Increasingly, the cyber security landscape feels like “an asymmetric battle”, as Microsoft aptly put it. Cyber security professionals are no longer just contending with solo threat-actors, but coordinated, well-funded, groups of highly trained hackers. Many of these groups are funded by governments. ATO Commissioner of Taxation, Chris Jordan, recently claimed it’s what keeps him up at night. While the battle continues to feel lop-sided, significant strides have been made in Q3 to level the playing field, and hopefully pave the way to a more cyber resilient future.
The State of the Nation: Cyber Security Insights
Domestic and international cyber security headlines were abundant in Q3. The majority of headlines spoke to doom and gloom, with the occasional silver lining, such as the unmasking of the Medibank hacker, and the LockBit takedown (however short lived the LockBit takedown may have been). Regardless of these small glimmers of hope, there have been plenty of instances to validate the concerns of Australia’s top CEO’s, who recently nominated cyber security as the singular most important “risk or trend not getting the attention it deserves, despite rising number of high-profile breaches”.
Simply cast an eye across recent cyber security stats, and you will understand why these CEOs are feeling so unnerved:
- 30,000 new superannuation accounts were established by bots deployed by cyber-criminals in recent months, according to the ATO’s Commissioner of Taxation, Chris Jordan.
- The Australian Signals Directorate (ASD) received 94,000 reports of cyber crime in 2022-2023. That’s approximately 1 report every 6 minutes, which is a 23% increase from the previous reporting period.
- Financial and insurance services are among the top 10 reporting sectors for cyber-crime in 2023.
- The ATO is handling 4.7 million cyber-attacks per month.
- In late March, Aware Super reported that $36 million in member savings had been targeted by cyber criminals.
- In FY24 Q3 alone, Australians have lost approximately $82.1 million to cyber scams.

While the Financial Services Information Sharing and Analysis Centre (FS-ISAC) claims 2023 “was more stable” than previous years, it’s evident that there’s still much to be desired in this space. Aware’s COO, Jo Brennan, aptly summarised the situation — “For any financial services organisation the reality is that we will always be a target”. It’s at times like these that it’s important to look beyond our industry and see how others are managing similar situations.
Partners in crime (detection)
A burst of partnership announcements emerged this past quarter. Indeed, according to one source, 117 cyber security partnerships have been established since the beginning of 2024. There are a couple of particular importance, including:
- The Microsoft and Australian Signals Directorate (ASD)’s partnership, creating a Cyber Threat Intelligence Sharing (CTIS) plugin for Microsoft Sentinel
- The CrowdStrike and Nvidia collaboration, which will see Nvidia’s AI computing services integrated into CrowdStrike’s Falson XDR platform, to deliver “customised and secure generative AI model creation for their shared clientele”
These partnerships are a step in the right direction towards solving a key integration and orchestration problem. By tapping into the specific capabilities of a trusted partner, businesses and customers can reap the rewards of enhanced services and products. We must remember that it’s a team effort to reach this state of play; one where all participants come out on top. Cyber-security is not a zero-sum game. It is in everyone’s best interest to collaborate to solidify the industry, and protect the individual and collective participants within it. The benefits of such cooperation go beyond protecting a business; it has immediate benefits for customers. At a time where customers are expecting greater service and security from their service providers, these alliances are critical.
We are also seeing government-led alliances emerging, including the National Cyber Intel Partnership, which came into effect in late 2023. Already it can boast some big names on its board, including Atlassian, CommBank, Telstra and Woolworths. The goal is to promote cross-pollination of ideas from public and private sectors, in the hopes of creating “next-generation threat blocking capabilities across Australian networks”, as outlined in the 2023-2030 Australian Cyber Security Strategy Action Plan (more on the Cyber Strategy in the Tech Regulation Update). This alliance is of particular importance, as it is the first significant move towards “active co-ordination and collaboration…to deliberately bring our capabilities together and provide real-time protection for Australians against common threats”, as Westpac’s Chief Information Security Officer, Richard Johnson put it.
A Cyber Resilient Future
We expect to see these forms of B2B and government-driven partnerships become commonplace in industries like financial services. The question we must ask ourselves, as FSI leaders, is whether we are ready for it. As we inch closer to a cyber resilient future, we must ask ourselves:
- Do the people in my business understand the threat environment?
- How mature is my business’s cyber security? Do we know our weak spots and priorities for security uplift?
- Does my business have the skills to manage cyber security risks appropriately?
- Is my business meeting or exceeding regulatory expectations of Information Security, as outlined in CPS 234?
- Which organisations in our ecosystem are trusted, reliable and experienced in cyber security? Are we partnering with them already? If not, why not?
Partnerships are a crucial piece to the puzzle of building an ecosystem that is both proactive and responsive, defensive and collaborative, and above all, honest about the reality of the environment in which we are operating. If we’re to level the asymmetric battlefield, it’s something we must do collaboratively.
This article was produced as part of The Quarterly – Data and Technology in Superannuation, Q3 FY24
For more information about anything you’ve read here, or if you have a more general inquiry, please contact us.
Key Contributors:

Kevin Fernandez is General Manager, Market Strategy and Propositions at Novigi, and is based in the Melbourne office.

Sophie Bowen-James is an analyst in the Market Strategy and Propositions team at Novigi, and is based in the Sydney office.
