Responding to and recovering from cyber attacks
Report 12: 2023–24. Tabled date: 2024-06-04. 14 recommendations published as HTML.
Tabled Report 12: 2023–24
- Tabled date
- 2024-06-04
- Report year
- 2023-24
Entities audited
Not identified in the published HTML audit scope.
Recommendations
QAO's text Addressed to: all public sector entities
protect their systems and sensitive information by- maintaining a register of all systems and information assets and resources that are critical to their operations
- updating the register annually and whenever significant changes occur – either to their technology or to their organisational structure (for example, through machinery of government changes)
- identifying any ‘entry points’ or weaknesses through which threat actors (those who attack systems) could access information or disrupt services
- conducting regular risk assessments of all critical systems to identify security concerns
- considering the risks, and clearly specifying expectations and requirements, when setting up or extending contracts for cyber-related services with external organisations
QAO's text Addressed to: all public sector entities
formally recognise in key governance documents that responsibility for cyber security rests with the chief executive, or equivalentQAO's text Addressed to: all public sector entities
improve and test incident response plans by- reviewing their incident response plans (which are for identifying, eliminating, and responding to cyber incidents) annually against better practice frameworks and guidelines
- ensuring incident response plans integrate with other risk management strategies and plans (such as business continuity plans – which entities use to ensure they can continue to operate in the face of major business disruptions)
- producing playbooks (sets of procedures for responding to particular incidents) for a variety of risks and cyber incident scenarios
- ensuring they understand the conditions and requirements of any insurance they take out to protect themselves against cyber incidents. These should be incorporated into their plans
- testing their incident response and business continuity plans regularly against a range of cyber incident scenarios. This should include testing any external capabilities they plan to rely upon
QAO's text Addressed to: all public sector entities
improve their crisis communication plans and templates by- ensuring crisis communication plans (which outline processes, steps, and roles for communicating with stakeholders during a crisis) include thresholds for contacting key stakeholders and escalating communications to other parties (such as ministers and other government entities)
- developing templates for a variety of scenarios to support the quality and consistency of internal and external communications during times of crisis
QAO's text Addressed to: all public sector entities
gain access to the technical skills required to respond to and recover from cyber incidents by- assessing their cyber capabilities (both those in-house and through external arrangements)
- developing training plans to address gaps, or obtaining access to specialist technical skillsets externally where required (through either the Cyber Security Unit – CSU – or other external providers)
QAO's text Addressed to: all public sector entities
share cyber threat intelligence and lessons learnt with CSU and other public sector entities as quickly as possible.QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit
improves awareness of its products and services and enhances its guidance for developing incident response plans by- developing and publishing its strategic plan
- creating greater awareness of its role and responsibilities and the services it offers
- refreshing its incident management guideline to reflect current better practice frameworks and guidelines, and enhancing it with practical examples (such as playbooks) for a range of common cyber incident scenarios
QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit
assists public sector entities in conducting cyber simulations by- supporting them in testing their incident response plans
- where practical, involving external experts, to ensure they become sufficiently familiar with the information and communication technology (ICT) in public sector entities
QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit
increases public sector cyber skills and capabilities through- developing or adopting a cyber security capability framework that public sector entities can apply
- developing or adopting tools to assist public sector entities in understanding their capability gaps
- coordinating delivery of a training program that addresses identified capability gaps
QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit
improves the maturity of information security management systems by- working to understand root causes and challenges preventing entities from progressing and improving their information security management systems
- amending policy requirements to require public sector entities to test their incident responses through cyber security simulations
- continuing to encourage all public sector entities’ application of the Queensland Government Information Security Policy (IS18:2018) or an equivalent better practice framework.
QAO's text Addressed to: document their assessment as to whether IS18:2018 is applicable to their circumstances, and report this information to CSU. If applicable, statutory bodies
document their assessment as to whether IS18:2018 is applicable to their circumstances, and report this information to CSU. If applicable, statutory bodies should apply and adopt IS18 requirements.QAO's text Addressed to: all government owned corporations and local governments
document whether IS18:2018 is appropriate for their environments, and if not, which frameworks are being applied to manage information security risks.QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit
shares cyber threat intelligence and lessons learnt by- developing and distributing a process for entities to share cyber threat intelligence from incidents, in a consistent format
- engaging with public sector entities (including statutory bodies, government owned corporations, and local governments) to raise awareness of communities of practice and to promote sharing of cyber threat intelligence
- using its unique position to compile and share examples of better practice templates and guidance, such as playbooks.
QAO's text Addressed to: the Department of Housing, Local Government, Planning and Public Works
increases local governments’ knowledge of available support by partnering with CSU to- increase local governments’ awareness of CSU’s services and communities of practice (for sharing cyber threat intelligence) through its existing channels
- increase local governments’ awareness of CSU’s incident response capabilities and services in the event of a cyber incident
- encourage local governments to establish agreements with neighbouring councils to increase access to the required capabilities in the event of a cyber-related crisis.
Authoritative report — Queensland Audit Office
Source: Queensland Audit Office, CC BY 4.0
Catalogue snapshot 2026-10-09
© The State of Queensland (Queensland Audit Office) 2026
Report metadata arranged into a catalogue. Recommendations reproduce QAO's words with HTML formatting simplified; no model summaries. Responses and PDF bodies are excluded.
Report pages checked individually. Recommendations and body-derived entities are withheld for licence exceptions. Images, logos and multimedia are excluded.
No endorsement by the State of Queensland or Queensland Audit Office is implied.