Recent Blog
Recent Blog
Showing posts with label Government. Show all posts
Showing posts with label Government. Show all posts

31 October 2019

Indigenous voices send vital message on intergenerational trauma

Author :

A collaboration of Indigenous voices gathered in Perth to discuss solutions on the impacts of intergenerational trauma stemming from forced removal policies.

There are currently 20,421 indigenous children in out of home care, representing 37.3 per cent of the out of home care population. Since Kevin Rudd’s apology to Stolen Generation survivors, the rate of forcible children has increased massively.

Whilst there are concerns that children being placed in out of home care may experience the same loss of identity and connection to family, country and culture, this should not be cited as a second Stolen Generation.


Healing is part of life and continues through death and into life again. It occurs throughout a person’s life journey as well as across generations”, said Helen Milroy, Professor at the University of Western Australia and Commissioner for the National Mental Health Commission, when speaking at the National Indigenous Social and Emotional Wellbeing Forum in Perth.

“Healing is not just about recovering what has been lost or repairing what has been broken. It is about embracing our life force to create a new and vibrant fabric that keeps us grounded and connected, wraps us in warmth and love and gives us the joy of seeing what we have created,” said Helen.

The four-day conference, run by Akolade in partnership with Yokai and Two Point Co, focuses on the wider issues relating to social and emotional wellbeing and mental health in Indigenous communities. Tuesday 29 October, kicked off with a pre-conference focused on supporting Stolen Generations survivors.

Indigenous Elders and community leaders from different walks of life and different parts of Australia shared the message that something needs to be done. The impact of previous forced removal policies are impacting today’s younger generations, and Australia’s seeing higher child removal rates than ever as a result.

The impact of intergenerational trauma is profound and growing, and if nothing is done it will continue to tear families and communities apart.

Maisie Austin, Chief Executive Officer of the Northern Territory Stolen Generations Aboriginal Corporation, highlighted the ongoing impacts of forcible removals on Stolen Generations survivors. In order to help survivors of Stolen Generations and their families heal, and stop ongoing cycles of negativity, intergenerational trauma needs to be effectively addressed. It is important that the impacts of forcible removal on families and communities are fully understood in order to find ways forward.

“It’s important to address the impacts that past forcible removal policies are having on today’s younger generations, and to ensure history isn’t forgotten or repeated,” Austin said. Governments, communities and organisations need to collaborate and share knowledge and resources to address these issues. Intergenerational trauma is a growing problem, which can sometimes lead to different issues, such as family breakdowns, resulting in children being placed in out-of-home care.

The remaining days of the conference will see further discussions on breaking down the stigma and shame attached to mental illness in Aboriginal and Torres Strait Islander communities, vital to opening the conversation and enabling better access to services. With cases of Indigenous suicide increasing at an alarming rate, Australia urgently needs to rethink the services currently being offered and implement strategies to increase Social and Emotional Wellbeing.

If individuals and communities can work together and better understand the different constructs of mental health, then a holistic approach to social and emotional wellbeing with culturally inclusive services may be better accessed. It’s important that everyone works together to build trust in services and start the conversation on mental health, because mental health is everyone’s business.

Want to find out more about upcoming events and industry updates? Join our mailing list here.

Written by: Mimmie Wilhelmson

Mimmie grew up in Sweden and first came to Australia as a backpacker after high school. After travelling around the country for two years she returned to Europe and pursued a Bachelor’s degree in Journalism in London. But the longing for Australia and the sun became too strong. After having worked for some time in the media industry, Mimmie decided to make a change and swap the news for conferences. She now gets to do what she loves the most, meeting new people and keep learning about cultures and issues while producing conferences on current topics.



21 February 2019

Business Process Compromise - Insider and Outsider Threat

Author :


Last year I was at a security symposium in Sydney where I bumped into a friend working for a large security vendor. We discussed the latest industry rumours, trends and shared a few interesting stories on breaches - this is when I asked if his firm performs risks assessments for Business Process Compromise (BPC) to which he replied - "No". I was now thinking how on earth do they perform security assessments when they only look at one half of the big picture? Surely the other big half is equally as important? Don't believe me? - what about the big cyber-heist of Bangladesh's Central Bank which I will use as a case study a little later.

Interestingly I was told by my friend that often business process compromise results in fraud which is the responsibility of Human Resources, Finance, and Risk Officers. For those of you that have not heard of business process compromise - simply explained means that someone with deep knowledge (subject matter expert) as to how a process works typically in finance, sales, procurement and payroll, can bypass security controls, checks and balances, to commit financial theft, sabotage or intellectual property theft.

What makes business process compromise difficult to detect and counter is that it's usually performed by employees in sensitive or senior roles. These people are trusted to do the right thing and this makes it extremely difficult to identify who of them is biased to this type of behaviour - worst still, these employees know processes extremely well, including how security is configured on their specific systems such as finance, payroll and accounts payable - so monitoring for malicious actions and detection is that much more difficult. 

For those of you new to the concept of business process compromise it is important to note that there are two classes of malicious actors - the insider which is typically an employee or contractor employed by your firm, and the outsider which typically is someone outside of the organisation such as a terminated or ex-employee, consultant, technology vendors, supplier, etc. Both of these classes of the malicious actor have intimate knowledge of how your sensitive corporate functions work, for example, the financial platform consultant knows how your accounts payable process works front-to-back because they configured and installed the system based on your processes which they helped you capture and articulate. 

Now, should the financial platform consultant switch to the dark side (criminal intentions) and decide to commit fraud by issuing you a fake invoice using clever means such as Business Email Compromise (BEC) and social engineering - more than likely they will succeed, and more than likely detection will take many months if not longer.

The case involving the cyberheist at the Bangladesh Central Bank (BCB) was a combination of both insider and outsiders threat actors staging a sophisticated attack which involved hacking, social engineering, corruption of employees, intimate knowledge of the central bank operations, and deep knowledge of international financial banking platform - SWIFT

In a nutshell, what happened, malicious actors hacked into the SWIFT platform owned by the Bangladesh Central Bank and sent fraudulent instructions to their major bank account held at the Federal Reserve Bank of New York. The instructions were to transfer $1 Billion US dollars to offshore bank accounts in low compliance jurisdictions such as Philippines, Sri Lanka, Macau, etc. The majority of the payments were stopped, but $81 Million dollars made it through and ended up in fake bank accounts in a Philippine bank which was then transferred to a local casino and never to be found - the trail ended at the bank! Very sophisticated operation.


In summary, the following key points were identified as weaknesses which led to the cyber heist, I have summarised a few:

  • Insider threats were involved in some capacity - somehow malware got onto a "supposedly" secure machine, the only mechanisms available were email or USB memory stick. There are suggestions that someone most probably inserted an infected USB memory stick into the SWIFT server which allowed cybercriminals to create an undetected backdoor. The cybercriminals were probably accessing the infected server from anywhere from a few weeks to a year.
  • Insider threats most probably disabled the CCTV camera which was not working on the weekend the criminal activity took place. There are tell-tale signs of sabotage which investigators believed strongly pointed to the central bank employees or building maintenance contractors.
  • Outsider threats had intimate knowledge of global banking and settlements processes as they specifically targeted the central bank on a Friday which in Bangladesh is a bank holiday, this meant nobody was available to detect and stop the fraudulent fund's transfer.
  • Outsider threats built and deployed malware which specifically targeted the SWIFT payment platform - suggestions were that nation-states might have been involved as the malware was extremely sophisticated in that it covered the criminal's trail. 
  • Outsider threats knew that the Federal Reserve of New York has limited manpower to manually check for fraudulent payments, and also had knowledge that there was no 24 x 7 hotline to alert their employees to halt fraudulent payments.
  • Outsider threats created fake bank accounts 1 year before the heist of the Philippine bank - they corrupted the branch manager to create the fake accounts, and immediately settle the transfer and convert it to cash. (She was arrested - but was probably a minor player in the grand heist)


Now the interesting bit - how do you assess your vulnerability to business process compromise? The approach I advise is to identify your key business process, whatever they are - payroll, HR, accounts payable, finance, etc. Bring together diverse groups from within your firm, and even your trusty security consultants and ask them to let their minds run free - ask the question: if they were to commit the ultimate white-collar crime within your firm what would it be? how would they do it? Take note as the scenarios might sound far-fetched and impossible, but with time and resources, they are more than likely achievable.

Some methods to reduce exposure to business process compromise includes:
  • Listen to employee concerns in regard to insecure processes and systems.
  • Performing criminal and employment history background checks on new employment candidates, this includes contractors.
  • Monitoring employee movements - in some industries employees are asked to detail their travel plans. 
  • Monitoring of employee wealth - financial theft is sometimes identified by employees living beyond their means.
  • Regular physical and cyber security assessments. (Yes, physical security too!)
  • Auditing of employee access to facilities - both CCTV footage and electronic keycard access logs.
  • Using simple Machine Learning (ML) based in a wider context such as incorporating physical security and IT system logs. (Out of hours access to sensitive platforms might give away signs of possible fraud)
  • Cyber security awareness - teach employees tell-tale signs of phishing and social engineering. Build a culture where employees are encouraged to challenge suspect instructions.
  • Human resources should be vigilant with employee behaviour in particular with repeat offenders that don't respect company policies


I hope you found this article of interest. Feel free to contact me if you would like to further discuss - I look forward to a gold old chat!


Written by:
John Kouroutzoglou

14 February 2019

Major peak bodies could be doing more to inspire trust in donors

Author :



In the last month alone, the charity and not-for-profit sector has ended up in the media for all the wrong reasons. Financial mismanagement seems more prevalent than ever as major peak bodies’ attempt – but fail – to bring the sector back into positive light.

The latest scandal to hit the sector is the official charging of the ex-NSW RSL manager after a two-year investigation found he stole more than $238,000 in donations. Before that, The House of Hope Recovery Centre was stripped of its charity status following charges against its former General Manager for stealing more than $12,000.

Days before Christmas, a former Guide Dogs manager was found to have stolen more than $200,000 from the charity for home renovations – back in July, that same charity was awarded most trusted organisation by Australia’s Readers Digest.

Akolade
The Australian Charities and Not-for-profits Commission (ACNC), and its boss Dr Gary Johns, has been quoted in the media for months now, citing that the charity has done wrong but they cannot disclose anything due to privacy concerns – which is well and good until the charity’s wrongdoings gets splashed across front pages anyway.

Other than a column here and there, major peak bodies aren’t really doing much more to convince the public that there are still charities worth trusting. As more foundations end up in news articles for governance and financial mismanagement, people become more and more frustrated and dissociated with the Australian social sector, which in turn deters donors from supporting charities that haven’t done anything wrong.

Although updating governance standards – as done recently by the Australian Institute of Company Directors – could be a start, it isn’t enough to inspire donors to continue supporting the scandal-free organisations that are affected nonetheless.









07 December 2018

My Health Record- greater than the sum of its errors?

Author :











The technology behind My Health Record has been described by international experts as nothing more than “digitised paper”. Harvard Medical School International Healthcare Innovation professor Dr John Halamka claims it uses such out of date technology that crucial patient information may be unable to be ready or shared by computers.

“The My Health record is a noble idea but the standard they chose is from 1995; it uses PDFs, it’s not computable, it is just digitised paper,” he told News Corp Australia.

An ADHA spokesperson defended the software, replying that “Over 100 clinical information systems are accredited to connect to My Health Record and they consume structured data such as SNOMED [Systematised Nomenclature of Medicine] codes on diseases and AMT [Australian Medicines Terminology] codes on medicines. This functionality is driving decision support and other logic in those systems through those computable codes.” 

This criticism comes after My Health Record’s privacy chief quit early last month amid claims the organisation and Health Minister Greg Hunt’s office have not been taking the concerns of internal privacy experts seriously enough.

Whole Ms Hunt and ADHA have refused to comment, Ms Hunt has since joined ANZ Bank.
The agency has since announced citizens will be able to opt out of My Health Record at any time and permanently delete their records.

Previously, if an individual had not opted out by the given deadline, it couldn’t later be deleted- only made ‘unavailable’.

This decision comes in response to widespread criticism and concerns from citizens regarding the privacy of their data.

Mr Hunt has defended the scheme, arguing it offers greater benefits to citizens than the sum of these challenges.

“If you are a mum, you will be able to have access to the vaccination records of your children,” Mr Hunt told the Nine Network.

“If you have got older parents and you don’t know what medicines they have been on, and they are in an extreme moment in a hospital, the emergency department will be able to protect them and ensure they are not taking something for which they have an allergy.

“It is common sense and something that six million Australians have adopted. It will give all Australians access to their medical records, which should be a basic right.”


Still interested? Stay tuned for information on upcoming conferences and summits by following us on Facebook @ Akolade Aust 

Written by: Claire Dowler
Claire is the manager of Akolade’s government and digital portfolio. She’s passionate about emerging digital trends, particularly in the public sector. In her spare time she enjoys picking up heavy things and putting them back down again and animals are her favourite kind of people. 










Follow me on LinkedIn for information regarding future Akolade events as well as future blog posts @ Claire Dowler


07 November 2018

The 11th Social Media in Government Conference: A Twitter bird's-eye view

Author :














The Social Media for Government conference provided a platform for social media managers to share an array of information for us to both take in as well as disseminate. As you would expect from a conference about social media, attendees hit the many channels of their social media accounts to engage with one another. Twitter in particular.

So here is my review of the event - with a bit of help from the Twitter bird.


















I'm not sure if the conference turned out so wild that people were swinging from the chandeliers, however, thanks to Akolade Australia, the 11th Social Media in Government conference was a joy to be a part of. With many people sharing their experience and knowledge to the over 100 delegates that attended the two day event.

I really enjoyed delivering a presentation about the importance of Archiving Social Media, covering facts and information that may have been overlooked by the audience beforehand, not anymore. Covering items that included the responsibilities social media users in government hold, especially when deleting a post. Items such as, "does your social media policy allow it?" or "Does legislation allow it?" These are all questions that specified government bodies must think about before making a rash decisions in the form of deleting content. We need to learn from mistakes made in the past, and there have been quite a few to learn from.












Throughout the two-day conference there was a total of 20 speakers, of which most spoke about how government bodies can best engage with their communities on social media. There were many interesting strategies different organisations used that was displayed through case studies.


















Jessica Ryan from Australian Securities and Investments Commission gave some useful insights on how to get the whole organisation behind the social media effort. From how to convey your ideas to other teams who aren’t across social media, to reporting to those both up and across the chain in order to engage the audience.

Ryan Vanderhorst from Vic Emergency delivered a very popular presentation in which he explained to the audience how social media can connect those in need with those who can help. Key takeouts highlighted how social media is the quickest way to disseminate information these days, and thus can be a lifesaver when unexpected emergencies hit. Did you know that Emergency Management Victoria can get from 20,000 to 30,000 messages on a weekend when emergencies hit. Talk about a twitter storm. And yes, we too joined in on the twitter party…



















The conference also held its fair share of international speakers, notably the keynote, Dirk Von Holleben, a Social Media manager from the German Ministry of Defence was the international keynote speaker. He has done a great job with engaging with his audience through their very active social media channels. YouTube was his main topic of interest, as he found great success in using it to engage with the younger generation.















And as always, the conference had guest speakers from Facebook and Twitter. Talking about what's new and upcoming on their platforms. Sharing some trivia that you may not have heard of. Did you know that the average Facebook user scrolls through more than 100 meters of feed per day. That's higher than the statue of liberty. So how do you get them to stop and read your post? Luckily, that was something that Kylie Mackey, Senior Events & Marketing Officer, City of Greater Geelong covered.










All in all, the 11th Social Media for Government left us all with a lot to think of.
Jay Batten posted a tweet that I think summarised the event perfectly.


















If you missed the event but would like to have a discussion around social media in Government, we’re happy to have a coffee and conversation as one thing is certain; social media is here to stay and increasing in complexity and importance so we need to be across the management of it!

Written by: Damian Martina, Sales Manager at Brolly

An accomplished executive-level sales professional offering 15 + years’ experience analysing current and potential business processes to identify clear opportunities for improvement, meeting business objectives, ensuring client satisfaction and increasing employee productivity. 












12 October 2018

What is Digitisation Anyway?

Author :













Digitisation means different things to every organisation. I’ve just returned from an Inter-parliamentary Union (IPU) mission to Tuvalu to undertake an ICT capability assessment for the Tuvalu Parliament. Tuvalu is a small and isolated pacific nation, which is travel brochure beautiful and full of wonderful people. Tuvalu has little in the way of natural resources, and is heavily dependent on imports and international aid. Getting a computer working after something goes wrong is challenging in its own right. To the Tuvalu Parliament, just being able to store parliamentary documents electronically, in a central repository, and then being able to share these documents with the 15 members of parliament electronically, would seem like digitisation.

When Gartner introduced the concept of the Nexus of Forces back in 2014, it was hard for many of us to appreciate the impact the Internet of Things was going to have on our personal and professional lives. Why on earth would you want an internet connected fridge?! The constant improvement in consumer technology, and the increasing ease at which previously complex tasks can be completed by anyone with a powerful enough smart phone, led to an expectation of the same ease and choice we have in our personal lives to also be available in our professional lives.

New Zealand Parliaments journey of digitisation started back in 2013. We started with the vision of “enabling a mobile workforce to work securely anywhere, with fit for purpose tools”. Like most organisations, we knew we would need multiple streams of activity.

We knew we needed to rebuild the parliamentary network to support a mobile workforce. We also knew we would probably want to move to the Cloud at some point, so the network design needed to support this type of traffic. It was when we replaced our 30 year old PABX with Skype for Business (SfB) we had our first reality check – don’t believe anyone who says you don’t need to have some form of Quality of Service (QOS) in place to make good quality phone calls using SfB! Four years later we have just about completed the network refresh – it is hard to make substantive change around the busy business of parliament.

Another major stream of activity was our Line of Business applications. Many of the systems supporting the House were built on old technologies that were either no longer supported or becoming end of life. With an eye to one day moving to the Cloud, we defined a Technical Reference Model (TRM) for parliament that ensured the same frameworks, languages and technologies were used for all of parliament’s applications. Rightly or wrongly we choose SharePoint as the common platform on which to deploy our applications. We now have a stable and supportable stack of applications that, with a little bit of work, can be redeployed to the Cloud when we are ready to do so.

Security is a major concern in itself. Parliament naturally becomes a target for cyber activity by the very nature of what it represents. We are required to implement the highest level of security our users will tolerate, without impeding members rights around parliamentary privilege. Security is a constant tension against usability, and too often if you leave it up to the security experts to determine what is needed, you end up with something not very useful to your users. You can achieve a lot in the security space just through implementing a good user education programme.

Which brings me to our last major stream of activity – supporting our users. User expectations are constantly increasing against a back drop of evolving technology in the consumer space. If you can’t make it easy for them, they will work around you – implementing their own solution is just a google search and credit card away. More than ever you need to be talking to your users, understanding what they are trying to achieve and help guide them towards a solution you will be able to support them on, will also meeting your own standards and requirements.


I’m still not sure if my fridge will ever be connected to the internet, but it is starting to looking more compelling five years on from when I first heard it suggested, and, at some point, the choice may not even be mine to make.

Still interested? Stay tuned for information on upcoming conferences and summits by following us on Facebook @ Akolade Aust 

Written by: Michael Middlemiss, Chief Information Officer at Parliamentary Service

Michael has worked within the Information Technology industry for over twenty years and has acquired significant experience across a wide variety of roles, technologies, industries, and business processes. 

Michael has been involved in all levels of Information Technology, from hands on design and requirements gathering, through to roles involving Strategic Planning and thought leadership.
Michael is a seasoned people manager who has built several of his teams from scratch.