• About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • Disclaimer
  • Sitemap
Sunday, October 11, 2026
The AUSTRALIAN BUSINESS JOURNAL
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech
No Result
View All Result
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech
No Result
View All Result
Australian Business Journal
No Result
View All Result
Home Tech

Cyber Security Director Accountability Plan Draws Criticism from Major Companies

by Kamal Pranto
October 7, 2021
in Tech
0
Cyber Security Director Accountability Plan Draws Criticism from Major Companies

Image: Pexels

Share on FacebookShare on Twitter

The Australian government’s brand new plan to hold companies’ directors accountable for the failure to manage cyber security risks has garnered huge backlash and very little support. Many big guns of the industry, including Telstra, AWS (Amazon Web Services), L’Oreal Australia, etc have expressed their dismay with the proposed plan.

The plan was proposed back in July this year. It could possibly see an application of cyber security governance systems and liability standards to companies and directors. The standards may follow either a voluntary or a mandatory mode of execution.

At the time of the initial proposal, the government seemed to have favored the voluntary version of the scheme. They wanted to co-develop cyber security strategies with industry giants. In reality, this version sounded the more palatable one for the industry if a plan like this was to go through.

However, while completely rejecting the mandatory scheme, various high-profile organizations have also questioned the voluntary one. The main reason for that is the unlikeliness of particular cyber security directorial obligations to enhance board-level maintenance of cyber security risks. Also, these actions may inevitably lead to several conflicts of interest.

AWS’s Statement on the Cyber Security Plan

Amazon Web Services (AWS) in the Australia/New Zealand region have responded to the scheme in a critical way. They commented in a press release: 

“Mandatory cybersecurity governance standards or specific director’s duties will do little to improve [the] knowledge gap [of knowing that there is a risk and knowing how to address that risk. At its core, cybersecurity is a business risk and is already part of a director’s existing duties.”

Proposing an alternate way, AWS added:

“Instead, we believe company directors, senior executives, and other responsible officeholders need education and support to understand how to effectively manage their cyber security risks. A voluntary code may assist directors in making more informed investment decisions, but we caution against overly prescriptive codes that emphasize compliance with prescriptive technical controls at the expense of a holistic risk management strategy.”

Major Criticism from L’Oreal Australia

L’Oreal Australia, the cosmetics giants, took it one step further. They didn’t only reject the government strategy, they even asked for the protection of directors from several cyber security risks, including ransom demands, etc.

Jessica Amos, the legal counsel for privacy and data protection of L’Oreal Australia, suggested: 

“…that the government considers the introduction of safe harbor laws for directors and officers of companies that are the victim of a ransomware or similar attack and decide not to pay any ransom, where the company has acted reasonably with regard to its cyber security position.”

L’Oreal Australia’s official statement says:

“We believe that any measures taken by the government in relation to cyber security should consider the impact of penalizing companies that are themselves, victims of a cyber incident. Directors and officers are often placed in conflicting positions, whereby the crush of time pressure may push an interpretation of their duty to the company to force the payment of ransoms to avoid potentially disastrous consequences.”

What Did Telstra Have to Say?

Telstra, however, viewed the decommissioning of already existing directorial obligations as the cause of heightened cyber security risks. They also commented in a press release:

“Directors and officers of listed companies need to understand and continually reassess existing and emerging risks that may be applicable to the company’s business. These existing obligations and liabilities are sufficient and provide appropriate enforcement mechanisms. The generic (and principles-based) approach of director’s obligations provides an appropriate, and sufficiently flexible framework to assess cyber security risks and their appropriate mitigations.”

Later in the statement, Telstra suggested:

“We believe there is a role for government in producing clear guidance on how company directors should consider cyber risk and in developing some ‘best practice’ approaches to mitigating cyber risk.”

Apart from all the criticism, the government-proposed plan has gathered some positive responses as well. Some major tech players of the industry like Google, Facebook, and IBM (International Business Machines Corporation) have backed voluntary schemes. In fact, they stated their satisfaction with the flexible nature of the standards. They also think that the plan suits the ever-evolving nature of the cyber security realm. 

Amongst this modest support and all the diverse criticism, the future of the Cyber Security Director Culpability plan remains hugely uncertain.

Kamal Pranto

Kamal Pranto

Kamal Pranto is a versatile writer covering several topics in the realms of Tech, Entertainment & Sports. The Criminology major has exceptional language skills and is a master of current affairs. His unquenchable thirst for knowledge and new challenges has led him to research more and creating quality news content on a regular basis

Next Post
The 20 Australian Personal Development Experts and Coaches to Work With in 2022

The 20 Australian Personal Development Experts and Coaches to Work With in 2022

Please login to join discussion

Popular News

  • MyGov not working 2025

    MyGov Not Working? Here’s How to Fix It Fast (2025 Guide)

    0 shares
    Share 0 Tweet 0
  • 10 Australian Strategy Consultants Leading Change in 2026

    0 shares
    Share 0 Tweet 0
  • As Microsoft Exchange 2016 and 2019 Sunset, How Can Privacy-Conscious Organisations Future-Proof their Email?

    0 shares
    Share 0 Tweet 0
  • The 10 Australian Makeup Artists to Watch in 2021

    0 shares
    Share 0 Tweet 0
  • Australia Post Stamp Price Hike 2026 as Letter Volumes Hit 90-Year Low

    0 shares
    Share 0 Tweet 0
  • About Us
  • Contact Us
  • Terms of Use
  • Privacy Policy
  • Disclaimer
  • Sitemap

© 2021 The ABJ -The Australian Business Journal. All Rights Reserved.

No Result
View All Result
  • Home
  • Business and Finance
  • Entertainment
  • Entrepreneurs
  • Lifestyle
  • Marketing
  • Tech

© 2021 The ABJ -The Australian Business Journal. All Rights Reserved.