{"id":565070,"date":"2026-03-26T06:37:11","date_gmt":"2026-03-26T06:37:11","guid":{"rendered":"https:\/\/www.newsbeep.com\/au\/565070\/"},"modified":"2026-03-26T06:37:11","modified_gmt":"2026-03-26T06:37:11","slug":"government-entities-in-queensland-unaware-of-cybersecurity-vulnerabilities-audit-office-report-finds","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/au\/565070\/","title":{"rendered":"Government entities in Queensland unaware of cybersecurity vulnerabilities, audit office report finds"},"content":{"rendered":"<p class=\"paragraph_paragraph___QITb\">A cybersecurity audit has gained the &#8220;highest level of access&#8221; to two government entities in Queensland, highlighting serious gaps in the systems.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The auditor-general tested the effectiveness of a state government, local government, and statutory body&#8217;s IT security controls.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Its report noted the entities did not know &#8220;how vulnerable&#8221; they were to third-party cybersecurity threats.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;In each of the entities, we were able to obtain passwords, access systems, and extract sensitive information outside the intended scope of a third-party user,&#8221; the report said.<\/p>\n<p>&#8220;For two of them, we were able to bypass controls and gain the highest level of access to their IT environments.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">The report found increasing frequency and sophistication of cyber attacks could expose entities that had weak cybersecurity.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Entities that do not manage these risks effectively may experience a cyber attack through a third party, leading to a loss of privacy, financial cost, reputational damage, and other ramifications.&#8221;<\/p>\n<p class=\"paragraph_paragraph___QITb\">As a result of the lack of mitigation controls, the auditor-general noted the entities could not understand the extent of their supply chain risks.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Contracts were also found to be a significant security gap.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;Only two of 36 contracts we reviewed included requirements for third parties to report their cybersecurity incidents and vulnerabilities,&#8221; the report said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;This means that entities can have risks that they are unaware of and therefore cannot effectively manage.&#8221;<\/p>\n<p>Risks raised five years ago<\/p>\n<p class=\"paragraph_paragraph___QITb\">The auditor-general also assessed how the Queensland government&#8217;s housing department, customer services and open data department managed cybersecurity risks in the public sector.<\/p>\n<p><a href=\"https:\/\/www.abc.net.au\/news\/2025-11-21\/gold-coast-and-noosa-council-scammed\/106022070\" data-component=\"FullBleedLink\" class=\"RelatedCard_link__rsgR9 FullBleedLink_root__lTw_U interactive_focusContext__yRhc_ interactive_defaults__AKxUU FullBleedLink_showVisited__g3Xvz\" rel=\"nofollow noopener\" target=\"_blank\">Queensland councils scammed out of millions despite warnings<\/a><\/p>\n<p class=\"Typography_base__sj2RP RelatedCard_synopsis__cFwMW Typography_sizeMobile14__u7TGe Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">A year after Gold Coast Council was victim to a fraud attack, Noosa Council was also targeted by a sophisticated artificial intelligence scam.\u00a0<\/p>\n<p class=\"paragraph_paragraph___QITb\">It found the latter was not actively assessing or monitoring third parties&#8217; cyber capability.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;CDSB [Customer Services, Open Data and Small and Family Business department] has begun building capability across the public sector to manage third-party cybersecurity risks, but needs to do more to be effective,&#8221; the report stated.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The report noted the Commonwealth&#8217;s cybersecurity agency had flagged risks since 2021.<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;The Queensland government has been slow to develop a framework to help entities manage their third-party cybersecurity risks,&#8221; it said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">The auditor-general made several recommendations, including that all public sector entities and local governments review and update their IT systems, improve identification of suspicious activity, and strengthen contract management practices.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Local Government Minister Ann Leahy said her department would write to each council to &#8220;emphasise the importance of implementing the recommendations&#8221;.<\/p>\n<p><img decoding=\"async\" alt=\"A woman in a pink suit speaking in Queensland state parliament\" class=\"Image_image__5tFYM ContentImage_image__DQ_cq\"  src=\"https:\/\/www.newsbeep.com\/au\/wp-content\/uploads\/2026\/03\/d94aad2b1832cb9c8599baae96a7b248.jpeg\" loading=\"lazy\" data-component=\"Image\" data-lazy=\"true\"\/><\/p>\n<p class=\"Typography_base__sj2RP FigureCaption_text__zDxQ5 Typography_sizeMobile12__w_FPC Typography_lineHeightMobile20___U7Vr Typography_regular__WeIG6 Typography_colourInherit__dfnUx\" data-component=\"Typography\">Ann Leahy says her department will write to each council to &#8220;emphasise the importance of implementing the recommendations&#8221;. (AAP: Darren England)<\/p>\n<p class=\"paragraph_paragraph___QITb\">&#8220;However, I note that there are potential resourcing and capacity implications for some councils, particularly smaller or resource-constrained councils, associated with implementing enhanced governance and reporting,&#8221; she said.<\/p>\n<p class=\"paragraph_paragraph___QITb\">Director-general of the housing and public works department, Mark Cridland, said his team was committed to working to mature capability in identifying and managing third-party cybersecurity risks.<\/p>\n","protected":false},"excerpt":{"rendered":"A cybersecurity audit has gained the &#8220;highest level of access&#8221; to two government entities in Queensland, highlighting serious&hellip;\n","protected":false},"author":2,"featured_media":296445,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[278249,64,63,99,53556,43851,2458,278248,94,701,109777,15878],"class_list":["post-565070","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-ann-leahy","tag-au","tag-australia","tag-business","tag-cyber-attacks","tag-cyber-security","tag-data","tag-it-systems","tag-qld","tag-queensland","tag-queensland-audit-office","tag-queensland-government"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/565070","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/comments?post=565070"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/posts\/565070\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media\/296445"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/media?parent=565070"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/categories?post=565070"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/au\/wp-json\/wp\/v2\/tags?post=565070"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}