't want just another standard or we don't want something that is going to just be imposed. And so that kind of set us down a path in terms of the policy design around this JASANZ framework and having that kind of open element of standards that could come in. I think that provides a few things which are really positive. So one is, flexibility around applying a standard that suits your business.
I'm hoping that they're going to be set standards that people will sort of gravitate towards, but it could be that there are certain elements of the small business sector where there should be or needs to be a bespoke standard for particular types of small businesses. And I think the benefit of this approach allows that to be captured as well. It also provides that agility and ability to for standards on there, but then for whatever reason, it's no longer being kept current or there's an issue that it's not sort of just one standard that's relied upon.
So, there's elements there around competitive kind of elements around how they apply. There's parts around there around it being applicable to niche parts of the small business sector, and also there's a transparency element around this, right? It's not about picking winners, it's about making sure that small business have a standard that they can use easily and then rely on as part of the system.
So, that's kind of the thinking and why we didn't go down the road of just picking a standard or making our own and just imposing it through a framework. So, that is a decision in terms of the policy decision. But, in terms of the scheme design and how those standards interrelate, what's required, what's the minimum baseline, all those things are part of the scheme design consultation that we want to do to make sure that what we are allowing in this framework works for small business and meets our policy objectives. So, definitely open for those conversations.
Steven BOARDMAN
Thanks, Ash. And I'll grab one here that flows off the back of that. And Dan, if I could ask you to speak to this one.
Is CyberSmart intended to be another standard in its own right, or is it a framework leveraging existing standards?
Daniel PHILLIPS
Yeah, thanks, Steve. And look, as Ash was just saying, we're certainly not intending to construct or impose a new standard. The CyberSmart in itself is not a standard. It's a framework that allows the endorsement and the leveraging of existing standards. So, continuing to encourage the innovation that's already occurring within private industry to put these things together, make them available for smaller businesses to uplift their cyber resilience.
And CyberSmart really is the layer over the top that can give people the confidence that this is an endorsed standard and that this is a suitable path for them to take forward. And also allow some integration with other government levers, such as procurement, things like looking at the SOCI regulations and things where there is a need for supply chain assurance that is being called out loud and clear and making sure that we have a suitable accreditation mechanism for that. So yeah, we're certainly looking to leverage the work and build upon the work that's already been done by certain prime companies in this space.
Ashley BELL
Just on that, and to qualify my answer before a little bit, we did build in a redundancy within the policy design as it went forward to government, which said, if there were no suitable industry standards, then we would need to make our own. So just to be clear, if there weren't any that were suitable, although, as I said, there's a lot in the market that are doing good work, then government could put one in, just to be absolutely clear.
Steven BOARDMAN
Great. Thank you both.
I'm seeing a question around the length of the certification. So, how long does it last for?
That's been upvoted a few times. So, I might pass to you, Dan, to talk to that please.
Daniel PHILLIPS
This is something which we're going to need to consider as we take the design of the scheme forward. I think we need to balance the competing requirements where we want to make sure that any certifications are kept up to date, make sure that they're credible and current and up to date with current developments in terms of technology and risks and things like that, but also not create a burdensome framework where continual reassessment is going to become too onerous for small businesses to maintain.
So, we're certainly keen to consult industry in relation to what is a suitable cadence for recertification. I think those arrangements will be put into place into the scheme once we've, you know, had that consultation. And I guess that is something that we'll be able to adjust over time if we feel like that it's not working well. That's part of the process that we want to have going through our pilot and the early stages of the scheme to make sure that we have tuned these things correctly.
So, the frequency and the types of the reassessment could also differ across different tiers from the higher tiers to the lower tiers, depending on how the tiers shake out.
That's something that we're going to look to consult further on and, as I said, try and strike that balance between keeping them current, but avoiding an unnecessary burdensome requirements.
Steven BOARDMAN
All right, lots of questions still coming through and we do have some time remaining, so please do keep them coming in. We'll try to get to them, as many of them as we can.
Ash, if I could pass to you one here that says;
What opportunities for the broader IT cyber industry exist in terms of participation and support around CyberSmart and is this planned and do you see this growing in the industry?
Ashley BELL
Thanks. That's a great question, because that's another wonderful piece of this policy work that we are excited about. What I'll talk about now is kind of a future set, but we are very focused on before we can run, we've got to walk and then before we do, we've got to crawl. So, we're going to do the work to set this up with you guys.
In terms of what does this do for the future and what are the sort of drivers and policy drivers for why we think this is a scalable measure that we wanted to put forward in Horizon 2, the big part of this, and this goes to a few things we've heard from industry around how the Australian small business sector is supported. This obviously plays into elements around the cyber workforce, plays into availability of cyber professionals, but it also talks about price points of things like insurance and the penetration of the small medium business market. It talks to other elements around how do people understand the cyber maturity of a particular small business or medium business. And I think the challenge is, it's quite expensive to do that in a way. So, we're hoping that through the CyberSmart and the Trust Mark, that will work together to essentially provide that kind of signal to the market.
I also think as small businesses engage with the standard as they engage with some of the steps and it kind of demystifies the sort of scary elements of cybersecurity and shows these are some things that you can do, pretty practical, pretty sensible things that can be put in place. Like I said before, it gets those small businesses onto a journey. They're starting to look at cybersecurity as a business risk like they would anything else, whether that's locking the front doors of their shop or whether that's getting flood insurance or whether that's many of the other elements that small businesses are already doing to protect their business and protect their livelihood.
We hope that then as they go through that journey and as they start to climb the step ladder, they will be demanding more from the market. And that will provide opportunities for Australia, a dynamic and innovative market to respond to that, like they do with many other parts. So, I'm hopeful that the cyber profession then will be able to build around that and start to provide services bespoke to Australian small business needs. So, I think there's an element here about sparking that demand and getting that attention and providing a solution to, oh okay, this is what I need to do. Now, where do I go to get that help? And I think that plays into the other component of the CyberSmart program, which is the CyberSmart Hub, where we're hoping to then build and co-locate all the information, but an evolution of the CyberSmart Hub, which we're hopeful for, if we can get the traction that we're aiming for, that will be a place to then demystify service offerings and products and things that will be really helpful to small businesses, but they don't know where to go. They don't want to get sold something that they don't need. You know, is that suited for me in Australia? Is that suited for me in this particular small business sector? And so, as we build this community through the CyberSmart Hub, paired with that, we're also hopeful that'll provide a platform for that to come together.
So again, these are down the lines. Let's focus on getting this step in the program set up. But you can kind of see the ambition that we're sort of building up as we go to say, through baselining and transparency and through this government endorsed standard, we're going to get small businesses on the journey, we're going to get that scale. And then from there, we are hopeful that it will provide opportunities. It will provide parts for the cyber industry to support, but also other parts. You can imagine insurers being able to write policies at a much lower cap level if they can be confident about the cyber maturity, banks could be thinking about business risks in a different way. There's probably a lot more things and exciting things that we haven't even thought of yet.
So, welcome those ideas from you as well, or innovative ways that we could leverage this program. We're always open to those kinds of ideas. At the end of the day, the mission is just about uplifting cyber resilience for small medium businesses. So, if you've got a clever way of doing that, or you can think of a particular connection within what we're doing, let us know. We're really open to those ideas. Thanks, Steve.
Steven BOARDMAN
Thank you. All right, we'll keep moving on. And to address a question in the chat, yes, we are monitoring the Slido and those questions that are getting some traction with the thumbs up and we'll try to get to as many of them as we can.
I see a group of questions that all relate to cybersecurity service providers and how it might work in terms of becoming partnered with government to certify SMEs and to issue Trust Marks.
Now, Dan I'll throw this one to you, noting that we are early in the development phase here, but perhaps you could talk to some of the theory behind that.
Daniel PHILLIPS
Sure. The idea here is to allow different bodies to become accredited as assessors for CyberSmart. And so, once the JASANZ scheme is up and running, to actually have an accreditation system there that allows for lots of different providers, small or otherwise, to be able to be involved in this scheme and to be able to conduct the assurance that goes across the certifications. Providers like MSPs and others will be critical in part of this digital ecosystem. Those that are already engaged with small and medium businesses, those that are there on the ground talking to them about their needs and their vulnerabilities and the things that they're seeking to achieve for their business. Those are the people that we want to be engaged with this program so that they can be the ones that go, yes, you're ready to look at a particular level of CyberSmart, you've got the controls in place, or where there are some remaining gaps and vulnerabilities, they'll be in a position to advise on what those businesses need to do in order to reach particular levels, depending on what their organisation is doing, their risk profile and their maturity and all those types of things.
So, I think it's definitely a significant opportunity for service providers in this space to be on the front line of CyberSmart with us and helping to raise the overall cyber maturity and cyber resilience of small and medium businesses and other small organisations across the country, because they're the ones that are out there doing these jobs every day. So, what we're hoping with CyberSmart is to provide a nationally consistent framework that would allow that to provide that level of confidence that at particular tiers or thresholds or however we end up crafting that, that the providers who are dealing with small businesses know what is suitable for the context with that small business or other organisation is trying to operate in.
Steven BOARDMAN
Thank you, Dan. Ash, I might come back to you off the back of what you were talking about earlier. One of the questions that's received a bit of traction in the chat is;
How does the government plan to prevent the Trust Mark becoming another meaningless sticker that doesn't really provide any buyers, any real measure of assurance?
Ashley BELL
Thanks. Appreciate the question, Corch.
So, look, we don't want the Trust Mark to be meaningless. There'd be no point in doing this. Part of the elements which Dan's already gone through in terms of the certification process, we need it to be robust, but at the same time, we can't go too heavy-handed in terms of how we calibrate this, because then it will become too expensive. If we require extensive audits against the standards, up and down, it's going to be cost prohibitive. I'm not even sure that it would be practically viable. And look, I know that's not what you're suggesting in your question, but part of this is thinking about what the right level of either self-attested accreditation or review, and then obviously the frequency of that certification commensurate to the risk that's there. This is a big part of what we want to do in our consultation.
So let me be clear, this is the piece where we need you to come and support us to understand how we calibrate that correctly. There'll be different needs, right? So, you can imagine that there'll be a particular, let's say there's a government agency that is procuring for particular types of services, and they're going to a part of the small business sector where you'd want it to be pretty robust. Now, you're going to want to have a level of accreditation or a tier or whatever that is very different from your baker down the road, who really, based on their risk and threat profile, there's a lot of the basics that they could do, and there's a lot of elements that they could do in terms of securing their kind of IT systems, but the products that they're using, the hyperscalers the Microsoft products, as long as they've got the stuff switched on, as long as they've taken some pretty basic cyber hygiene, they're not the ones that need to go out and have an audited part.
So, the Trust Mark then itself connects to what that maturity level is. So don't get me wrong, we have a lot of work to do together to understand and to best calibrate those. We'll have learning, we'll try and get it as good as we can get it, and then we will continue to refine it as we go forward.
The idea here is that we have a framework, that we have a central point to have that conversation, rather than it being set by a tonne of different standards and a whole bunch of certifiers or other places. The idea is we're actually trying to bring that together and then kind of anchor that within sort of the government component. So, we're all singing off the same hymn sheet in a way. But look, there is no point doing any of this if it's just going to become a meaningless sticker. We don't want compliance. Well, I mean, we do want compliance, but we don't want just empty compliance. There's no point to it. We wouldn't be bothered doing this, and it's not the policy outcome we want.
So, the answer to your question is we're not going to let it become a meaningless sticker because we're going to work together with you guys to design it in a way that it's not. And I'm very open to any feedback. There's going to be 100 different views of different ways that we could do this and we are going to listen to them all. We're going to obviously make a decision, so we do something, but this is one of the ones that I really want us to focus on as part of our consultation. So, if you've got good ideas on this, if you're passionate about this one, definitely get in touch with us. And thank you for the question, Corch, because I know it's something you're passionate about too.
Steven BOARDMAN
Great, thank you, Ash. Okay, we've got about 5 more minutes, so we'll try and fit as many of these in as we can. I've seen a few relating to insurance, which is great to see an interest in cyber insurance. Dan, I might ask you;
Will the insurance industry be engaged to ensure that CyberSmart certificates can have a positive impact on cyber insurance?
Daniel PHILLIPS
Yeah, that's certainly our intention. We're keen to engage with the insurance industry and other important parts of the cyber ecosystem. I think one thing which we've seen in other jurisdictions is where there can be connections between certifications and being linked to the underwriting process for cyber insurance. While we don't want to be intervening in the cyber insurance market in Australia, we are keen to work with the insurance industry on ways in which the scheme which we're proposing and the way in which the design of that is being put together can actually support what they'll be seeking to do in terms of cybersecurity certifications or other elements that form part of the scheme.
So that's certainly on our radar that we want to work with the insurance industry to try and get this integrated into as many parts of the economy as we can to make it as easy for small businesses and others to make the best use of the work they're going to put into CyberSmart.
Ashley BELL
And think of it like, again, I've used flood insurance as an example, but when the government releases those floodplains information, that allows a business to understand what their risk is. That allows them then to determine through market forces and through whatever is out there, to be able to get those products to help ensure their business.
In a similar way, what we're trying to do with CyberSmart is provide the framework from which small businesses are able to identify their cyber risk and then level them the treatment that they need to do, which we are hopeful then will allow for the insurance sector to then support small business.
It's also, to my point before, about increasing demand. So suddenly insurance elements might be a really cost-effective way for a small business to manage its cyber risk, once it's aware. That then will open up hopefully those opportunities. So, we do see a connection, but we are, to Dan's point before, very conscious that we don't want to be distorting the market or kind of connecting anything too formal. We will continue to look at the policy settings around insurance as part of our regular work, and we always welcome feedback on that, especially if you're seeing things in the market which aren't going the way you think they should.
Steven BOARDMAN
Great, thanks, Ash.
I'll throw straight back to you, Ash;
There's some interest out there for an in-person event, perhaps in Sydney, to further talk about CyberSmart.
Ashley BELL
Yes, answer is yes. We would love to do events. We'd love to do engagement. And if there are ideas that you have, if you're from an industry association, if you're from a chamber of commerce, if you've got a group of people, we want to talk to as many people as possible. If you've got an idea about events, particularly we can speak to and understand the views of small businesses directly.
That's one we're really open to. It's really challenging at the Commonwealth government level. You know, we deal in macro and scale for our policy work. So, connecting that to those individual small businesses and providing a platform to do that would be great.
Steven BOARDMAN
Brilliant. Thank you, Ash. Dan, I think we have time for one or two more. How about we go to;
How CyberSmart will support sole traders and small or micro businesses that want to improve their cyber resilience but may not need certification?
Daniel PHILLIPS
So, I guess this goes to part of the work which you touched on earlier in relation to the Cyber Health Check and the other initiatives that we have going. Certainly, at a very entry level, the Cyber Health Check Tool is useful for individuals, small businesses, sole traders of all kinds of small organisations.
But also, part of what we're hoping to achieve with the CyberSmart Hub is to make the resources available and have the guidance available, even if organisations ultimately don't decide that the certification is something that they need to pursue. So certainly, our intent is that CyberSmart will be useful in many different contexts and for organisations of all sizes, including sole traders, and that there'll be lots of value that they can obtain from the resources and the other materials that we have available, even if the certification is not something that they ultimately need. So, at different tiers, hopefully we'll have enough accessible guidance for different maturity levels and different organisational requirements for different businesses, and then everyone will be able to find the information that they need by going to the CyberSmart Hub.
Steven BOARDMAN
Great, thank you. Okay, time for one more, I think. Ash, if I could throw back to you; How does government see this being used in procurement? And will agencies or organisations be encouraged to recognise CyberSmart certification when engaging SMEs?
I think you spoke to this a little earlier.
Ashley BELL
Yeah, I did. So, as part of the policy decision that we've taken forward from government, the intention is to require a CyberSmart accreditation for Commonwealth government procurement. One of the things that we heard a lot from our consultation was, it's all good and well to have a standard or a guidance or a material, but how do you get small businesses to engage? How do you get them to pay attention? And I imagine there'd be a fair few frustrated CISOs on the line that are thinking exactly that. And so one of the elements that we've looked at is the government lever, because we want to uplift Commonwealth Government cybersecurity, and so we need to make sure that our supply chain is secure, much like we're asking for industry to be looking at their supply chain and small businesses and their supply chain and making sure that they're secure. The Commonwealth Government is going to do that and lead by example as well.
We also think that, given the amount of government contracts, that will also provide a strong incentive for small businesses to pick up the CyberSmart certification, particularly when it's so easy and cheap and wonderful. So yes, the intention is to link to that. And it's certainly an element that we will be consulting on how we do it so that we don't create undue regulation for small business. But to be clear, we do want to uplift our Commonwealth cybersecurity, and we do want to encourage uptake of the scheme. So, those are policy drivers that we are working towards.
Steven BOARDMAN
Brilliant. Thank you, Ash, and thank you Dan, for tackling so many of those questions. We have unfortunately run out of time.
And I might pass back over to you, Ash, now if I can, just to wrap us up.
Ashley BELL
Wonderful. Thanks, Steve, and thank you for coordinating the questions. We've got tonnes of them in Slido. We've been going through them all and the team's been kind of organising them all to get it through. So, we've captured all of those questions, which are going to be really important. So, thank you. Apologies if we didn't get to your question. I'll get to the details of how you can reach out to us, but please just e-mail your questions through to us. Like I said, we're very keen to talk.
Before I wrap up, I'd like to give a quick shout out to the launch of the not-for-profit Cyber Uplift Community of Practice, which is the first event tomorrow, online at the same time as today. QR code to register is on the screen. I saw this question come up around, what about not-for-profits? This is the part that we're doing it. Think of it like a TISN for not-for-profits. We're really excited about this. This is another one where we're really keen to build the community and to build our new ideas. And we're working with the ACNC on that as well. And word has it, maybe we might have a minister at the launch event tomorrow. So, you just have to find out tomorrow.
So, look, thank you all for your time and for the valuable insights, questions you've shared throughout your engagement through town halls, submissions, co-design workshops. That's what keeps us moving along. That's what keeps this strategy real and delivering for Australians. So, my call to action is keep co-designing with us. We want to make sure that we're engaged. If you have any other feedback around how we're doing that, what we can do better, we're always open to that as well. We really appreciate the opportunity to improve the way that we're engaging, but also how we're developing the policy. And of course, you've got some details here about how to be engaged. If you are interested in other parts of the strategy, Home Affairs website's the best place to be, or you can kind of monitor Home Affairs and the coordinator's LinkedIn. We usually put our events on those as well.
So lastly, I want a really big thanks to my team for all the work that they've done, both in the leading up to this, but also for the Town Hall. Thank you for your time, and I hope you have a great rest of the day. Thanks.