Federal government departments and agencies must do more to protect information from hackers, according to a new report from the Australian Government's auditor general.
The auditor general in his report notes that 70 findings were received from the audit. Of these, 56% concerned the management of IT controls, mainly privileged users. These are users who can make significant changes to IT systems, while having the ability to bypass security settings and access information that not all users have. These findings increase the risk of unauthorized changes to systems and data.

The Australian Signals Directorate (Cybersecurity agency) frequently reports to the government. In several of them, it has emphasized that the primary target for hackers is user accounts like these, i.e. privileged users.
This is why the auditor said that organizations should first focus on IT to avoid problems. According to his report, privileged user access should be restricted and, when this is not possible, recorded, audited and monitored regularly.
Cybersecurity has been a hot topic recently, with reports of hackers gaining access to the Australian National University database, and last February, they breached the Parliament network. Investigations conducted by Australian agencies appeared to investigate whether China, among other state actors, was behind the attempt .
The parliamentary network was used normally by all MPs and their staff. When a politician was asked publicly about the breach, he said that he had been informed and was satisfied with the samples he had received so far, but that this attack had woken everyone up.
