<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>InConsult</title>
	<atom:link href="https://inconsult.com.au/feed/" rel="self" type="application/rss+xml" />
	<link>https://inconsult.com.au</link>
	<description>Helping you confidently take risks</description>
	<lastBuildDate>Tue, 02 Dec 2025 04:46:12 +0000</lastBuildDate>
	<language>en-AU</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://inconsult.com.au/wp-content/uploads/2021/06/cropped-favicon-3-32x32.jpg</url>
	<title>InConsult</title>
	<link>https://inconsult.com.au</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Hardhats and Hacking: Cyber Threats in Construction</title>
		<link>https://inconsult.com.au/hardhats-and-hacking-cyber-threats-in-construction/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Tue, 02 Dec 2025 03:54:30 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=14453</guid>

					<description><![CDATA[<p>InConsult Partners with TAFE NSW to Spotlight Cyber Threats Impacting the Construction Sector The Australian Federal Police recently issued a media release highlighting a significant surge in scams targeting the Construction industry. Unfortunately, this trend is not isolated. Across Australia, organisations in every sector are experiencing an increase in cyber-enabled fraud. At InConsult, we’re seeing [&#8230;]</p>
The post <a href="https://inconsult.com.au/hardhats-and-hacking-cyber-threats-in-construction/">Hardhats and Hacking: Cyber Threats in Construction</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<div class="relative basis-auto flex-col -mb-(--composer-overlap-px) [--composer-overlap-px:28px] grow flex overflow-hidden">
<div class="relative h-full">
<div class="flex h-full flex-col overflow-y-auto thread-xl:pt-(--header-height) [scrollbar-gutter:stable_both-edges]">
<div class="flex flex-col text-sm thread-xl:pt-header-height pb-25">
<article class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto [content-visibility:auto] supports-[content-visibility:auto]:[contain-intrinsic-size:auto_100lvh] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" tabindex="-1" data-turn-id="4073e3df-4dab-4132-aaaa-d2c77d7b9ff6" data-testid="conversation-turn-2" data-scroll-anchor="true" data-turn="assistant">
<div class="text-base my-auto mx-auto pb-10 [--thread-content-margin:--spacing(4)] thread-sm:[--thread-content-margin:--spacing(6)] thread-lg:[--thread-content-margin:--spacing(16)] px-(--thread-content-margin)">
<div class="[--thread-content-max-width:40rem] thread-lg:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" tabindex="-1">
<div class="flex max-w-full flex-col grow">
<div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;]:mt-1" dir="auto" data-message-author-role="assistant" data-message-id="2748509a-6352-4254-9a6e-b6d9cf290a6f" data-message-model-slug="gpt-5-1">
<div class="flex w-full flex-col gap-1 empty:hidden first:pt-[1px]">
<div class="markdown prose dark:prose-invert w-full break-words dark markdown-new-styling">
<h1 data-start="230" data-end="329"><strong data-start="232" data-end="329">InConsult Partners with TAFE NSW to Spotlight Cyber Threats Impacting the Construction Sector</strong></h1>
<p data-start="331" data-end="623">The <a href="https://www.afp.gov.au/news-centre/media-release/criminals-target-construction-sector-business-email-compromise-scams" target="_blank" rel="noopener">Australian Federal Police</a> recently issued a media release highlighting a <strong data-start="408" data-end="474">significant surge in scams targeting the Construction industry</strong>. Unfortunately, this trend is not isolated. Across Australia, organisations in <em data-start="554" data-end="561">every</em> sector are experiencing an increase in cyber-enabled fraud.</p>
<p data-start="625" data-end="815">At InConsult, we’re seeing these threats first-hand. That’s why we’re bringing together experts who are currently responding to these attacks on the ground.</p>
<p data-start="817" data-end="1031">We invite you to join us for an engaging evening of insights, real-world examples, and a live demonstration of one of today’s most common (and costly) cyber attacks affecting Construction and many other industries.</p>
<hr data-start="1033" data-end="1036" />
<h2 data-start="1038" data-end="1058"><strong data-start="1041" data-end="1058">Event Details</strong></h2>
<p data-start="1060" data-end="1380"><strong data-start="1060" data-end="1072">📅 When:</strong> 4 December 2025, 6:00pm<br data-start="1096" data-end="1099" /><strong data-start="1099" data-end="1112">📍 Where:</strong> Lecture Theatre, Building M, TAFE NSW, Meadowbank NSW 2114<br data-start="1171" data-end="1174" /><strong data-start="1174" data-end="1199">👥 Who Should Attend:</strong> IT Managers, Project Managers, Builders, Students — <strong data-start="1252" data-end="1271">all welcome</strong><br data-start="1271" data-end="1274" /><strong data-start="1274" data-end="1286">💲 Cost:</strong> Free event + light refreshments provided</p>
<hr data-start="1382" data-end="1385" />
<h2 data-start="1387" data-end="1422"><strong data-start="1390" data-end="1422">Why the Construction Sector?</strong></h2>
<p data-start="1424" data-end="1770">With high-value transactions, frequent invoicing, and often limited cyber security resources, the Construction sector has become a <strong data-start="1555" data-end="1571">prime target</strong> for cyber criminals. Threat actors are exploiting gaps in processes, systems and controls — often resulting in <strong data-start="1683" data-end="1713">large-scale financial loss</strong>, stalled projects, and in some cases, business collapse.</p>
<p data-start="1772" data-end="1851">These attacks rarely make the headlines. They are happening quietly, every day.</p>
<hr data-start="1853" data-end="1856" />
<h2 data-start="1858" data-end="1892"><strong data-start="1861" data-end="1892">What to Expect on the Night</strong></h2>
<p data-start="1894" data-end="2033">InConsult is proud to collaborate with <strong data-start="1933" data-end="1945">TAFE NSW</strong> and the <strong data-start="1954" data-end="1989">Institute of Applied Technology</strong> to deliver this important industry session.</p>
<h3 data-start="2035" data-end="2114"><strong data-start="2039" data-end="2114">Panel Discussion – Industry Experts Share What They’re Seeing Right Now</strong></h3>
<p data-start="2116" data-end="2126">Hear from:</p>
<ul>
<li data-start="2130" data-end="2157"><strong data-start="2130" data-end="2143">William Makdessi</strong> – InConsult</li>
<li data-start="2160" data-end="2187"><strong data-start="2160" data-end="2174">Jawad Khan</strong> – Gridware</li>
<li data-start="2190" data-end="2248"><strong data-start="2190" data-end="2206">Pete Tyrrell</strong> – Australian Payments Network (AusPayNet)</li>
</ul>
<p data-start="2250" data-end="2365">Our panellists will share current case studies, emerging scam techniques, and practical advice for mitigating risk.</p>
<h3 data-start="2367" data-end="2438"><strong data-start="2371" data-end="2438">Demonstration – A Real Attack Happening in Australia Today</strong></h3>
<p data-start="2440" data-end="2705">Following the panel, we will showcase a simple but highly effective attack technique that is <strong data-start="2533" data-end="2588">actively impacting Construction companies right now</strong>. This is the type of attack that often leads to six- and seven-figure losses, yet receives little public attention.</p>
<p data-start="2707" data-end="2829">This demonstration will help attendees recognise threats early and strengthen controls before they become the next victim.</p>
</div>
</div>
</div>
</div>
</div>
</div>
</article>
</div>
</div>
</div>
</div>
<p>&nbsp;</p>
<div class='printomatic pom-default ' id='id2463'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/hardhats-and-hacking-cyber-threats-in-construction/">Hardhats and Hacking: Cyber Threats in Construction</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>IIA&#8217;s Global Internal Audit Standards Now Effective</title>
		<link>https://inconsult.com.au/iias-global-internal-audit-standards-now-effective/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Tue, 04 Nov 2025 01:06:37 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Services]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=12496</guid>

					<description><![CDATA[<p>The Institute of Internal Auditors (IIA) has officially implemented its revised Global Internal Audit Standards, which took effect on January 9, 2025. These updates, initially published in January 2024, are part of the organisation&#8217;s ongoing efforts to evolve its International Professional Practices Framework (IPPF). The development of these new standards was a comprehensive, multiyear process [&#8230;]</p>
The post <a href="https://inconsult.com.au/iias-global-internal-audit-standards-now-effective/">IIA’s Global Internal Audit Standards Now Effective</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>The Institute of Internal Auditors (IIA) has officially implemented its revised Global Internal Audit Standards, which took effect on January 9, 2025. These updates, initially published in January 2024, are part of the organisation&#8217;s ongoing efforts to evolve its International Professional Practices Framework (IPPF).</p>
<p>The development of these new standards was a comprehensive, multiyear process that involved collaboration with thousands of professionals worldwide, including internal audit practitioners, service providers, and international standard-setters. This inclusive approach ensures the standards are both practical and globally relevant.</p>
<p>As organisations continue to navigate a complex business environment, these updated standards are poised to provide internal auditors with a robust framework to deliver greater value, align with organisational goals, and adapt to evolving challenges.</p>
<p>The revised standards aim to elevate the practice of internal auditing by ensuring better performance, enhanced quality, and greater consistency across organisations worldwide.</p>
<p>Key enhancements in the revised standards include:</p>
<ul>
<li><strong>Internal Audit Strategy</strong>: Emphasis on aligning internal audit activities with organisational objectives to enhance strategic relevance.</li>
<li><strong>Stakeholder Relationships</strong>: Strengthening communication and collaboration with stakeholders to ensure audit activities meet their needs and expectations.</li>
<li><strong>Performance Measurement and Accountability</strong>: Introducing metrics and accountability frameworks to assess and improve internal audit effectiveness.</li>
<li><strong>Governance Conditions</strong>: Defining essential governance structures and practices necessary for effective internal auditing.</li>
</ul>
<p>Over the past year, these standards have gained significant traction within the global internal audit community. Translated into 25 languages, they have been downloaded nearly 600,000 times, underscoring their broad appeal and importance.</p>
<p>For more analysis, including a step by step guide to adapting the new standards, read our publication <a href="https://inconsult.com.au/publication/new-2024-internal-audit-standards-insights-for-caes/" target="_blank" rel="noopener">New 2024 Internal Audit Standards: Insights for CAEs</a></p>
<p>For further details about the new standards, visit the official <a href="https://www.theiia.org/en/standards/2024-standards/global-internal-audit-standards/?utm_source=chatgpt.com" target="_blank" rel="noopener">IIA website</a>.</p>
<h2>Next Steps</h2>
<p>By now, most Chief Audit Executives, have transitioned to their organisation to align with the new 2024 Global Internal Audit Standards.  Many have compared the current practices of the internal audit function with the updated requirements to identify areas of non-compliance or improvement.  What now?</p>
<p>Continue to engage with stakeholders.  Inform the board, audit committee, and senior management about the transition to the new standards and their significance and benefits for your organisation.</p>
<div class='printomatic pom-default ' id='id3339'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/iias-global-internal-audit-standards-now-effective/">IIA’s Global Internal Audit Standards Now Effective</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Next-Gen GRC Needs Next-Gen Thinking: Welcome Andy</title>
		<link>https://inconsult.com.au/next-gen-grc-needs-next-gen-thinking-welcome-andy/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Wed, 16 Jul 2025 23:00:19 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Services]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=12594</guid>

					<description><![CDATA[<p>GRC isn’t just about ticking boxes. It’s about making better decisions, increasing resilience, and unlocking the power of technology to bring it all together. As Satya Nadella, Chairman and CEO of Microsoft, once said: “Technology is best when it brings people together and makes work easier.” At InConsult, we believe that’s exactly what Next-Gen GRC [&#8230;]</p>
The post <a href="https://inconsult.com.au/next-gen-grc-needs-next-gen-thinking-welcome-andy/">Next-Gen GRC Needs Next-Gen Thinking: Welcome Andy</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>GRC isn’t just about ticking boxes. It’s about making better decisions, increasing resilience, and unlocking the power of technology to bring it all together. As Satya Nadella, Chairman and CEO of Microsoft, once said:</p>
<p style="text-align: left; padding-left: 40px;">“<em>Technology is best when it brings people together and makes work easier</em>.”</p>
<p>At InConsult, we believe that’s exactly what Next-Gen GRC technology should do.</p>
<p>We know that the future of risk management, audit, and compliance lies where deep expertise meets forward-thinking innovation. That’s why we’re excited to welcome <a href="https://inconsult.com.au/about-us/our-team/">Andy Chu</a> as our new Risk Technology &amp; Innovation Lead.</p>
<p>Andy brings a powerful combination of Big 4 consulting experience and a proven track record in technology-driven transformation. With close to a decade at KPMG, Andy worked across assurance, digital consulting, and innovation portfolios. Most recently, he played a key role in NBN Co’s product strategy team. He helped accelerate the adoption of high-speed internet and improve customer experience at scale.</p>
<h2>Next-Gen GRC Starts Now</h2>
<p>In his new role at InConsult, Andy will lead the ongoing development of our <a href="http://www.guardianerm.com">GuardianERM</a> GRC platform, drawing on his strengths in assurance, audit, technology enablement, and risk transformation.</p>
<p>Andy’s focus will include:</p>
<ul>
<li>Gathering and prioritising client and market feedback</li>
<li>Scanning the horizon for emerging technologies and trends</li>
<li>Identifying more opportunities to enhance GuardianERM’s features, user experience, and value</li>
</ul>
<p>Supporting Andy is our dedicated GuardianERM engineering and support team. He is also backed by InConsult’s powerhouse of governance, audit, cyber security, AI, and risk management specialists. Together, they bring a depth of knowledge and momentum to help our clients confidently navigate the complex risk and compliance landscape.</p>
<p>With Andy at the helm, GuardianERM is set to evolve in exciting new ways—where the rigour of traditional risk management meets the agility of modern digital tools. Whether it&#8217;s enabling internal audit automation, streamlining compliance reporting, or leveraging AI for smarter risk insights, we’re building a platform designed for tomorrow’s challenges.</p>
<p>Watch this space — a new era of Next-Gen GRC innovation is just beginning.</p>
<p>&nbsp;</p>
<div class='printomatic pom-default ' id='id5675'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/next-gen-grc-needs-next-gen-thinking-welcome-andy/">Next-Gen GRC Needs Next-Gen Thinking: Welcome Andy</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>International Internal Audit Month</title>
		<link>https://inconsult.com.au/international-internal-audit-month-3/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Mon, 05 May 2025 07:44:09 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=12558</guid>

					<description><![CDATA[<p>May is Internal Audit Month and we want to tell the world that we are proud to provide internal audit services to our many clients. Internal Audit Month aims to increase awareness of the Internal Audit profession to a wider audience.  Internal auditors bring a disciplined approach to evaluating and improving governance, risk management, and [&#8230;]</p>
The post <a href="https://inconsult.com.au/international-internal-audit-month-3/">International Internal Audit Month</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>May is Internal Audit Month and we want to tell the world that we are proud to provide internal audit services to our many clients.</p>
<p>Internal Audit Month aims to increase awareness of the Internal Audit profession to a wider audience.  Internal auditors bring a disciplined approach to evaluating and improving governance, risk management, and control processes.</p>
<p>We encourage all organisations with an internal audit department to get involved this May. So here are our 7 strategies to boost internal audit awareness and improve the level of engagement with managers and staff:</p>
<ol>
<li>Auditors love internal controls and are the internal control design experts.  Internal audit teams can host an <strong>on-line Internal Control Awareness Training</strong> session for all managers.</li>
<li>Younger people love <strong>social media</strong>, engage them with internal audit memes and/or  short educational videos from our <a href="https://www.youtube.com/user/OneMinuteRiskManager" target="_blank" rel="noopener noreferrer">YouTube &#8211; One Minute Risk Manager </a>channel.</li>
<li>Have an <strong>on-line meeting catch up (and coffee)</strong> with managers who may be struggling to implement past audit recommendations and help them to move forward.</li>
<li>Host an on-line webinar for all staff to<strong> introduce the audit team members and members of the Audit and Risk Committee</strong>, outline exactly what internal audit does and doesn&#8217;t do.</li>
<li>Update the <strong>Internal Audit Page</strong> of your companies intranet page.</li>
<li><strong>Review your Strategic Audit Plan</strong> including any realignment to the organisations risk profile and assurance framework.</li>
<li>Help senior managers and risk owners to <strong>review and update their risk registers</strong> via a workshop or an on-line meeting.</li>
</ol>
<p>Remember that whatever you do, it&#8217;s all about keeping the role of internal audit and internal controls front of mind.</p>
<h2>InConsult Delivers Internal Audit Quality</h2>
<p>In November 2020, InConsult engaged the Institute of Internal Auditors Australia to conduct an independent External Quality Assessment of our internal audit services and InConsult achieved the highest rating possible of “Generally Conforms”.</p>
<p>Our clients can be reassured that InConsult is committed to quality and continuous improvement and that our internal audit activities are conducted in accordance with the International Standards for the Professional Practice of Internal Auditing​ (Standards).</p>
<p>Select from either one-off special audits, co-sourced or outsourced internal audit options and we will tailor our internal audit services to suit your needs, size of your organisation and your budget.</p>
<p>Check out InConsult&#8217;s <a href="/services/internal-audit-assurance/" target="_blank" rel="noopener noreferrer">Internal Audit and Assurance</a> capabilities to find out how we can help you.</p>
<div class='printomatic pom-default ' id='id3718'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/international-internal-audit-month-3/">International Internal Audit Month</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Setting Sail After 17 Years: Farewell to Director Mitchell Morley</title>
		<link>https://inconsult.com.au/setting-sail-after-17-years-farewell-to-director-mitchell-morley/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Tue, 08 Apr 2025 19:49:55 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Services]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=12537</guid>

					<description><![CDATA[<p>After 17 impactful years with InConsult, we bid farewell to our esteemed Director and friend, Mitchell Morley, who is officially retiring and setting sail into a well-earned next chapter. Mitchell’s career spans over four decades, primarily in the NSW public sector, where he held senior roles including Governance Manager, Corporate Services Director and Acting General [&#8230;]</p>
The post <a href="https://inconsult.com.au/setting-sail-after-17-years-farewell-to-director-mitchell-morley/">Setting Sail After 17 Years: Farewell to Director Mitchell Morley</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>After 17 impactful years with InConsult, we bid farewell to our esteemed Director and friend, Mitchell Morley, who is officially retiring and setting sail into a well-earned next chapter.</p>
<p>Mitchell’s career spans over four decades, primarily in the NSW public sector, where he held senior roles including Governance Manager, Corporate Services Director and Acting General Manager. He served as Chair of the NSW Local Government Governance Network, was a Board Member of Westpool (now CivicRisk Mutual), and held executive positions at Liverpool, Marrickville (now Inner West), Hornsby, and Fairfield Councils.</p>
<p>Mitchell joined InConsult in 2008, at a time when we had just a handful of local government clients. Bringing with him deep expertise across corporate governance, probity, records and privacy management, insurance, risk management, internal audit, and administrative services, Mitchell worked tirelessly to establish InConsult as a trusted partner to local government. Thanks largely to his knowledge, leadership and commitment, InConsult now works with 115 of NSW’s 128 councils.</p>
<p>Mitchell’s experience, insight, steady leadership and thoughtful approach have been a cornerstone of our success. As a Director, he brought balance and perspective to our Board, enriching our strategic decision-making. He also led our internal audit and assurance engagements with professionalism, precision and an unwavering commitment to client outcomes. A standout achievement was guiding one of our clients to a prestigious risk management award.</p>
<p>A prolific thought leader, Mitchell has authored numerous articles on governance, audit, and risk, and presented at conferences across Australia and overseas. He continues to serve as an independent member on several Audit and Risk Committees.</p>
<p>Beyond the boardroom, Mitchell loves sport &#8211; Golf, horse racing, rugby league (go Parramatta) and &#8220;Aussie Rules&#8221; (go Hawthorn).  Mitchell has long been an active figure in his local community, contributing as a player, coach, and committee member in grassroots sports.</p>
<p>As he embarks on retirement, Mitchell is looking forward to lowering his already enviable golf handicap, spending more time with family, and exploring the world alongside his wife. In between travelling and lowering his golf handicap, Mitchell will continue to keep a close eye on our future business endeavours.</p>
<p>Following Mitchell’s departure, Dane Parsons, Internal Audit Manager, will take the lead in delivering all internal audit and assurance engagements. Dane will be supported by Director Tony Harb, who will remain closely connected with the team as they continue to deliver the high standard of service our clients know and trust.</p>
<p>Mitchell, thank you for your exceptional leadership, dedication, loyalty and friendship over the past 17 years. Your contribution to InConsult, internal audit and to the wider public sector has been profound &#8211; and your legacy will continue to shape our journey.</p>
<p>Wishing you calm waters, smooth fairways, and many unforgettable adventures ahead.</p>
<p>&nbsp;</p>
<div class='printomatic pom-default ' id='id186'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/setting-sail-after-17-years-farewell-to-director-mitchell-morley/">Setting Sail After 17 Years: Farewell to Director Mitchell Morley</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber Security Awareness Month 2024</title>
		<link>https://inconsult.com.au/cyber-security-awareness-month-2024/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Wed, 02 Oct 2024 22:48:45 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Services]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=12234</guid>

					<description><![CDATA[<p>October is Cyber Security Awareness Month and an annual reminder for all of us to stay secure online. With the ever-evolving digital landscape that now includes Artificial Intelligence (AI), cybersecurity threats are becoming more sophisticated, targeting individuals and businesses alike. It’s crucial to recognise the role we all play in securing the digital world, from [&#8230;]</p>
The post <a href="https://inconsult.com.au/cyber-security-awareness-month-2024/">Cyber Security Awareness Month 2024</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>October is Cyber Security Awareness Month and an annual reminder for all of us to stay secure online.</p>
<p>With the ever-evolving digital landscape that now includes Artificial Intelligence (AI), cybersecurity threats are becoming more sophisticated, targeting individuals and businesses alike. It’s crucial to recognise the role we all play in securing the digital world, from using strong passwords to implementing comprehensive security measures in organizations.</p>
<p>The Australian Cyber Security Centre (ACSC) leads the Australian Government’s efforts to improve cyber security.</p>
<p>The theme for 2024 is &#8216;Cyber security is everyone&#8217;s business&#8217;.  There are 4 simple steps you can take to be cyber wise and significantly boost your cyber security:</p>
<ol>
<li><strong>Turn on multi-factor authentication</strong> &#8211; Multi-factor authentication (MFA) is one of the best ways to protect your accounts.</li>
<li><strong>Keep your devices and software up to date</strong> &#8211; Check that automatic updates are on and install updates as soon as possible.</li>
<li><strong>Use strong and unique passwords, such as a passphrase</strong> &#8211; Passphrases are more secure versions of passwords, using 4 or more random words.  Consider storing your passwords and passphrases in a reputable <a title="Password managers" href="https://www.cyber.gov.au/protect-yourself/securing-your-accounts/password-managers" target="_blank" rel="noopener" data-entity-type="node" data-entity-uuid="71928c7e-5d57-4234-a4bf-5d5e38bde4c7" data-entity-substitution="canonical">password manager</a>.</li>
<li><strong>Recognise and report phishing</strong> &#8211; Visit the ACSC <a title="Recognise and report scams" href="https://www.cyber.gov.au/learn-basics/explore-basics/recognise-and-report-scams" target="_blank" rel="noopener" data-entity-substitution="canonical" data-entity-type="node" data-entity-uuid="8e08ae90-d462-4a08-8b12-d12fa41cf9b6">Emails and texts</a> information page for more details on how to identify and report phishing attempts.</li>
</ol>
<p>Find out more about Cyber Security Awareness Month 2024 by visiting the <a href="https://www.cyber.gov.au/learn-basics/view-resources/cyber-security-awareness-month" target="_blank" rel="noopener">Australian Cyber Security Centre</a> website.</p>
<h2>10 Ways to Promote Cyber Security Awareness</h2>
<p>Don&#8217;t miss this opportunity to reinforce the importance of cyber security within your organisation. What will you do to raise awareness that cyber security is everyone&#8217;s business?</p>
<p>Here is our list of 10 things you can do during Cyber Security Awareness Month:</p>
<ol>
<li>Plan ahead. Work with your People &amp; Culture, Risk Management and Communication teams in a <strong>rollout plan</strong> to engage and reach as many employees as possible.</li>
<li>Set the &#8216;tone from the top&#8217; by <strong>creating a culture of cyber security awareness</strong>. The entire C-suite needs to understand and embrace cybersecurity efforts.  Cyber security habits are best learned through management taking the lead.</li>
<li>Review your<strong> cyber security touchpoints</strong>.  Is cyber security awareness part of onboarding? How often does your organisation communicate about cyber security? Which vendors pose the highest cyber risk for your organisation?</li>
<li>Arrange <strong>cyber security awareness training</strong> sessions. Awareness training should reinforce that cyber security is everyone&#8217;s business and stress the importance of cyber security at work and at home.</li>
<li>Run a <strong>simulated phishing campaign</strong> to evaluate employee behaviour on receipt of a socially engineered phishing email, analyse results and provide a report of the results to all staff.</li>
<li>Review and update key elements of your <strong>IT-Disaster Recovery Plan </strong>or <strong>Data Breach Incident Response Plan</strong>.</li>
<li>With cyber attacks and third party data breaches on the rise, conduct a <strong>Crisis Management Team simulation exercise </strong>covering one of these risks.</li>
<li>Provide management a high level presentation covering the concept of operation of the<strong> Data Breach Incident Response Plan</strong>.</li>
<li>Run <strong>on-line games and quizzes</strong> such as crosswords and find a word with cybersecurity words as the central theme.</li>
<li><strong>Reward good behaviour</strong> and people who embrace cyber security. Rewards don’t have to be expensive &#8211; small gift vouchers are often enough and always appreciated.</li>
</ol>
<h2>Want to Strengthen Cyber Resilience?</h2>
<p>InConsult is an ACSC partner and we strongly encourage all organisations to get involved in Cyber Security Awareness Month. Contact us if you would like help in planning or conducting cyber awareness training or email phishing campaigns.</p>
<p>Remember that whatever you do, it’s all about keeping cyber security front of mind! Check out InConsult’s <a href="https://inconsult.com.au/services/cyber-resilience/" target="_blank" rel="noopener">Cyber Resilience</a> capabilities to find out how we can help you build a more resilient organisation.</p>
<p>Be more resilient to a wide range of cyber risks and <a title="Contact Us" href="https://inconsult.com.au/contact-us/" target="_blank" rel="noopener">contact us</a> to discuss how we can help strengthen your cyber security posture.</p>
<p>#staysecureonline #CyberSecurityAwarenessMonth2024</p>
<div class='printomatic pom-default ' id='id6605'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/cyber-security-awareness-month-2024/">Cyber Security Awareness Month 2024</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cyber Security Awareness Month 2023</title>
		<link>https://inconsult.com.au/cyber-security-awareness-month-2023/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Mon, 18 Sep 2023 05:29:59 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Services]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=11301</guid>

					<description><![CDATA[<p>October is a BIG month for cyber security awareness and presents a great opportunity for organisations to promote cyber security awareness and #becyberwise. Cyber attacks are still on the rise and your employees and vendors are more susceptible than ever to attacks like phishing and social engineering. Cybercriminals are constantly developing more sophisticated and targeted [&#8230;]</p>
The post <a href="https://inconsult.com.au/cyber-security-awareness-month-2023/">Cyber Security Awareness Month 2023</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>October is a BIG month for cyber security awareness and presents a great opportunity for organisations to promote cyber security awareness and #becyberwise.</p>
<p>Cyber attacks are still on the rise and your employees and vendors are more susceptible than ever to attacks like phishing and social engineering. Cybercriminals are constantly developing more sophisticated and targeted tactics to exploit both people and vulnerabilities.</p>
<p>According to the ACSC, one cybercrime is reported every 7 minutes.</p>
<p>In Australia, October is Cyber Security Awareness Month and it&#8217;s an annual reminder for all Australian’s to stay secure online.  The Australian Cyber Security Centre (ACSC) leads the Australian Government’s efforts to improve cyber security.</p>
<p>The theme for 2023 is &#8216;Be cyber wise – don’t compromise&#8217;.  There are 4 simple steps you can take to be cyber wise and significantly boost your cyber security:</p>
<ol>
<li>Update your devices regularly</li>
<li>Turn on multi-factor authentication</li>
<li>Back up your important files</li>
<li>Use passphrases and password managers</li>
</ol>
<p>Meanwhile, in the United States, October is also Cyber Security Awareness Month.  The event runs all month and aims to raise awareness about the importance of cybersecurity. 2023 marks 20 Years of Cybersecurity Awareness Month.  Cybersecurity Awareness Month 2023 will focus on four key behaviours all month long:</p>
<ol>
<li>Use strong passwords and a password manager</li>
<li>Turn on multifactor authentication</li>
<li>Recognize and report phishing</li>
<li>Update software</li>
</ol>
<p>Find out more about Cyber Security Awareness Month 2023 by visiting the <a href="https://www.cyber.gov.au/learn-basics/view-resources/cyber-security-awareness-month" target="_blank" rel="noopener">Australian Cyber Security Centre</a> and the <a href="https://staysafeonline.org/programs/cybersecurity-awareness-month/" target="_blank" rel="noopener">National Cyber Security Alliance</a> websites.</p>
<h2>10 Ways to Promote Cyber Security Awareness</h2>
<p>Don&#8217;t miss this opportunity to reinforce the importance of cyber security within your organisation. What will you do to raise awareness and encourage people to #BeCyberWise?</p>
<p>Here is our list of 10 things you can do during Cyber Security Awareness Month:</p>
<ol>
<li>Plan ahead. Work with your Human Resources, Risk Management and Communication teams in a <strong>rollout plan</strong> to engage and reach as many employees as possible.</li>
<li>Set the &#8216;tone from the top&#8217; by <strong>creating a culture of cyber security awareness</strong>. The entire C-suite needs to understand and embrace cybersecurity efforts.  Cyber security habits are best learned through management taking the lead.</li>
<li>Review or audit your<strong> cyber security touchpoints</strong>.  Is cyber security awareness part of onboarding? How often does your organisation communicate about cyber security? Which vendors pose the highest cyber risk for your organisation?</li>
<li>During the pandemic, many employees may still be working from home.  Conduct <strong>on-line cyber security awareness training</strong> sessions. Awareness training should reinforce that it is everyone’s role to #BeCyberWise and stress the importance of cyber security at work and at home.</li>
<li>Run a <strong>simulated phishing campaign</strong> to evaluate employee behaviour on receipt of a socially engineered phishing email, analyse results and provide a report of the results to all staff.</li>
<li>Review and update key elements of your <strong>IT-Disaster Recovery Plan </strong>or <strong>Data Breach Incident Response Plan</strong>.</li>
<li>With cyber attacks and third party data breaches on the rise, conduct a <strong>Crisis Management Team simulation exercise </strong>covering one of these risks.</li>
<li>Provide management a high level presentation covering the concept of operation of the<strong> Data Breach Incident Response Plan</strong>.</li>
<li>Run <strong>on-line games and quizzes</strong> such as crosswords and find a word with cybersecurity words as the central theme.</li>
<li><strong>Reward good behaviour</strong> and people who embrace cyber security. Rewards don’t have to be expensive &#8211; small gift vouchers are often enough and always appreciated.</li>
</ol>
<h2>Want to Strengthen Cyber Resilience?</h2>
<p>InConsult is an ACSC partner and we strongly encourage all organisations to get involved in Cyber Security Awareness Month. Contact us if you would like help in planning or conducting cyber awareness training or email phishing campaigns.</p>
<p>Remember that whatever you do, it’s all about keeping cyber security front of mind! Check out InConsult’s <a href="https://inconsult.com.au/services/cyber-resilience/" target="_blank" rel="noopener">Cyber Resilience</a> capabilities to find out how we can help you build a more resilient organisation.  Our cyber risk management services include:</p>
<ul>
<li>Gap Analysis of your Cyber Security and Resilience</li>
<li>Cyber Risk Governance Framework Review</li>
<li>Cyber Risk Governance Framework Development</li>
<li>Third-Party Vendor Review and Cyber Risk Analysis</li>
<li>Cyber Risk Awareness Training and Internal Campaigns</li>
<li>Email Phishing Campaigns</li>
<li>Cyber Incident Response</li>
<li>Post-Cyber Incident Review</li>
<li>Crisis Team Familiarisation Training</li>
</ul>
<p>Be more resilient to a wide range of cyber risks and <a title="Contact Us" href="https://inconsult.com.au/contact-us/" target="_blank" rel="noopener">contact us</a> to discuss how we can help strengthen your cyber security posture.</p>
<p>#staysecureonline #becyberwise #CyberSecurityAwarenessMonth2023</p>
<div class='printomatic pom-default ' id='id6438'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/cyber-security-awareness-month-2023/">Cyber Security Awareness Month 2023</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>New Sustainability and Climate Reporting Standards Agreed</title>
		<link>https://inconsult.com.au/new-sustainability-and-climate-reporting-standards-agreed/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Thu, 04 Aug 2022 11:16:10 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Services]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=10069</guid>

					<description><![CDATA[<p>Australia’s leading financial and business bodies have agreed on the need for consistent sustainability and climate reporting standards. The group of 20 peak bodies include the Insurance Council of Australia, Financial Services Council, Australian Banking Association, the Australian Council of Superannuation Investors, CPA Australia, Chartered Accountants Australia and New Zealand and the Institute of Public [&#8230;]</p>
The post <a href="https://inconsult.com.au/new-sustainability-and-climate-reporting-standards-agreed/">New Sustainability and Climate Reporting Standards Agreed</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>Australia’s leading financial and business bodies have agreed on the need for consistent sustainability and climate reporting standards.</p>
<p>The group of 20 peak bodies include the Insurance Council of Australia, Financial Services Council, Australian Banking Association, the Australian Council of Superannuation Investors, CPA Australia, Chartered Accountants Australia and New Zealand and the Institute of Public Accountants.</p>
<p>Collectively the group represent more than 400 companies, approximately 300 investors with US$33 trillion assets under management and 500,000 business and finance professionals.</p>
<p>The group welcomed the new <a href="https://www.ifrs.org/groups/international-sustainability-standards-board/#about" target="_blank" rel="noopener">International Sustainability Standards Board</a> (ISSB) draft sustainability standards published in March 2022.  The group believes that clear, transparent, comprehensive and comparable disclosure of sustainability-related information to be part of the foundations of a well-functioning global financial system.</p>
<p>The group also recognised that climate is a “first order risk” to the Australian economy and stated that it supported the Paris Agreement and its objective to achieve net-zero emissions.</p>
<p>The only caveat&#8230;the group said the transition to achieving a net-zero emissions economy needed to be undertaken with care.  The group said, “To avoid large-scale financial risks from a disorderly transition to net zero emissions and the physical impacts of climate change, there must be clear and comparable disclosure of sustainability-related and in particular, climate-related information.&#8221;</p>
<h3>The ISSB Will Lead Sustainability &amp; Climate Reporting</h3>
<p>The ISSB released two exposure drafts in March 2022.  They set out general sustainability-related disclosure requirements and specified climate-related disclosure requirements while also providing stakeholders with the opportunity to comment on the proposed standards.</p>
<p>Just days earlier, the effort to establish a global baseline for sustainability disclosures took another positive step with the consolidation of the Value Reporting Foundation (VRF) into the IFRS Foundation.</p>
<p>The IFRS Foundation is home of  both the ISSB and the International Accounting Standards Board (IASB), the global standard-setter for financial reporting.</p>
<p>In recent years, investors with global investment portfolios have been calling for more transparent environmental, social and governance (ESG) reporting by companies.  The ISSB was launched by the IFRS Foundation at last year’s COP26 summit and was tasked with developing a single set of standards to meet the information needs of investors.</p>
<p>In March 2022, the U.S. Securities and Exchange Commission’s (SEC) proposal on thorough environmental reporting by American public companies also came in response to a shift in investor interest and public opinion.</p>
<h3>Sustainability &amp; Climate Reporting Next steps</h3>
<p>The agreement provides the foundations for taking further steps towards sustainability and climate reporting reporting. Moving forward:</p>
<ul>
<li>There will be a global approach to the development of sustainability disclosure standards.  The coordinated approach helps ensure there is no regulatory fragmentation in definitions, terminologies, and metrics on disclosure.</li>
<li>The ISSB will be the global body overseeing these standards.</li>
<li>There will be collaboration and coordination between sustainability disclosure initiatives and financial accounting standard setting.</li>
<li>The goal will be to achieve a globally consistent and verifiable corporate reporting system.</li>
<li>The new disclosure standards will impact Australia’s capital markets and participants, as investors continue to demand comparable disclosures.</li>
<li>The 20 peak bodies will work with the Australian government as well as other national and international stakeholders.</li>
<li>The assurance providers including Registered Company Auditors, will need to expand their skill set in order to keep up with a fluid environment.</li>
</ul>
<p>The agreed approach now provides the foundations for taking steps towards sustainability and climate reporting reporting.</p>
<p>Financial institutions like banks and insurers and well as listed companies will need to stay vigilant and engage with their peak bodies.  Also, risk, investment, finance, audit and assurance professionals will need to stay ahead of developments and keep their skill set up to date.</p>
<h3>The Challenges</h3>
<p>Recently, 86 finance chiefs from across the globe signed a letter sent to the ISSB insisting on the improvement of its proposed reporting standards in 6 areas:</p>
<ol>
<li>Alignment with relevant existing sustainability reporting standards “to the greatest extent possible.”</li>
<li>Clarity on what constitutes enterprise value, recognizing that investors may need disclosures on broader social and environmental impacts to assess risk and make investment decisions.</li>
<li>Clear definitions and guidelines for preparers.</li>
<li>Disclosure requirements should enable a “continued focus on setting science-based, ambitious targets and the actions needed to achieve them.”</li>
<li>Promote integrated thinking through frameworks such as the Integrated Reporting Framework.</li>
<li>Address the environmental, social, and economic issues that impact decision-making.</li>
</ol>
<h3>The Benefits</h3>
<p>More than 80% of mainstream investors now consider ESG information when making investment decisions. There are currently $23 trillion of assets being professionally managed under responsible investment strategies, an increase of 25% since 2014 which exceeds the gross domestic product of the entire USA economy.</p>
<p>Besides the clear benefits to the environment and reducing the financial impact of climate change, improved guidance will reduce the risk of &#8216;greenwashing&#8217;.  This is when an organisation spends more time and money on marketing itself as sustainable and environmentally friendly than on actually minimizing its environmental impact.  We saw this when Volkswagen admitted to cheating emissions tests by fitting various vehicles with a “defect” device, with software that could detect when it was undergoing an emissions test and altering the performance to reduce the emissions level.</p>
<h3>12 ESG Questions</h3>
<p>Achieving the desired ESG posture is not easy and there are lots of questions the board can ask.  Here are 12 questions to start:</p>
<ul>
<li>Does the organisation&#8217;s vision and values specifically reflect a commitment to ESG?</li>
<li>Is the board approved ESG policy and framework aligned to the organisations vision and values?</li>
<li>Are ESG responsibilities clearly described and included in positions descriptions and performance incentives?</li>
<li>Is ESG on the board and leadership agenda?</li>
<li>Has the organisation identified the ESG related compliance obligations and assigned responsibilities to monitor?</li>
<li>Has the organisation identified the ESG related risks and developed the appropriate action plans?</li>
<li>Are ESG practices embedded into day-to-day business processes and activities?</li>
<li>Does your ESG framework extend to third parties, vendors and suppliers?</li>
<li>Is there regular communication between your organisation and stakeholders?</li>
<li>Is there regular reporting and monitoring of your ESG posture to the board?</li>
<li>Are the underlying assumptions in the analysis reasonable and supported by evidence?</li>
<li>Does internal audit verify the accuracy and completeness of ESG reporting processes, external disclosure and data?</li>
</ul>
<p>There is no right or wrong here, but your answer should be appropriate to your organisation, industry and stakeholder expectations.</p>
<p>Remember, climate change financial risks are often categorised into physical, transition and legal/ liability risks and they all must be managed.</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter wp-image-8929" src="https://inconsult.com.au/wp-content/uploads/2021/12/climate-net-zero-inconsult-1-1-300x240.jpg" alt="sustainability inconsult net zero" width="486" height="389" srcset="https://inconsult.com.au/wp-content/uploads/2021/12/climate-net-zero-inconsult-1-1-300x240.jpg 300w, https://inconsult.com.au/wp-content/uploads/2021/12/climate-net-zero-inconsult-1-1-768x615.jpg 768w, https://inconsult.com.au/wp-content/uploads/2021/12/climate-net-zero-inconsult-1-1.jpg 1144w" sizes="(max-width: 486px) 100vw, 486px" /></p>
<h3>Next steps</h3>
<p>What does this agreed way forward mean to your business? What does sustainability look like at your organisation? How far do you want to go to minimise the impact of climate change on your business?</p>
<p>Whatever your climate resilience posture, making a start as soon as possible is better than waiting to get it perfect or waiting until you have researched all the alternatives.</p>
<p>There are four ways that we can help you with your environmental and sustainability reporting:</p>
<ol>
<li>Interpreting applicable standards and frameworks and advising you on their benefits and application.</li>
<li>Environmental/sustainability performance reporting obligation compliance.</li>
<li>Understanding the best metrics and data to record and report.</li>
<li>Generating your reports.</li>
</ol>
<p>Be more resilient and <a title="Contact Us" href="https://inconsult.com.au/contact-us/" target="_blank" rel="noopener">contact us</a> if you would like help with developing sustainability strategies, climate change risk assessments and testing, sustainability education and reporting.</p>
<div class='printomatic pom-default ' id='id5898'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/new-sustainability-and-climate-reporting-standards-agreed/">New Sustainability and Climate Reporting Standards Agreed</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Act Now: Release of New Ransomware Threat Guidelines</title>
		<link>https://inconsult.com.au/act-now-release-of-new-ransomware-threat-guidelines/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Tue, 08 Mar 2022 01:14:52 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=9102</guid>

					<description><![CDATA[<p>There has been a historical pattern of cyber attacks against Ukraine that have had unintended international consequences. Sanctions and digital measures could put the US, its allies and other NATO nations at high risk as the threat of a response is likely and of an unpredictable scale. Malicious cyber activity could impact Australian organisations through [&#8230;]</p>
The post <a href="https://inconsult.com.au/act-now-release-of-new-ransomware-threat-guidelines/">Act Now: Release of New Ransomware Threat Guidelines</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>There has been a historical pattern of cyber attacks against Ukraine that have had unintended international consequences. Sanctions and digital measures could put the US, its allies and other NATO nations at high risk as the threat of a response is likely and of an unpredictable scale. Malicious cyber activity could impact Australian organisations through unintended disruption or uncontained malicious cyber activities. Typically, high-value targets in state-sponsored digital warfare include governments, militaries, energy, finance, and critical infrastructure. Despite this, the Australian Cyber Security Centre (ACSC) is recommending that all Australian organisations, no matter the size or industry, urgently adopt an enhanced cyber security position in response to the threat of malware, particularly ransomware.</p>
<p>In this context, the Australian Cyber Security Centre has published two guides to help organisations manage and respond to ransomware threats. Much like the Third Party Risk enhancements NIST introduced in late 2021, these new guidelines are a direct response to the global state of cyber risk and how organisations should better prepare.</p>
<p>The two documents are:</p>
<ul>
<li><a href="https://csrc.nist.gov/publications/detail/nistir/8374/final"><em><u>The Ransomware Risk Management: A Cybersecurity Framework Profile (NISTIR 8374):</u></em></a> this incorporates feedback from earlier drafts and is based on the broader NIST Cybersecurity Framework Version 1.1. NIST says that it can be used as a guide to manage the risk of ransomware events &#8211; which includes helping to gauge an organisation&#8217;s level of readiness to counter ransomware threats and to deal with the potential consequences of events if they occur.</li>
<li><a href="https://csrc.nist.gov/publications/detail/white-paper/2022/02/24/getting-started-with-cybersecurity-risk-management-ransomware/final"><em><u>Getting Started with Cybersecurity Risk Management: Ransomware</u></em>:</a> a guide that is designed to enable organisations to make a quick start on managing ransomware risks by encouraging enhanced communication and taking risk-based action in response to the new threat landscape.</li>
</ul>
<p>By introducing these guidelines, NIST is addressing the current environment while also encouraging adoption of the entire Cyber Security Framework. By adapting it to what many organisations would consider the greatest cyber threat &#8211; ransomware, the relevance of the framework becomes clearer, especially for those that have documentation that is loosely adapted or incomplete. The NIST Cyber Security Framework and all sub-guides are based on the five key areas &#8211; Identify, Detect, Protect, Respond, Recover.</p>
<p>The time is now. Be your framework incomplete or the perfect example of compliance, review and improvement is never ending and key to the combined fight against cyber threats. We must act. Our cyber gaps not only pose a threat to us, but our vendors, stakeholders, clients and much more. Indirect exposure is prolific in Australian infrastructure with an IBM-Ponemon study revealing more than half of all organisations have experienced a data breach due to a third party.</p>
<h3><span style="color: #cb0000;">6 steps you need to take right now to combat ransomware</span></h3>
<p>Here is our list of 6 steps you can take to help improve the maturity of your cyber security:</p>
<ol>
<li>Strengthen <strong>COMMUNICATION</strong> with staff to ensure a combined understanding of the evolving threat. Human error still remains the greatest weakness.</li>
<li>Enhance your <strong>DETECTION</strong> tools to predict and alert your security team before an impact occurs.</li>
<li>Review and exercise your <strong>RESPONSE</strong> documentation to ensure a sense of readiness throughout the organisation.</li>
<li>Adopt a strict <strong>ZERO TRUST</strong> policy across all platforms to ensure access to sensitive information is limited to requirements and review existing privileged access regularly.</li>
<li>Ensure all devices whether company owned or BYOD are <strong>PATCHED</strong> and kept up to date as often as possible (e.g. enable auto-update on end user devices).</li>
<li>Broaden your organisation&#8217;s overall <strong>CYBER HYGIENE</strong> to ensure existing and new processes are designed with cyber security at the foundation (e.g. multi factor authentication, centralised password rules, anti-malware on all devices including BYOD).</li>
</ol>
<p>Equally important, InConsult encourages all organisations to regularly monitor Australian Cyber Security Centre advisories, threats and alerts. Contact us if you would like to know more about any notices released and how they may affect your organisation.</p>
<p>And finally, remember that whatever steps you take, ensuring Cyber Risk is prioritised and regularly discussed is already the first step to enhancing your cyber posture! Check out InConsult’s <a title="Business Continuity Management" href="https://inconsult.com.au/services/cyber-resilience/" target="_blank" rel="noopener">Cyber Resilience</a> capabilities to find out how we can help you build a more resilient organisation.</p>
<h3>InConsult is an official partner of the Australian Cyber Security Centre</h3>
<p>We are proud to be an official partner of the Australian Cyber Security Centre (ACSC), a part of the Joint Cyber Security Centre that is collectively enhancing communication between security agencies worldwide. As an official partner, we are privileged to priority notifications and direct support from the ACSC to address any matters or concerns relating to threats to the Australian business landscape.</p>
<p><img decoding="async" class="aligncenter" src="https://guardianerm.com/wp-content/uploads/2021/12/logoacsc-1.png" alt="ACSC Logo - Ransomware Guidelines" width="349" height="55" /></p>
<p>&nbsp;</p>
<div class='printomatic pom-default ' id='id2018'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/act-now-release-of-new-ransomware-threat-guidelines/">Act Now: Release of New Ransomware Threat Guidelines</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Business Continuity Awareness Week 2022</title>
		<link>https://inconsult.com.au/business-continuity-awareness-week-2022/</link>
		
		<dc:creator><![CDATA[Tony Harb]]></dc:creator>
		<pubDate>Mon, 21 Feb 2022 02:38:17 +0000</pubDate>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://inconsult.com.au/?p=9070</guid>

					<description><![CDATA[<p>Business Continuity Awareness Week (BCAW) is a global event designed to raise awareness of business continuity and resilience by educating, sharing experiences, knowledge and best practices. This year, BCAW 2022 will run from 16th – 20th May 2022 and celebrates the theme, “Building Resilience in the Hybrid World”. Why this theme?   According to The Business Continuity Institute  (BCI), [&#8230;]</p>
The post <a href="https://inconsult.com.au/business-continuity-awareness-week-2022/">Business Continuity Awareness Week 2022</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></description>
										<content:encoded><![CDATA[<p>Business Continuity Awareness Week (BCAW) is a global event designed to raise awareness of business continuity and resilience by educating, sharing experiences, knowledge and best practices.</p>
<p>This year, BCAW 2022 will run from <strong>16th – 20th May 2022</strong> and celebrates the theme, <strong>“Building Resilience in the Hybrid World”</strong>. Why this theme?   According to The Business Continuity Institute  (BCI), in the last 24 months, the world has seen a rise in the adoption of hybrid work models, where employees have the flexibility to work part in the office and part remotely. In this new work environment, organizations need to rethink the way they embed, validate and raise awareness amongst their staff of Business Continuity Plans.</p>
<p>The aim of the theme is to equip organisations &amp; Business Continuity Professionals with the necessary tools to embed &amp; improve awareness of Business Continuity in this new workplace reality.</p>
<p>Don&#8217;t let the pandemic get in your way. You are resilient right? Be creative. What will you do to raise awareness of business continuity and the importance of resilience?</p>
<h3>8 things to do during Business Continuity Awareness Week</h3>
<p>Here is our list of 8 things you can do during BCAW 2022 to help improve the level of engagement in resilience and business continuity management:</p>
<ol>
<li>Update your organisations <strong>Business Impact Analysis</strong> (BIAs) via on-line meetings or a hybrid meeting.</li>
<li>Review and update key elements of your response plans such as the <strong>BCP,</strong> <strong>Crisis Management Plan,</strong> <strong>Pandemic Plan, </strong><strong>IT-DRP </strong>or <strong>Data Breach Response Plan</strong>.</li>
<li>As many employees may still be working from home and this increases cyber risks &#8211; conduct <strong>on-line cyber security awareness training</strong> sessions.</li>
<li>With climate risk and third party risks on the rise, conduct a hybrid <strong>Crisis Management Team simulation exercise </strong>covering one of these risks.</li>
<li>Conduct <strong>refresher training</strong> for the Crisis Team and those senior managers involved in implementing your response plans.</li>
<li>Provide management a high level presentation covering the <strong>concept of operation of the various response plans</strong>.</li>
<li>Run a hybrid of <strong>games and quizzes</strong> such as crosswords and find a word.</li>
<li>How creative are your people? Run a <strong>competition</strong> and have people draw a picture, design a meme or write a short poem on what ‘Building Resilience in the Hybrid World’ means to them.</li>
</ol>
<p>Equally important, InConsult encourages all organisations to get involved in Business Continuity Awareness Week 2021.  Contact us if you would like help in planning or conducting events during BCAW 2022.</p>
<p>In the mean time, find out more about BCAW 2022 at the <a href="https://www.thebci.org/event-detail/event-calendar/business-continuity-awareness-week--bcaw--2022.html#theme" target="_blank" rel="noopener noreferrer">Business Continuity Institute’s website.</a></p>
<p>And finally, remember that whatever you do, it’s all about keeping business continuity front of mind and staff aware of your organisations response strategy! Check out InConsult’s <a title="Business Continuity Management" href="https://inconsult.com.au/services/business-continuity-management/" target="_blank" rel="noopener">Business Continuity Management</a> capabilities to find out how we can help you build a more resilient organisation.</p>
<h3>InConsult is a member of the #1 global BC professional association</h3>
<p>We are proud to be a corporate member of the Business Continuity Institute (BCI), the world’s leading institute for business continuity and resilience.  Just like InConsult, the BCI promotes and facilitates the adoption of good business continuity practice to help build more resilient organisations.  Further, the BCI is the leading membership and certifying organization for Business Continuity (BC) professionals worldwide.</p>
<p><img decoding="async" class="alignnone wp-image-7745" src="https://inconsult.com.au/wp-content/uploads/2021/09/BCI-Corporate-member-logo-300x206.jpg" alt="business continuity" width="175" height="120" srcset="https://inconsult.com.au/wp-content/uploads/2021/09/BCI-Corporate-member-logo-300x206.jpg 300w, https://inconsult.com.au/wp-content/uploads/2021/09/BCI-Corporate-member-logo-768x529.jpg 768w, https://inconsult.com.au/wp-content/uploads/2021/09/BCI-Corporate-member-logo.jpg 943w" sizes="(max-width: 175px) 100vw, 175px" /></p>
<p>&nbsp;</p>
<div class='printomatic pom-default ' id='id4480'  data-print_target='body'></div>The post <a href="https://inconsult.com.au/business-continuity-awareness-week-2022/">Business Continuity Awareness Week 2022</a> first appeared on <a href="https://inconsult.com.au">InConsult</a>.]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
