Skip to content

Menu

Responding to and recovering from cyber attacks

Report 12: 2023–24. Tabled date: 2024-06-04. 14 recommendations published as HTML.

All audit reports

Tabled Report 12: 2023–24

Tabled date
2024-06-04
Report year
2023-24

Information technology Local government Whole of government

Entities audited

Not identified in the published HTML audit scope.

Recommendations

  1. QAO's text Addressed to: all public sector entities

    protect their systems and sensitive information by
    • maintaining a register of all systems and information assets and resources that are critical to their operations
    • updating the register annually and whenever significant changes occur – either to their technology or to their organisational structure (for example, through machinery of government changes)
    • identifying any ‘entry points’ or weaknesses through which threat actors (those who attack systems) could access information or disrupt services
    • conducting regular risk assessments of all critical systems to identify security concerns
    • considering the risks, and clearly specifying expectations and requirements, when setting up or extending contracts for cyber-related services with external organisations 
  2. QAO's text Addressed to: all public sector entities

    formally recognise in key governance documents that responsibility for cyber security rests with the chief executive, or equivalent
  3. QAO's text Addressed to: all public sector entities

    improve and test incident response plans by
    • reviewing their incident response plans (which are for identifying, eliminating, and responding to cyber incidents) annually against better practice frameworks and guidelines
    • ensuring incident response plans integrate with other risk management strategies and plans (such as business continuity plans – which entities use to ensure they can continue to operate in the face of major business disruptions)
    • producing playbooks (sets of procedures for responding to particular incidents) for a variety of risks and cyber incident scenarios
    • ensuring they understand the conditions and requirements of any insurance they take out to protect themselves against cyber incidents. These should be incorporated into their plans
    • testing their incident response and business continuity plans regularly against a range of cyber incident scenarios. This should include testing any external capabilities they plan to rely upon
  4. QAO's text Addressed to: all public sector entities

    improve their crisis communication plans and templates by
    • ensuring crisis communication plans (which outline processes, steps, and roles for communicating with stakeholders during a crisis) include thresholds for contacting key stakeholders and escalating communications to other parties (such as ministers and other government entities)
    • developing templates for a variety of scenarios to support the quality and consistency of internal and external communications during times of crisis 
  5. QAO's text Addressed to: all public sector entities

    gain access to the technical skills required to respond to and recover from cyber incidents by
    • assessing their cyber capabilities (both those in-house and through external arrangements)
    • developing training plans to address gaps, or obtaining access to specialist technical skillsets externally where required (through either the Cyber Security Unit – CSU – or other external providers)
  6. QAO's text Addressed to: all public sector entities

    share cyber threat intelligence and lessons learnt with CSU and other public sector entities as quickly as possible.
  7. QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit

    improves awareness of its products and services and enhances its guidance for developing incident response plans by
    • developing and publishing its strategic plan
    • creating greater awareness of its role and responsibilities and the services it offers
    • refreshing its incident management guideline to reflect current better practice frameworks and guidelines, and enhancing it with practical examples (such as playbooks) for a range of common cyber incident scenarios
  8. QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit

    assists public sector entities in conducting cyber simulations by
    • supporting them in testing their incident response plans
    • where practical, involving external experts, to ensure they become sufficiently familiar with the information and communication technology (ICT) in public sector entities
  9. QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit

    increases public sector cyber skills and capabilities through
    • developing or adopting a cyber security capability framework that public sector entities can apply
    • developing or adopting tools to assist public sector entities in understanding their capability gaps
    • coordinating delivery of a training program that addresses identified capability gaps
  10. QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit

    improves the maturity of information security management systems by
    • working to understand root causes and challenges preventing entities from progressing and improving their information security management systems
    • amending policy requirements to require public sector entities to test their incident responses through cyber security simulations
    • continuing to encourage all public sector entities’ application of the Queensland Government Information Security Policy (IS18:2018) or an equivalent better practice framework.
  11. QAO's text Addressed to: document their assessment as to whether IS18:2018 is applicable to their circumstances, and report this information to CSU. If applicable, statutory bodies

    document their assessment as to whether IS18:2018 is applicable to their circumstances, and report this information to CSU. If applicable, statutory bodies should apply and adopt IS18 requirements.  
  12. QAO's text Addressed to: all government owned corporations and local governments

    document whether IS18:2018 is appropriate for their environments, and if not, which frameworks are being applied to manage information security risks.  
  13. QAO's text Addressed to: the Department of Transport and Main Roads – Cyber Security Unit

    shares cyber threat intelligence and lessons learnt by
    • developing and distributing a process for entities to share cyber threat intelligence from incidents, in a consistent format
    • engaging with public sector entities (including statutory bodies, government owned corporations, and local governments) to raise awareness of communities of practice and to promote sharing of cyber threat intelligence
    • using its unique position to compile and share examples of better practice templates and guidance, such as playbooks.
  14. QAO's text Addressed to: the Department of Housing, Local Government, Planning and Public Works

    increases local governments’ knowledge of available support by partnering with CSU to
    • increase local governments’ awareness of CSU’s services and communities of practice (for sharing cyber threat intelligence) through its existing channels
    • increase local governments’ awareness of CSU’s incident response capabilities and services in the event of a cyber incident
    • encourage local governments to establish agreements with neighbouring councils to increase access to the required capabilities in the event of a cyber-related crisis.

Authoritative report — Queensland Audit Office

Report PDF on QAO

Source: Queensland Audit Office, CC BY 4.0

Catalogue snapshot 2026-10-09

© The State of Queensland (Queensland Audit Office) 2026

Report metadata arranged into a catalogue. Recommendations reproduce QAO's words with HTML formatting simplified; no model summaries. Responses and PDF bodies are excluded.

Report pages checked individually. Recommendations and body-derived entities are withheld for licence exceptions. Images, logos and multimedia are excluded.

No endorsement by the State of Queensland or Queensland Audit Office is implied.

CC BY 4.0 · QAO copyright and exceptions