Geoscience Australia has apparently failed to implement the mandatory cybersecurity requirements for a company of its size and importance. This negligence has left the organization highly vulnerable to possible cyberattacks such as data theft, ransomware, denial of service, and other advanced persistent threats. The agency was taking almost 30 days to install critical patches whereas the current requirement to do the same is just 48 hours. The audit also pointed out that while all these agencies had implemented or were progressing towards the implementation of the four mandatory mitigation strategies, they were indifferent towards implementing the non-mandatory strategies.”]
Source: https://hackercombat.com/geoscience-australia-highly-vulnerable-to-cyber-attack/