Other Projects

The CSCRC builds effective collaborations between industry, government and researchers, creating real-world solutions for pressing cyber-related problems. We achieve this by identifying, funding and supporting research projects that build Australia’s cyber security capacity, across both technology and policy.

Some of our current projects are showcased below.

Live projects

Cyber-Buddy (October 2023 - November 2024)

Small Medium Enterprises (SME) are the soft underbelly of our economy when it comes to cybersecurity. With much of the economy and critical supply-chains heavily depending on their operations, government has targeted SME cyber maturity as a priority area. With much assistance, and advice already being available and frequently not taken up by SMEs, Cyber-Buddy focuses on the engagement of SMEs through technology. Nudging technologies, as used in fitness, health and learning apps, will be adopted to grow a pool of cyber-champions amongst the SME workforce and take SMEs on a continuous improvement journey. Impacts: The project team has developed a proof of concept to support the use of nudging technologies, this has been demonstrated to the Participants. A successful trial and focus group evaluation took place in July and in October 2024. The project delivered a proof of concept that would require further development into a widely usable platform for SMEs and individuals.

IoT Data Security and Assurance Framework for Intelligent Transport (January 2023 to November 2024)

The proliferation of the Internet of Things (IoT) in transportation has been a huge enabler for service provision by improving the safety and efficacy of transport systems. Provenance, trustworthiness, and assurance of IoT data processing and management are critical requirements for such systems. This project devises practical and innovative solutions to address some of the long-standing security challenges of adopting IoT in intelligent transportation. Impacts: Cisco is seeking to protect the generated IP through a patent and the team is building academic impact through an industry/academia focused workshop at the IEEE DSN conference in Brisbane, June 2024. The outcomes are scheduled to be presented to engineers from CISCO’s business units.

Ransomware resilient file safe havens for cloud data (October 2022 to November 2024)

Organisations lose control of critical data files due to unauthorised access, theft and encryption. In May 2021, ransomware forced the Colonial Pipeline plant in Pelham, Alabama, and JBS Foods, to stop production at multiple sites worldwide. This project aims to create a proxy solution and transform cloud storage into file-safe havens where files become resistant to ransomware and other unexpected encryption. Impacts: The project has delivered a working Proof of Concept that has been demonstrated to Terem and Office of Digital Government (WA). Terem is undertaking a market discovery and the Office of Digital Government is testing the solution for deployment in to the WA Healthcare sector although further testing is required. Further evaluation is taking place through Cyber NSW, and commercial interest is pursued through Phase Alpha in addition to Terem. The CSCRC has trademarked the project under the name “R3DWIR3”.

Socrates: Software Security with a Focus on Critical Technologies (November 2022 to November 2024)

Software forms the foundation for digital services. Despite the recent advances in software security, executives and experts are still puzzled by the question: Can we trust software coming into our organisation? The proliferation of AI and advancement in Quantum computing exacerbates the trust problem. This project has developed and evaluated novel technologies for software security assurance during the development, deployment, and maintenance of software systems. Impacts: The project has developed a proof of concept supply-chain vulnerability analysis tool for evaluation by Participants. TCS plans to evaluate the solution in their software development environment. A prototype for a machine learning model security and privacy testing tool (AI-Compass) has been developed and Participants are evaluating its utility. A Proof of Concept solution for Post Quantum Cryptography-enhanced Virtual Private Network (VPN) and DNSSEC (secure Domain Name Service) has been implemented in a prototype. The work package on law and policy aspect of secure software has made 9 policy submissions (one of which involved oral evidence before the before Parliamentary Committee on Legal and Constitutional Affairs as well as a written submission). A conference paper by the research team on “An Explainability-Guided Testing Framework for Robustness of Malware Detectors” won the SIGSOFT Distinguished Paper Award at ESEC/FSE 2023 (A* Core Ranking).

SCATES: Securing Critical Agriculture Technology and Emerging Solutions (February 2023 to November 2024)

AgTech aims for increased productivity and resilience of farming practices in increasingly harsh climatic conditions. However, using such solutions require cyber maturity with security skills to ensure resilient farming systems are supported by trustworthy data. This project is delivering integrated solutions for data, devices, and humans to improve cyber maturity at farms and their supply chains. Impacts: The project has run focus groups in NSW with farming communities. The team has developed a Prototype of the proposed virtual CISO solution and demonstrated to industry partners. The solution is being considered for commercialisation alongside Cyber Buddy and in the scope of Terem’s discovery work. A demonstration and potential trial has progressed through WA’s AgriStart.

Privacy Enhancing Digital Credential wAlleTs (PEDCAT) (April 2023 to November 2024)

Digital Identities are being deployed across Australia, for example through digital driver licences in NSW and other federal initiatives. However, the use of these identities carries risks to their owner’s privacy where identifiable attributes are disclosed unconditionally to a verifying party. The concept of Verifiable Credentials (VC) has emerged as a viable alternative to federated identity systems and can offer greater levels of control and ownership to users over their Digital Identity (DID). However, the inability of users to make optimal decisions in relation to use of VC leads to privacy risks. The project will deliver a digital credentials wallet (DCW) solution that incorporates novel privacy-preserving decision-making technologies for safe use of digital credentials. Impacts: The team developed a Proof of Concept and demonstrated to TCS’s head of financial and banking risk division based in Sweden and is adapting their solution based on the received feedback. The team reached out to Department of Finance and Service Australia to provide input to the TEx initiative.

ACDC: Augmenting Cybersecurity Defence Capability (August 2022 to December 2024)

Australia’s Cyber Security strategy 2023-2030 emphasises the need for cyber security exercises. Often these are walkthroughs of incident response plans or table-top exercises. However, it is rare for organisations to exercise the technical skills of their incident response (blue) team against a capable adversary (red team). ACDC delivers five technical exercises and augments technical abilities of the defending blue team using state of the art AI. The AI will work alongside human Incident Response (IR) teams enhancing their capabilities during fast-paced cyber incidents on a simulated critical infrastructure. The research is grounded in work on understanding human behaviour during cyber defence exercises and using attacker and defender behaviour models. Impacts: The project had developed a functional training environment for red-on-blue exercises using OT and IT simulated infrastructure. This has been developed in collaboration with three WA ports and the project partners, creating a significant knowledge exchange. Over 60 incident response professionals participated over three exercises including port operators. The exercises red-team attracted international participants from Limes Security (an OT specialist security company) and provided international visibility to the project. The project integrated and evaluated deception technology from partner Penten. The exercises provided large, annotated datasets that combine technical data and human decision making and situational awareness, now being used to train AI models. The final exercise has gathered significant interest from Participants such as ActewAGL.

Sharing Cybersecurity Data for Australian Research (SCReeD) (April 2023 to December 2024)

The CSCRC connects research infrastructure of Participants for experiments generating large datasets that would be beneficial to the wider research community. This project is creating a data repository and develop processes for collecting, storing, classifying, and providing this data while ensuring adequate protection and responsible disclosure of IP-sensitive data. Impacts: This project mainly is concerned with the future utilisation of CSCRC funded project data and will create value for our Participants in the long-term and legacy of the CSCRC.

Completed Projects

THRD: Threat Detection and Response with Heterogeneous Data Sources

This project was focused on using machine learning (ML) to standardise the threat hunting processes across data lakes. Cyber security organisations and their experts need to search through petabytes of real-world data collected over months across all customers operating various technologies to detect, locate, isolate, and mitigate stealthy and persistent threats. Hence, the project was aimed at supporting data analysts with threat hunting capabilities and speeding up the hunting process with higher accuracy across different datasets. Impacts: The CSCRC closed the project, as Participant ParaFlare exited the CSCRC. The research outputs and IP has been made accessible to the related Threat Hunting project and be assigned accordingly.

Cyber Assurance in Energy Systems for Security and Resilience (CAESAR)

Energy is a fundamental critical infrastructure, and Australia’s energy systems are fast evolving to become decentralised, consumer owned and managed by a number of diverse stakeholders ranging from individual households, to aggregators, suppliers and Original Equipment Manufacturers (OEM). This project looks at systemic issues and solutions that affect Australia’s energy security through a cyber security lens, identifying supply-chain risks, foreign ownership considerations and technical standards and compliance regimes that can over time reduce risks from consumer energy resources to acceptable levels. Impacts: The project has obtained datasets and support from e.g. the DER Cyber Working Group. The CSCRC is represented on Australia’s Consumer Energy Resources Reference Group and national standard bodies, directly impacting policy development and regulations. The project also informed standardisation efforts through Standards Australia’s IT-012 working group.

AD:EPT - Australia’s Data Emerging Privacy Preserving Techniques

Data privacy is a growing and significant concern that hampers effective data sharing by organisations for promoting societal benefits. This project has developed new methods to generalise our AI-enabled privacy-preserving data-sharing tool (OptimShare+, an outcome of the Personal Information Factor project) to support broader applications and data types. With the easy-to-use OptimShare+ tool, data privacy protection will become highly automated, more systematic (rather than ad-hoc), and consistent across different organisations. Impacts: OptimShare+ has been patented and prototypes have been evaluated by NSW Governments, and WA Department of Transport and their data-analytics teams. The CSCRC has completed a market discovery exercise with our partner Terem, moving now to trial with Horizon Power to demonstrate the value of the partnership towards a Joined Venture. In July 2024 OptimShare has won the Merit Award in Victoria’s AIIA iAwards.

TAPE: Threat Automation and Prioritisation of Emails

Security Operation Centre (SOC) teams receive a large volume of alerts generated from many connected cyber security monitoring systems. However, handling all these alerts leads to cognitive overload on SOC analysts, and could delay identifying critical incidents. TAPE aims to address this challenge by developing a novel autonomous email alert prioritisation system during triage which identifies and prioritises critical alerts that are part of malicious campaigns in a privacy-preserving manner. Impacts: The TAPE tool has been tested and deployed in WA’s Office of Digital Government’s SOC; its effectiveness is currently being evaluated by their SOC analysts. We demonstrated this to Aarnet and the project team is scoping adaptation requirements for Aarnet’s end-user evaluation (first customer). Our commercialisation partner Terem is starting their discovery process and demonstrations to other SOC providers are taking place to establish market value and opportunities.

Threat Hunting with Threat Augmentation using Azure Sentinel

Threat Hunting is a trending active defence method that detects new and existing threats on an organisation’s systems. There is a shortage of people with threat-hunting capabilities world-wide. This project leverages AI to identify existing cyber security threats and breaches, and augments existing threat information to create a threat-hunting platform that is accessible to SOC analysts to help compensate for the current skill shortage. Impacts: The software developed by the project has been security tested by Office of Digital Government SOC (WA) and is deployed in their environment. The team is now evaluating the efficacy and impact of the deployment in this operational environment.

RAAISE: Robust Authentication using Ambient Intelligence in Smart Environments

The RAAISE project uses smart technology and sensors to continuously identify personnel in their working environment. This approach strengthens an organisation's security and overcomes limitations and vulnerabilities of traditional authentication mechanisms, such as passwords or fingerprints, by continuously asserting a user’s identity through smart technology embedded in their environment. Impacts: The project developed a proof of concept (PoC) for the continuous authentication technology for four scenarios in a test-research space. The PoC has been evaluated by Tata Consultancy Services and the PoC will now be expanded to a prototype that is tested in a larger space with increased sensor coverage in Q3. TCS is planning to demonstrate the project outcomes to some of the Victorian based customers and is pursuing commercial developments based on the outcomes of the project.

Cyber Threat Intelligence in Distributed Energy Resources (DER) Systems

This project has established a dedicated cyber security research facility for DER at UNSW Sydney, enabling experimentation on the impact of vulnerable DER devices on an emulated power grid. The project has developed a dedicated Risk Assessment Framework, feeding into AEMO’s DER cyber security working group and technology, allowing operators to scan potentially vulnerable DER components, such as smart inverters. Impacts: The project has established a test-lab for DER cybersecurity at UNSW. It was the basis for some of the technical research underpinning the CSCRC’s “Power Out” policy paper highlighting the risks to Australia’s energy systems through Consumer Energy Resources and their supply chains. This paper was referred to in Budget Estimates and sparked a series of initiatives across Australia. Aligned with the project the CSCRC has been leading, the Distributed Energy Resources Cyber Working Group on behalf of DEIP/ISC, bringing together stakeholders across the Australian Energy Market and international partners, including collaborations with the US through the SunSpec Alliance, and the UK’s Figure forum in collaboration with UK Ofgem, generating international visibility. Participant Jemena is evaluating the use of the risk-assessment tool developed in the project as part of their processes.

SAARACI: Secure and Authenticated access within Critical Infrastructures

This project has developed a resilient authentication approach to manage access to remote assets in critical infrastructure. Infrastructure assets can become isolated due to communication outages, and prolonged disconnection can impact on the ability of systems and users to authenticate. The outcomes of this project provide resilient authentication in the light of communication failures. Impacts: The project delivered a proof-of-concept authentication solution using a Proof-Of-Possession approach, aligned with IETF standards (RFC7519 and 8725). The PoC has been evaluated by Tata Consultancy Services (TCS) and IP protection through a patent is in progress. TCS is seeking to utilise the project outcomes and further develop and integrate the technology in their TCS IoT Platform (TCUP).

PPTA: Privacy Preserving Text Analytics

The use of text data (e.g., medical records and emails) for analytics is rapidly becoming a standard with Natural Language Processing (NLP) advancements. However, such text data contain or is often linked with sensitive private information. Hence, privacy preservation of text data is essential before sharing or releasing them for analytics. In this work, we are developing a text data-sharing platform, called PPTA, that uses advanced techniques to enforce privacy on text data while preserving their utility. Impacts: Impacts for PPTA are at this point mainly academic. Commercial opportunities evaluate PPTA in the context of AD:EPT.

Executive gamification for cyber security - Game board production (Phase 2)

Executive gamification for cyber security builds cyber security awareness on a corporate and executive level, to instil a deeper understanding of the technical, operational, and strategic implications of cyber security related decision making at an executive level. This project broadens the application of the Phase 1 ‘Table top gamification for executives’ deliverables with the intent to produce a licensable game board product, including more scenarios and sector applications. Impacts: The first project output is the Corporates Compromised cyber security simulation. The CSCRC trademarked Corporates Compromised across five categories in Australia, US, Europe and India. Corporates Compromised is still being validated in the market, with the CSCRC having earned income through licencing and training delivery and available through www.corporatescompromised.com.au Wider impact of Corporates Compromised is that the CSCRC has agreed to collaborate with the European Union to develop a variant for a Diplomat’s Edition supporting the Australian Cybersecurity Strategy, Shield 6. The CSCRC is working with Limes Security (Austria) on a translation to the European Context (NIS, GDPR) and German language. Through ECU and TCS, the CSCRC is exploring a roll-out to India, with the game being demonstrated during a delegation to Chennai (Tamil Nadu).

Cyber security curriculum in WA primary and secondary schools

A working group has been established to advise the Western Australian Government on future curriculum expansion on STEM and to help improve the state and national curriculum on cybersecurity in primary and secondary schools. Impacts: The project mapped the WA curriculum and run consultative workshops in WA with over 80 organisations. Briefings have been provided to WA Ministry of Education. The CSCRC has trademarked the developed CyberLicence approach for school teachers and is exploring investment and commercialisation options with the project partners. The project has been successful in disseminating its findings widely through national media. The CSCRC is assigning the IP and Trademark to ECU to continue this activity.

Examining opportunities and constraints of civilianisation for enhancing law enforcement cyber capability in Australia

This project focusses on the challenges for policing organisations caused by rising cyber crime and the increasing sophistication of it. International research highlights that police organisations are struggling to respond to cyber crime and identify their role when it comes to preventing and responding to incidents. The project assesses the opportunities and constraints of civilianisation for enhancing law enforcement cyber capabilities in Australia. Impacts: Significant knowledge transfer from international partners informing AFP policy and strategy for policing. The CSCRC is preparing a more detailed impact case-study for this project.

Cyber Strategy for Boards

Boards and directors of companies must consider the importance of cyber security governance, risk and compliance is when considering their obligations. Specifically, in the event of a cyber event, boards and directors could face civil action for failing to ensure reasonable steps are taken to ensure adequate cyber defences. The implementation of cyber security strategy tools will support boards and ensure that reasonable steps are taken in relation to cyber risk. Impacts: The outcomes of this project are intended as a public good and made available freely. The materials sit alongside the Executive Gamification project (Corporates Compromised™) and bridge the Corporates Compromised simulation and the Cyber Security Implementation Planning (CSIP) tool. A pilot has run with NSW Department of Customer Services for March. The Office of Digital Government (WA) is planning to use the materials in their cyber security uplift program for the state.

Whole-of-Government Cyber Benchmarking

Government departments play a critical role in the handling and management of data and are trusted to make decisions based on that data. Data protection and security is vital in terms of the public trust vested in the department. Measuring and benchmarking cyber security capabilities can help departments identify areas that could pose future cyber security risks and pinpoint opportunities to effectively elevate the cyber security capabilities across the NSW Government. Impacts: The team surveyed all of NSW Government and established a baseline for their cyber security maturity. The developed results and tools are used by NSW Government to guide policy and investment.

Supply Chain uplift for Critical Infrastructure SME provider

Working with Home Affairs, this project delivered easy-to-understand guidance on the cyber security uplift of SMEs. It provided the ‘who’, ‘what’ and ‘why’ that SMEs need to know when providing services to Australian critical infrastructure. Impacts: The final report has been submitted to Home Affairs.

Cybersecurity in Digital Agriculture

This common good project was a pilot to the CSCRC’s wider activity in the agricultural technology space. The project clarified and investigated challenges in the secure use of digital technologies in the agricultural supply chain and engaged with key stakeholders, including the Food Agility CRC and CSU’s digital farm operation. Impacts: This pilot project surveyed cybersecurity challenges in the food and grocery sector and led to the development of SCATES project.

POKAPS: Platform for Compiler and Kernel Augmented run-time software Patching as a Service

Many software patches are so significant they can only be applied when IT systems are not functioning, disrupting users, and adding cost for businesses. Our researchers developed ways to apply these patches to 'live' systems, so the infrastructure was kept secure without disruptions. Impacts: The project developed a prototype for dependency analysis in patches and deployed to South Australia Health in an operational environment. Auxiliary analysis tools proved to be useful to Quintessence Labs for determining library dependency and usage statistics for the purposes of establishing Virtual Machine attack surface and size optimization.

Smart deployment of IoT at smart airports: Making smart airports safer

Smart devices connected to the internet help enable airline passengers to move seamlessly through Australian airports. We researched ways to make air travel more secure by automatically discovering and neutralising vulnerabilities in these devices. Impacts: The main innovation is being patented with support of Tata Consultancy Services (TCS). Several demonstrations were made to TCS stakeholders and potential commercialisation pathways within TCS explored.

Making future defence bases safer and smarter

'Smart' bases, that operate using a series of interconnected devices and operate autonomously of satellites, will be vital defence resources in the future. However, interconnected devices are vulnerable to cyber attack and defence could be targeted. Our research investigated ways to help ensure these devices can be made safer by identifying and fixing vulnerabilities. Impacts: The project outputs were integrated and deployed in two ADF exercises at the coast of Adelaide, Industry partner Cisco evaluated the outputs and decided not to proceed with commercial exploitation.

Deception as a service

Organisations sometimes use decoy files to lure and catch malicious actors. Our research helps automate the production of this deception technology, ensuring decoy files always look convincing and can be produced affordably and at scale. Impacts: The main outcome has been patented and assignment is under negotiation with the project partners. Earlier work has been open sourced and implemented/adapted into Penten’s suite of products. The project won the runner-up ACT iAward 2023.

Artificial intelligence smart shield to prevent email phishing

Cyber infections and financial losses are growing as email phishing becomes more sophisticated. This project developed a 'Smart Shield' utilising machine learning and artificial intelligence so system owners can stay one step ahead of phishing scams. Impacts: Technology has been patented and significant science outcomes in leading journals. The prototype has been deployed and tested and the IP is further developed in the TAPE project. The project won the NSW iAward 2022.

Automatic tracking of access privileges

Staff in large organisations often need standing authorisations to access sensitive information, but when they leave or change roles, IT administrators do not always know to revoke access. Our researchers developed automated tools to revoke access, which will protect sensitive information. Impacts: The project outcomes have been evaluated and used in NAB’s operational environment and supported NAB with significant knowledge transfer and insights into their identity management processes. A prototype was integrated in their operational environment and evaluated as part of NAB’s IAM processes. Ultimately the project provided guidance in their procurement of their new IAM solution.

Automatic Assessment and Protection of Personal Information for Data Sharing

Data sharing creates tremendous potentials of innovation in service delivery and economic efficiency. However, personal privacy is a big concern that hampers effective data sharing. This project developed automated tools that facilitate privacy-preserving data sharing. Impacts: The outcomes have been used to analyse NSW Covid’19 datasets prior to release. Some outcomes have been open sourced and others have led to the follow on project AD:EPT. The project won the runner up in the NSW iAward 2022.

Detecting Anomalies in Key Management Systems

Large scale enterprise networks often use enterprise key management (EKM) platforms for unified management of encryption keys. Monitoring access and usage patterns of EKM systems may enable detection of anomalous (possibly malicious) activity in the enterprise network not detectable by other means. Impacts: The project led to some knowledge transfer between Quintessence Labs and QUT academic staff.

Development of Australian Cyber Criteria Assessment

This project promotes Common Criteria among stakeholders in IT security products related to specification, development, evaluation, certification and approval, procurement, and deployment. The project focussed on authentication technologies and encryption systems and developed a number of relevant Protection Profiles according to Common Criteria for these technologies and identify adoption barriers. Impacts: The project led to the establishment of a Common Criteria profile for Key Management Systems. It created closer collaboration between Quintessence Labs and ACSC. The project won the AISA 2022 best project award. Participants fed back that this is an example of a project that would not have been possible without the CSCRC.

Data ‘Sharing’: Clarity in Contracting

This project produced clear guidance to government and industry, identifying the problem and explaining how data sharing agreements can be drafted to better align with parties’ and regulators’ requirements and expectations. Impacts: The project opened and maintains a collaborative dialogue with the Australian Office of the National Data Commissioner (NDC). The project leads submitted recommendations to the NDC.

Examining the legal and ethical dimensions of using automated data collection technologies to combat cyber threats in Australia.

This project delivered guidance and advice for researchers and agencies that collect data from open sources or the dark web and explore legal and ethical implications that arise from these activities. This provided a foundation for responsible research using such sources in the fields of cyber security, artificial intelligence, and social science. Impacts: No discernible impact.

Ransomware Resilient File Safe Havens

This exploratory project validated ideas and concepts to adapt existing shared file storage solutions to be intrinsically resilient to ransomware attacks. The project could lead to a larger technology development activity that can protect organisations data from the effects of ransomware in real time. Impacts: Initial prototype led to the follow on project “R3DWIRE”

Responsible Research and Innovation for Cyber Security CRC projects

The project analysed the legal and ethical implications of the CSCRC core collaborative projects. In particular, the project examined data ethics, responsible innovation, and human rights issues (including privacy) that may arise from developed technologies. It focussed on identifying existing challenges and proposing desirable and sustainable solutions. Overall, the project aimed to integrate Responsible Research and Innovation (RRI) approaches into the CSCRC’s processes. Impacts: The project has directly affected the work of six project teams within the CSCRC, working together with projects' leads and participants to create knowledge around RRI and support and assist the teams to improve their products and processes. The research resulted in the lead Shiri Krebs to provide two briefings to the UN (The UN Council, and the Australian Delegation to the UN) directly related to the project findings.

Tabletop Executive Gamification for Cybersecurity

The project built a tabletop cyber security game platform for stimulating discussion in executives to better understand cyber security application in a real-world scenario. The aim of the project was to build an awareness training package that can be used on a corporate and executive level, to instil a deeper understanding of the implications (both technical, operational, and strategic) of cyber security related decision making on an executive level. Impacts: This project provided the first mandated cyber security training for more than 70 senior executives in Office of Digital Government (WA) as part of their Cybersecurity Summit. It engaged three marine port authorities in the initial design and development and the success led to the follow-on project that resulted in Corporates Compromised.

Threat Hunting in Critical Infrastructure

Many organisations use cyber threat hunting to proactively detect attacks before they cause a major breach. The goal of hunting is detecting threat actors early in the cyber kill chain by searching for signs of an intrusion. Threat hunting is a proactive activity that starts with a hypothesis to verify. This capability includes the exploration and analysis of network and system data, and it utilises various toolsets and techniques to investigate network traffic and endpoints. The aim of this project was to find suitable and low-cost ways to implement threat hunting in industrial control systems (ICSs). Impacts: This project resulted in knowledge exchange between ACSC and QUT.

Cyber Common Operating Picture

Security environments are complex and noisy. Turning threat data into something that is readily understood by boards and senior management remains a challenge. Organisations need the ability to synthesise all the threat data in a way that communicates the threat but allows decisionmakers the opportunity to have an opinion and assess the risk. Impacts: The project outcomes were presented to AEMO and disseminated to their members in a workshop. Concrete examples of the metrics framework and knowledge exchange has changed the thinking of Participants in reporting cybersecurity metrics to their boards. The component with NAB on metrics for security awareness has been presented by NAB to AISA and the CSCRC is working with NAB on improving the tooling to be open sourced.

Acknowledgement of Country

We acknowledge the many Traditional Custodians of Country throughout Australia and honour their Elders past and present.

We respect their deep enduring connection to their lands, waterways and surrounding clan groups since time immemorial. We cherish the richness of First Nations Peoples’ artistic and cultural expressions.

We are privileged to gather on this Country and through this website to share knowledge with future generations.