How are you mitigating the biggest cyber-security risks in Australia?

Alan Herrity  | September 7, 2020

By Alan Herrity  | September 7, 2020 | Cyber Security

How are you mitigating the biggest cyber-security risks in Australia?
Australia’s new strategy, the risks, and the security measures your business need to make.

Cyber security is more crucial now than ever, as we consistently move everything we own – as businesses and individuals – online. On 6 August 2020, the Australian Government released Australia’s Cyber Security Strategy 2020, highlighting its investment and action plans to strengthen the protection of Australians, business and infrastructure.

At Momentum Search, our regular Virtual Round Tables are designed to bring expert advice and know-how to senior management and executives across Australia. On 13 August, as a key and vital part of Australian business, we set out to explore the new strategy with guest speaker Daniel Pludek. An experienced CIO with a keen interest in security, Daniel has over 20 years’ experience delivering over $300m worth of programs across risk, compliance, and technology, working with regulators across industries ranging from banking to energy.

Throughout the discussion, Daniel highlighted key issues with the strategy, uncovering that whilst the Government is correctly investing in this area, education remains as one of the best ways to combat threats. On the other hand, Daniel agreed this becomes more challenging and complex for larger organisations as the organisational change, training and embedment of new behaviours will take time, whilst cyber criminals are becoming more sophisticated every day.

What can we do within organisations to mitigate cyber security risks?

Our conversation also drew focus to the importance of having a minimum cyber security baseline for each organisation. In the discussion, a C-level attendee explained that the organisation he works for had gone too far with too many processes and controls, meaning employees would find it challenging to be compliant. Since, these measures have been reduced, still ensuring that they have the right processes and controls in place to be effective, while allowing employees to work as productively as possible.

Looking to the future, it is likely to be small and medium business that face some of the biggest challenges, as we come to understand how the Government intends to assist small and medium-sized organisations in uplifting their capability. Additionally, it will be key to observe how cyber criminals, both in Australia and abroad, are going to be caught and prosecuted.

At the round table, conversation shifted to an open debate around how to combat insider threat attacks, how to address the increase of DDoS attacks, the increased use of AI and ML, and where the weakest links in an organisation may be. The subject of Bug Bounty programs was also raised, with the key benefits these are bringing to organisations.

Key steps for businesses

To protect against cyber security risks, Daniel offered key suggestions of what companies can individually do. These include:

1.   Empower your business’ Chief Information Security Officer.
2.   Shift the focus away from tools to ensuring that you have the right information, processes, and approach to risks in place to secure your environment.
3.   Ensure that staff are vigilant and continuously trained/tested (Daniel is a big believer in using baiting to get a better level of understanding of your organisation).
4.   Begin Zero Trust Architecture where possible.
5.   Understand and value the importance of cyber security being embedded into your procedures, processes, and ways of working, rather than this being an audit item. This is not an IT problem; this is a corporate problem that we all need to address.

To find out more and download Daniel’s presentation in full, follow the link below.

Alan Herrity

By Alan Herrity March 17, 2026
Case Study - Test Director - Core Banking Migration
By Alan Herrity March 17, 2026
Case Study - Process Architecture & Governance Leader
By Alan Herrity March 17, 2026
Case Study - PMO Director – Confidential Initiative
By Alan Herrity March 17, 2026
Case Study - Program Director – Core Banking & Operations
By Alan Herrity February 4, 2026
Case Study - Innovation and Accelerated Delivery Director
By Alan Herrity February 4, 2026
Case Study - Director - Enterprise Testing
By Alan Herrity February 4, 2026
Case Study - IT Director – Application and Technical Services
By Alan Herrity January 16, 2026
Case Study - Program Manager, Data Centre Exit Program
By Alan Herrity January 16, 2026
Case Study - Senior Manager, Enterprise Data
By Alan Herrity January 13, 2026
Appointing Interim Program Leaders Early Shapes Better Outcomes Organisations rarely struggle to agree which programs matter. Where they often struggle is deciding when to bring a senior delivery leader into the conversation. Recently, an Executive asked me for advice on how to structure and resource a critical program of work. The organisation is still at an early stage. The business case was being drafted, funding discussions were ongoing, and there was understandable desire to ensure success. The question wasn’t about whether leadership was required. It was about timing. My view was clear: the right Program Director should be involved as early as possible to help you shape success. The risk of waiting too long In some programs, senior delivery leadership is introduced once funding has been approved and the initiative is formally underway. By that point, key decisions have already been made. Assumptions have already been made; Timelines, budgets, and benefits are often framed around optimism rather than delivery reality. When a Program Director joins at that stage, they inherit constraints rather than help shape success Their role becomes one of mitigation rather than design. This is rarely intentional. It’s usually driven by a desire to control cost or avoid “over-engineering” too early. But in practice, delaying leadership often creates the very inefficiencies organisations are trying to avoid. What early hiring enables Bringing an experienced Program Director in early changes the nature of the conversation. Instead of planning in isolation, organisations benefit from delivery-informed thinking at the point where it matters most. At an early stage, the right interim leader can help: Shape a credible business case grounded in what is realistically deliverable. Clarify the level of funding required and the benefits that can genuinely be achieved within that investment Define the team, skills, and capability required to deliver, rather than retrofitting roles later and potentially blowing out budgets which were incorrect in the first place. Identify the organisational change impact early and work with the change practitioner/team to ensure success. Why interim leadership is often the right choice For many organisations, this level of program leadership capability doesn’t exist in-house, particularly for niche initiatives. Even where strong leaders are available, they are often already committed to existing priorities. Interim Program Directors offer a practical alternative. They bring a wealth of expertise, sector-specific experience, and the ability to operate independently of internal politics. Importantly, they can focus on setting the program up for success without the land and expand model of the consultancy world. Used well, interim leadership at this stage is not an added cost. It is an investment in clarity, realism, and better decision-making. Shifting the mindset The organisations that consistently deliver complex programs well tend to share one characteristic. They involve delivery expertise early, before plans become fixed and difficult to challenge. They treat program leadership as a strategic design input, not just a delivery function. That shift in mindset often determines whether a program starts with momentum or spends its early phases recovering from avoidable missteps. A question worth considering If you’ve been involved in shaping or sponsoring major programs, you’ll likely have seen both approaches in action. When have you seen prompt hiring of an Interim Program Director materially improve the outcome of a program? And where has waiting too long made recovery harder than it needed to be? Those experiences are often where the most valuable lessons sit. Please contact Alan Herrity to explore this topic further.