Director Download - Transcript

30 September 2026

KULJA COULSTON: Hello and welcome to Director Download, I'm Kulja Coulston.

BENNETT MASON: And I am Bennett Mason. October marks Cyber Security Awareness Month, but this year there's a deliberate shift, the message from government, awareness alone is not enough. Organisations are being encouraged to turn awareness into practical action and build greater resilience against cyber threats.

KULJA COULSTON: And one of the messages is particularly pointed. Organisations need to adopt an assumed breach mindset. It's time to prepare for when a compromise occurs not whether it might occur.

BENNETT MASON: Cyber threats continue to evolve, and while the headlines often focused on the latest technologies, the fundamental challenge for boards remains the same, understanding whether their organisation can withstand an attack, respond and recover quickly.

So, for directors, what does being genuinely cyber resilient actually look like?

KULJA COULSTON: To help us unpack that, we're joined by Lieutenant General Michelle McGuinness, Australia's National Cyber Security Coordinator. Michelle leads whole-of-government coordination of Australia's Cyber Security Strategy, responses to significant cyber incidents and national cyber preparedness. She's also served in the Australian Defence Force for more than 30 years in senior intelligence, operational and strategic roles in Australia and internationally.

Michelle, welcome to Director Download.

MICHELLE McGUINNESS: Well, thank you so much, it is great to be here.

BENNETT MASON: Now, before we get into cyber resilience and Cyber Security Awareness Month, could you tell us a little bit about your role as National Cyber Security Coordinator; what does the position involve?

MICHELLE McGUINNESS: I lead a small but fantastic team called the National Office of Cyber Security. I am obviously a serving military officer, but I'm seconded into the Department of Home Affairs working to Minister Burke as the Minister for Cyber Security, and the role really, I mean the trigger's in the title, the role is to coordinate our whole-of-government response to nationally significant incidents.

As part of that, my team, the National Office of Cyber Security, will support entities, victim entities, or organisations through identifying, managing and mitigating consequences of an incident. We also drive our national public awareness campaign. I work with a number of colleagues across government on our deterrence posture and also support the implementation of our strategy.

KULJA COULSTON: From a national security perspective, how significant is cyber as a priority for Australia today?

MICHELLE McGUINNESS: It's absolutely a national security issue, and you phrased that exactly. You know, this is not a technical issue, this is not just an issue for our IT folk, this is an issue of national security, national stability and of course prosperity.

I was astounded when I came into the role two and a half years ago to really understand the magnitude and the scale of the situation. Today our business leaders and our Government and our critical infrastructure operators and owners are absolutely on the frontline of national security. We are being probed every day for vulnerabilities and opportunities for all kinds of malicious threat actors to take advantage of Australia- to understand, impersonate, to trick, to extort, it is prolific, and I think the last two and a half years unfortunately we haven't seen a reduction in that appetite. We do know that AI and new technologies and tools make some of these actors faster. It has in some areas, you know, lowered the barrier for entry where they can rely on tools.

KULJA COULSTON: Where does engagement with boards sit in your priorities?

MICHELLE McGUINNESS: We are very small, but I'm often engaging with boards - you know, there are a couple of forums that we do that through. One is we work with a number of leaders across the economy and our [indistinct] organisations, and we do exercises. We exercise from within the National Office of Cyber Security, but I will say that we're also looking at how do we scale that by building exercises that people can access online and test themselves, so they can go through and really exercise themselves as a board before engaging, or as well as engaging in a large exercise with other sectoral peers or even cross-sectoral organisations.

BENNETT MASON: Let's shift now to cyber action month, or as it's been repackaged, cyber action year. This time it's focused on resilience, but that word can mean different things to different people. So, what do you mean by resilience, and I guess what should an organisation be able to withstand, continue doing, if it is attacked, and then recover from?

MICHELLE McGUINNESS: Thank you for highlighting the change. We're absolutely focused on action. It aligns with our strategy and our horizons. Horizon 1, we built the foundation, we actually provided uplift across awareness, we provided good advice for organisations and individuals, we built strong partnerships, we established legislation, we built strong coordination.

We now are moving from a view that we might try to prevent everything to actually being able to withstand the current environment.

KULJA COULSTON: How can a board assess whether their organisation is resilient?

MICHELLE McGUINNESS: There's multiple parts to this. I think it's knowing the right questions to ask. I think it's looking for evidence rather than assurance, asking those questions and looking at the evidence that the organisation is ready.

But when I think about boards and cyber security, it's so clear to me that this is absolutely a board responsibility, this is about culture, it's about resources, it's about prioritisation and it's about risk. And the cyber security risks should be treated just like every other business risk that the organisation is managing, and if they aren't doing it, they need to find someone who can help them do that, find someone to ask the right questions.

Do we know what are your critical assets? Do you have visibility over your critical assets? Have you got the right governance around any AI that you might be using? Have you got the right culture that actually assumes that people are your strongest defence and possibly your greatest vulnerability as well? And build that cyber security culture around - it is everybody's responsibility to understand and recognise cyber security threats. Have you got that culture - and you mentioned it earlier, the philosophy of assumed breach - you know, are you approaching this that you've already been compromised, and therefore, you're building layered defences and you're having a zero trust environment that allows you to actually prevent movement, understand what's happening, have strong logging, all the technical things that my colleagues and friends at the Australian Cyber Security Centre will partner on and publish on.

But it's really important to have that mindset that you assume you are breached and then you respond with your strategy around zero trust.

BENNETT MASON: We would hope that most boards, organisations, senior leaders are aware now of the risk, but let's be really explicit, what's on the line if an organisation or board gets this wrong; what's the worst that can happen?

MICHELLE McGUINNESS: I've seen catastrophic incidents that have actually put businesses into insolvency. Today as - you know, we are a deeply interconnected society, we are digital platforms, and failing to recognise the vulnerabilities that operating in the digital environment can bring can actually mean that you lose access to your data, even worse, lose the ability to control or deliver your services. You can have significant compromises around security, but also personal information which all need to be reported and remediated.

But as I said, the devastating consequences are incredible financial loss, loss of confidence in the marketplace of both yourself and your customers, and it really does have a real emotional toll.

I've dealt and supported organisations who've gone through incidents, and the emotional toll is huge, and the toll on the staff that are looking to resolve and minimise the harm, it's a really frenetic and confusing time when you realise something might have gone wrong, whether it be a technical issue or a malicious incident.

I think that's the other bit of most important advice for a board is to have a response plan and then to exercise it. When we exercise our plans, we really unearth assumptions.

I often say no incident is going to go exactly as exercised, of course, and that's the same in the military: we train and exercise so that we have that learned memory, that experience, and we expose ourselves to new ways that we might be vulnerable and that we could improve and harden, and I think it's just as important in the business space, is to test your plans, to actually go through and practise them, evolve them and then test them again.

KULJA COULSTON: Michelle, it seems to me when you're speaking about this that it is so human. Does that change an organisation's perspective when it is centred around the people involved and what the people themselves can do?

MICHELLE McGUINNESS: I think it does, I think that's exactly right, it is a very human - of course we have technical capabilities and technical responses, but it's a very human area where people make mistakes or feel very vulnerable.

I've spoken to organisations, entities and individuals who feel incredibly exposed and vulnerable in this space, particularly when they've witnessed an incident. We also know that so many incidents are the result of human error.

And back to both what I said about humans being your greatest defence and possibly our greatest vulnerability, as we go into Horizon 2 and we seek to build that resilience across the economy, we've really taken a laser-like focus across three areas, and the first is people as our greatest defence.

So, we're investing a lot in uplifting our people, empowering them to understand, to recognise both risks and threats, but also to have strong cyber hygiene.

I often talk about the very strong physical security culture that we have in Australia. I think really good examples are the way we do road safety, the way we educate our children, the way we do SunSmart, the which we teach our kids how to swim, where to swim in between the flags, how we look our doors. That's a physical security culture that we need to bring in to the digital space. We need to understand that we actually can control our own environment and keep ourselves secure in the digital space as well.

So that's the first lens for Horizon 2 is really that people is our greatest defence. The second is a laser-like focus on critical infrastructure and our critical government systems, and the third is shaping and securing and embracing technology.

KULJA COULSTON: You mentioned that operating in a no-trust environment in that we're not going to assume trust in anything, but within an organisation we also need high trust environments where we trust the information coming to a board. How does a board know whether the information they're receiving from management is giving them a genuine picture of the organisation's cyber resilience?

MICHELLE McGUINNESS: I think looking for evidence rather than assurance, you know, looking at how you're structured, looking at the data around your cyber security culture, for example, understanding that this is a continuous conversation, looking at how connected are your CISOs or your IT staff to their peers within the sector and beyond.

You know, I think information sharing, and it's one of the shields in our strategy, rapid information sharing, threat sharing and blocking is incredibly important, and we take that across the community and drive initiatives. But belonging to a threat information sharing network, being a member of the ASD partnership program, collaborating through community forums and being connected so that you are alert to the threats, that you are learning, that you have got a dynamic, you know, staff who are evolving as the threats evolve, 'cause this is such a fast-paced moving activity, so allowing your team and being confident that your operators are actually getting the both on the job learning but also aware of the environment, having them, you know, attend conferences, events, maintain currency around what's happening and draw connection.

This is an area for collaboration and not for competition because it only hurts every Australian when we have these incidents.

BENNETT MASON: Most directors won't themselves be cyber experts. I think boards have come a long way, there's been a lot of upskilling and there's some great resources from government, the AICD, other organisations, but still, like I said, directors aren't experts. So how can they really understand the cyber threat environment in a meaningful way?

MICHELLE McGUINNESS: Know your networks, know your dependencies, know what your critical assets and outputs are. I think in every incident, data was always where data wasn't supposed to be, and connections were always where connections weren't supposed to be.

So being able to build some assurance and confidence that your team are across your connections and where your vulnerabilities lie.

Also, one of the key learnings that I've seen is communication is critically important, and a big part of that is about trust, transparency, but also your ability to continue to move through an incident, which can be an operational space. So, getting the communications right is also very critical.

How do you build confidence in your team? It's like with any issue, you know, understanding your leaders, spending time with them, asking those questions and ensuring that you have a safe space for people to tell you if they're not sure if there is a risk, inviting understanding around where are we carrying risks, where are we vulnerable, I think that builds that trust, and then identifying how you can invest.

You know, I think there's great advice, and it's for your technical staff out there on cyber.gov.au, but actually asking them, have they followed the latest advisories, have they patched, you know, how confident are they in what vulnerabilities they have, and then having that safe space for them to share where there are concerns and navigate how you prioritise them.

KULJA COULSTON: I wonder if increasingly Internet-connected equipment, fleet vehicles, other, you know, operational technology, other Internet-enabled devices are increasingly coming on to that list of understanding what you've got and understanding how you're managing it, particularly around vehicles. I don't know if electric vehicles are any more vulnerable to cyber-attack than other vehicles that have computers in them, but I'd be interested in your reflections on that holistic understanding of what might be vulnerable to cyber-attack. Is there already with boards, do you think?

MICHELLE McGUINNESS: I mean this is part of our strategy, and we have had successive developments and initiatives to address this exact issue actually. Secure by Design can't just be a slogan, it's actually what needs to be promoted. We need to build security into our policies, our technologies, our processes, and not adding it on.

To that end we have given advice, including from the Australian Cyber Security Centre, on what are secure systems, particularly for small businesses. So, you can go and take a package, whether it be of different vendors, and know that it's got some security.

On the actual IOT devices, we know that all Internet-connected devices can be a vulnerability, so we are working to ensure that even as an Australian population we can make really informed decisions.

We actually legislated at the end of 2024 the minimum mandatory standards for Internet of Things devices, so the IOT devices that you find in your home, but also your routers and your basic equipment.

That legislation has now come into force, and anything manufactured today has to meet those standards. We've now piloted a labelling scheme with a couple of large vendors that will actually show us what is the security of that device.

BENNETT MASON: Let's shift now to what happens when an attack or incident actually takes place. So let's pretend for a moment that the worst has happened, and you are at the centre of a serious cyber incident. What should happen in those first few hours, and I guess for our audience, what is the role of the board and what should be left to management?

MICHELLE McGUINNESS: My best advice is when this happens your first call is to Report Cyber, or 1300 CYBER 1, and you can go online there and report your incident, and that's important for so many reasons, but if you need support from a technical perspective, that's where you can reach out for that support.

It's also really important that we rapidly report these things so that we do have a repository of information, so that if others may be impacted, or this may be a new threat that our intelligence organisations aren't tracking, that they can actually monitor and protect broad parts of the economy.

In an incident the engagement can extend to my team, the NOCS, and this is something that a lot of people ask me, what do we do, how does an incident feel? So I might take the question from that perspective first.

So an organisation who is having an incident, and it's never quite clear to start with, the first story is never the last story, there's a very safe space through recent legislation that allows both the Australian Cyber Security Centre and my office and myself that we are obligated by a limited use obligation.

So, the information that is shared to us in a cyber incident, we are limited in how we can use it, and for my purposes and my office, is that information can be used to minimise the harm and mitigate the consequences. Importantly, it can't be used for regulatory purposes or investigative purposes. So that has built a foundation of trust to have people come forward.

What we've found in the past, and we've had some fantastic Australian companies who've been incredibly authentic and shared their experiences in an incident, and I've had an organisation say to me that in the first 48 hours of an incident, they identified 87 organisations across different layers of government and different stakeholders they had to call and tell. That is not the case today.

That's what my team and I will do when we convene a victim entity and bring together the stakeholders who are either impacted or have a role in supporting the mitigation of that incident.

So, we will bring together the right people, allow a victim to tell their story once and to seek the support and to share across their stakeholders and across government what's happening and where they're at.

It's incredibly powerful when we support an organisation through an incident, it's not our incident, but we will walk along beside them and partner with them in how the incident gets resolved.

My team are fantastic at providing advice on what regulatory obligations they may have during this window, how they might move forward, encouraging and working with them should they wish to make a law enforcement referral, ensuring they have got the right technical advice, and of course ensuring that if we need to bring together other stakeholders, be them competitors, supply chain or other organisations who can help manage their circumstances, that they are available and mobilised.

And it's incredibly powerful. We ran a very large incident only a few months ago where within 48 hours of an incident an international organisation was able to speak to its 600 Australian and New Zealand customers here and share exactly what had happened, what they were doing about it and how to move forward, which builds calm.

So coming back to your question, and I'm not ignoring your question, coming back to your question about what should boards do, boards are going to need to give space to the operators and the technical leaders to actually figure out what's happened, and as I said, the first story is never the final story, so it's going to be evolving.

They're going to have to be thinking very quickly about their communications and who they need support from and who they're going to reach out to. Partnering with the NOCS will support, amplify your communications, but we'll also talk to you about what we've seen work in the past and how we might support you in developing some of those communications, just from experience, and what we - you know, I think it's really important to identify what you know, what you don't know, what those that are impacted can expect, and what you're doing to overcome this, what services and supports are out there.

But the board is going to have to be setting a battle rhythm whilst allowing a very busy and almost certainly very stressed team to figure out what's happened and how they might remediate it.

KULJA COULSTON: When organisations are under pressure, what are the common things that your team's noticing that might go wrong, or that they're needing to learn on the job?

MICHELLE McGUINNESS: Well, a couple of things. One, it can be incredibly complicated, and it can be incredibly hard to figure out what has happened. I think it can also very quickly catch up on you on what the consequences might be, which is why we say when you exercise, actually map out what might be connected and what might occur.

You know, the second, third, fourth and fifth order consequences can be quite obscure, and we've seen that in some outages as well, where we've actually identified the little widget that was impacted that actually prevented the loading of a truck for a distribution centre, everything else was working. You know, what are those unintended consequences that probably need to be managed and mitigated.

I think the communication piece is absolutely key. If you have customers who are relying on your services, or who may now be vulnerable to further exploitation or extortion, making sure that we can be clear, that you can be clear about those consequences and provide advice to ensure that people can protect themselves.

And this really is about understanding and clarity and being calm rather than panicking. But I will say that through almost every incident that has been public in my time as the coordinator, there have been substantial follow-on scams and extortion. This is the nature of the very gross and vile criminal sector out here, which really, if cybercrime was a country, it would have the third largest GDP in the world. It is vile, but the number of people who are believed to have been caught up in an incident that is public, who then receive phone calls, emails, offering for help, "Hey, your data has been exposed in breach X, or in incident Y, click the link to let us know you've got this email" or "Call this" or "I'm here to remediate, can you call me back".

Quick advice on what the company will and won't do is really important. Come out and say, "We will not call you. If you're concerned, call this hotline. Here is where you can get support from something like IDCARE". You know, "We will not email you, we will not send you a WhatsApp message unsolicited". So that message around protecting your customers from further extortion is as important as actually figuring out the clarity of the messaging, cause there is a lot of follow-on scams.

KULJA COULSTON: I imagine that it would be really tricky for an organisation to balance that and weigh up how fast to come back online for instance, say everything came down, how early to go back when you're also trying to contain a cyber-attack. I mean how do you see organisations balancing that and what advice would you have for organisations when they're not quite sure they've got it all, should they come back on and provide those critical services or not?

MICHELLE McGUINNESS: We have a fantastic technical authority, world-leading in the Australian Signals Directorate to the Australian Cyber Security Centre, and that really is their lane, so I encourage people to follow their advice, to reach out and get help.

But these are all things that the board is going to be weighing up, the risk of what is being faced, but they don't have to do it alone. I think that's a really important message, and I think the evolution over the last two and a half years is that we are here to partner with you.

There are resources out there, and if you're unsure, reach out. If there's a critical incident that you need support with, then reach out and get support.

And I think that's really important for the board too. This hopefully goes without saying, but at the height of a crisis this is about identifying what's happening and how we might be able to fix it and how we actually minimise harm, not about who did something wrong.

And in so many cases I absolutely can see that by the grace of God go others. I've had some great conversations with cyber security officers, CISOs, from across the organisations that have had incidents, and what is overwhelmingly consistent is the absolute pressure and the intensive commitment they have to remediating, and at a time like that they need support, and they need to probably have some support to make sure that people know they can go home, they can be switched out, the world is not sitting on their shoulders, you know, basic leadership and management to ensure that you're not exposing yourself to further risk by exhausting people and putting people under really beyond human kind of pressure.

And that's the kind of stories that entities who've had big incidents tell, and by the same token, I know that there is a network out there, whether it be CISO Lens, Cyber Tribe, a whole lot of communities and collaborative forums where people can - I'm sure even through your organisation - where people can reach out for peer support and help, and I think that's incredibly important.

BENNETT MASON: I wanted to go back to something you talked about a moment ago, extortion and the scourge of cybercrime. You've been very firm, very clear on ransom. I know you said recently that nobody should ever pay ransom attacks. Why is that?

MICHELLE McGUINNESS: I'm so glad you asked. And of course it's not against the law to pay a ransom, because we can envisage, of course, a threat to life scenario. But for boards, paying a ransom has not solved any of your problems, and I'm really pleased to engage in a conversation with anyone who tells me it has, because I cannot think of a single problem that it solves.

Firstly, your data has been exposed, your system has been impacted, it may have even been encrypted. You are dealing with criminals, so yes, you may get your data back, but it's not the only copy that you get back. You haven't actually relieved yourself of any of your reporting obligations or your regulatory requirements. You still have to remediate everything that was exposed, whether it was on sold or not, and whether you know it's been on sold or not.

There is no guarantee, again, you're dealing with criminals, that when you pay you'll get your details back, or that you'll be protected from further extortion. In fact the evidence is quite the contrary. There is strong data to suggest that when an entity pays they are known as payers, and this means two things; one, they can sometimes be re-extorted, sometimes by the same organisation or under the same incident, but they will be targeted because they are known as being someone who might pay. They'll be targeted by other criminals as well.

It is so important that we drive a culture, which starts at our resilience, to not be vulnerable to having to pay. If your only choice is to pay to get your data and your system back, it's a really tricky situation.

So that's why we talk about setting up your system so that you do have back-up, so that you can monitor what's happening and you can restore.

But the payment thing, it's a huge issue globally, and Australia is taking a leading role in addressing this through the Counter Ransomware Initiative, where we work with dozens and dozens and dozens of countries to try and drive a framework to limit and to respond to this scourge.

It is really tricky. It's incredibly lucrative, criminals are out there extorting, and the only way we're going to change it is if we can break the system and stop paying back into that cycle of extortion and ransom.

KULJA COULSTON: And the AICD cybersecurity principles encourage boards to pre-plan how issues such as ransomware demands will be handled. Are there other like ransomware that boards should be bringing to the table and pre-planning, Michelle?

MICHELLE McGUINNESS: Yeah, I think there are a range of scenarios, and we do have scenarios in a box online, but if I can just step back to ransomware, there is a ransomware playbook available online as well, both on the Home Affairs website, and the NOCS website and on cyber.gov.au, and it's important to say that part of our efforts to actually combat this scourge has been the legislative change, where we've actually legislated that any entity that has a turnover of more than 3 million annually, who pays a ransom, needs to report.

That reporting is no fault, no liability. It's to allow us to actually understand the magnitude and help build stronger policies against it. But I think that's really important to reinforce as well, that directors know their obligations under law and under regulation when incidents occur.

In terms of other things boards should be doing, you should be practising the exercises that are provided and scenarios that are realistic.

KULJA COULSTON: You mentioned that you and Australian organisations and the Australian Government is working internationally and cooperatively on this, and Australia's increasingly seeking to shape international discussions on emerging technologies, including AI and cyber security through a seat on the UN Security Council. From your perspective, what opportunities are there for greater international cooperation on cyber resilience and where can Australia make the biggest contribution, do you think?

MICHELLE McGUINNESS: Look, I think we're leading in so many areas, and to be clear, the vision of our 2023-2030 strategy is to be a world leader in cyber security, in fact by 2030.

I know that the ecosystem that we have built, particularly around our trusted public partnerships, are absolutely unmatched around the world. We have really great collaboration and trust within sectors and across sectors; initiatives such as the Executive Cyber Council again are the envy of so many.

I think that's really important internationally because our supply chains are international. The challenge here, the cyber security does not respect geography, does not comply with boundaries. So, you know, the next step, or the continuous part of our journey is to ensure that we can collaborate with international partners, either because we have strong interdependencies and concentration of supply chain, but also to ensure that we are moving forward and raising the bar globally.

I know a really important part of our strategy is to call out bad behaviour and drive norms through, when we have the intelligence - the sovereign intelligence to do so and it's in our national interest, and we take that really seriously, because this is not an issue we're going to address on our own.

You know, we can't be secure in an insecure region, or when there are international interdependencies that we have that provide vulnerability. So actually engaging with like-minded partners, driving standards, uplifting our region, supporting the area, sharing lessons, the lessons that we've learnt- and I think lessons learnt are a really great habit to be in, and we certainly have, even out of the National Office of Cyber Security, published a few lessons learnt on the HWLE incident, on our management and support of the Medisecure incident, both of which were novel and in fact so many incidents we have are unique.

We're constantly learning how to do better at responding and doing consequence management, but sharing those public lessons as well, because none of us should learn the same lesson, and I think this is really important around your networks, around your communities, is actually speaking up about the successes you've had, the challenges you've faced, the complexities or the vulnerabilities you've identified and sharing that experience so we can all learn and become more resilient and secure together.

KULJA COULSTON: How like-minded is the international community on cyber security? I imagine it would be tricky to build like-mindedness across the globe on this issue.

MICHELLE McGUINNESS: I don't see that. We partner a lot with international leaders, service providers, telecommunications providers, cyber security companies, organisations that specialise in this, and countries, and you know there are some great international forums, whether it be the Prague Cyber Security Conference, Singapore International Cyber Week coming up next month, conferences like Billington in DC and events like RSA on the West Coast of the US as well. They are huge forums where like-mindeds come together and we are all growing, learning and sharing.

There is actually a great collaborative community of really diverse nations. I have partnered and collaborated and met with European partners, with South Pacific partners, with Estonia, Latvia, Czechia Republic, these are countries that have a very dynamic cybersecurity environment and who have real operational impacts and consequences every day, being much closer to a land war and to Russia and their aggression.

We are all learning and sharing, and there is so much commonality across partners in this space, and so many efforts to drive awareness and uplift knowing that this is a global issue.

KULJA COULSTON: Thank you so much for spending so much time with us on the Director Download.

MICHELLE McGUINNESS: Thank you so much.

Director Download - Transcript

Sign up

Sign up for news and updates from our agency.