November saw CI-ISAC Australia convene its inaugural Annual General Meeting (AGM) on the Sunshine Coast. This governance milestone gave CI-ISAC members a chance to hear first-hand from our Chair, Stephen Beaumont AM and CEO, Dаvid Sandell on current progress and achievements during the first 9 months of operation.
Key AGM highlights:
- 11 of the 12 sectors CI-ISAC membership covers now have intel sharing coverage.
- All internal CI-ISAC functions (Intel, Ops, Business Development, Member Services, Communications) are fully operationalised and Tracey French is our Sunshine Coast based Member Services Lead.
- 15 fortnightly cross-sectoral Threat Intel Forums (TIFs) have been held to discuss cyber-attacks and threats across our CI membership.
- 15 Member Briefings have been run by the National Intelligence Office to raise awareness on relevant threats and provide strategic updates.
- Our Australian-sovereign Threat Intelligence Platform has been operationalised and members connected to the automated threat feed.
- Our first Quarterly Threat Report was issued in Nov ’23, providing an Australian-centric strategic overview of threats observed across CI-ISAC’s membership.
- Our inaugural Industry Advisory Group has been held and member contributions will guide our service and capability uplifts through Q1-24.
- To date we have issued 101 vulnerability and 85 threat advisories, every one of these in a structured format that has been quality assured and provides actionable recommendations for members.
A selection of member AGM feedback by sector:
- Telecoms – In response to the recently announced Australia Cyber Strategy; great to see ISACs mentioned. The amount of work CI-ISAC has done and mechanisms already in place make an excellent board to jump off to deliver value as part of the cyber strategy.
- Telecoms – CI-ISAC needs be clear on what it is and what it is not. Who should join and why. CI-ISAC supports existing initiatives and are not replacing TISN, CTIS, etc.
- Government – Building a membership base across 12 sectors is hard work, let us try to help spread the message to local services such as Water, Transport, etc which exist in our Local Government Authorities (LGAs).
- Transport – As a smaller member, the model is working well and getting a lot of value. We are currently using the Cyber Threat Level in monthly reporting and the intelligence analysis and feedback is great. The improved situational awareness is better than anything else we would usually get.
- Transport – Keen to leverage our own networks to help spread the message and grow the membership.
- Health – WE are getting value in the more Australian-based intelligence provided out of CI-ISAC. Health-ISAC is more focussed on American healthcare companies, with higher volumes of indicators/messages from members, however when these US-attacks go global, the relevant indicators are not easily tied to a specific campaign which makes proactively investigating difficult.
- Health – CI-ISAC enables more of a story around the cyber-attacks impacting Australia, analysis and indicators are tied to relevant attacks, which helps us respond.
- Health – Having Australian-centric attack information helps us get attention internally. While there have only been a handful of AU Health-sector attacks, having the additional information from across Australian Critical Infrastructure sectors helps gain internal stakeholder’s attention, which is valuable.
- Telecoms – Being a mature player, CI-ISAC reports help validate what we’re seeing internally and within our own vertical. Seeing some good information coming through and having additional context is helpful.
- Energy – We have benefitted a lot from threat & vulnerability advisories as we don’t currently have a Threat Intel Platform.
- Energy – CI-ISAC’s approach is helpful to streamline our own advisories to relevant teams internally. CI-ISAC helps summarise threats to CI sectors, and saves a lot of time we would have spent collating all the information and compiling a report ourselves.
- Energy – The Threat intel forums are valuable as they cover covers Threat Actors, threats and emerging trends across CI sectors.
- Energy – The team has been very supportive and responsive to our needs and looking forward to enabling bi-directional sharing once our Threat Intel Platform comes online.
Our key takeaway from member feedback is confirmation that our cross-sectoral approach works well, having a focus on Australia helps gain stakeholder attention and providing threat context is key to effective prioritisation of responses.
Conclusion:
We are at a point where we must be constantly growing, scaling and innovating to thrive. Our volunteers have built an operating concern within less than twelve months without any injection of funding from government or philanthropists. Our strong and unified team is solidifying our intelligence flows, intelligence office, and other capabilities, as it delivers ever more value to members.
However, we remain a not-for-profit, new start-up that relies entirely on members to generate revenue. While that team of volunteers represents our arteries, our members are our lifeblood.
Originally published on LinkedIn, 28th November 2023


