<!--The Official Report of Parliamentary Debates (Hansard) of the Legislative Council and the House of Assembly of the Parliament of South Australia are covered by parliamentary privilege. Republication by others is not afforded the same protection and may result in exposure to legal liability if the material is defamatory. You may copy and make use of excerpts of proceedings where (1) you attribute the Parliament as the source, (2) you assume the risk of liability if the manner of your use is defamatory, (3) you do not use the material for the purpose of advertising, satire or ridicule, or to misrepresent members of Parliament, and (4) your use of the extracts is fair, accurate and not misleading. Copyright in the Official Report of Parliamentary Debates is held by the Attorney-General of South Australia.-->
<hansard id="" tocId="" xml:lang="EN-AU" schemaVersion="4.0" xsi:noNamespaceSchemaLocation="hansard_1_0.xsd" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2007/XMLSchema-instance" xmlns:mml="http://www.w3.org/1998/Math/MathML">
  <name>House of Assembly</name>
  <date date="2022-12-01T11:00:00+10:30" />
  <sessionName>Fifty-Fifth Parliament, First Session (55-1)</sessionName>
  <parliamentNum>55</parliamentNum>
  <sessionNum>1</sessionNum>
  <parliamentName>Parliament of South Australia</parliamentName>
  <house>House of Assembly</house>
  <venue></venue>
  <reviewStage>published</reviewStage>
  <startPage num="2631" />
  <endPage num="2703" />
  <dateModified time="2023-07-06T08:48:10+09:30" />
  <proceeding continued="true">
    <name>Question Time</name>
    <subject>
      <name>Frontier Software Cybersecurity Incident</name>
      <text id="20221201930fd59a238c474590000607">
        <heading>Frontier Software Cybersecurity Incident</heading>
      </text>
      <talker role="member" id="6898" referenceid="38856d262aa84b0080f5548c318f1adc" kind="question">
        <name>Mr FULBROOK</name>
        <house>House of Assembly</house>
        <electorate id="">Playford</electorate>
        <questions>
          <question date="2022-12-01T00:30:00+10:30">
            <name>Frontier Software Cybersecurity Incident</name>
          </question>
        </questions>
        <startTime time="2022-12-01T14:47:43+10:30" />
        <text id="20221201930fd59a238c474590000608">
          <timeStamp time="2022-12-01T14:47:43+10:30" />
          <by role="member" id="6898" referenceid="38856d262aa84b0080f5548c318f1adc">Mr FULBROOK (Playford) (14:47):</by>  My question is to the Treasurer. Can the Treasurer provide an update on what steps have been taken to recover costs and ensure the future security of South Australian government employee information?</text>
      </talker>
      <talker role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9" kind="answer">
        <name>The Hon. S.C. MULLIGHAN</name>
        <house>House of Assembly</house>
        <electorate id="">Lee</electorate>
        <portfolios>
          <portfolio id="">
            <name>Treasurer</name>
          </portfolio>
        </portfolios>
        <questions>
          <question date="2022-12-01T00:30:00+10:30">
            <name>Frontier Software Cybersecurity Incident</name>
          </question>
        </questions>
        <startTime time="2022-12-01T14:47:56+10:30" />
        <text id="20221201930fd59a238c474590000609">
          <timeStamp time="2022-12-01T14:47:56+10:30" />
          <by role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9">The Hon. S.C. MULLIGHAN (Lee—Treasurer) (14:47):</by>  I'm grateful to the member for Playford for asking this question because it's an important question, and I'm also grateful for the opportunity to be able to make a contribution today. It's an historic day. It's not every day a former Premier is set to announce their retirement from the parliament and the commissioning of a by-election, but we look forward to that later this afternoon.</text>
        <text id="20221201930fd59a238c474590000610">
          <event kind="interjection">Members interjecting:</event>
        </text>
      </talker>
      <talker kind="speech" role="office">
        <name>The Speaker</name>
        <house>House of Assembly</house>
        <text id="20221201930fd59a238c474590000611">
          <by role="office">The SPEAKER</by>:  Order! The Treasurer has the call and will not engage in digression or personal reflection.</text>
      </talker>
      <talker role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9" kind="answer" continued="true">
        <name>The Hon. S.C. MULLIGHAN</name>
        <house>House of Assembly</house>
        <electorate id="">Lee</electorate>
        <portfolios>
          <portfolio id="">
            <name>Treasurer</name>
          </portfolio>
        </portfolios>
        <text id="20221201930fd59a238c474590000612">
          <by role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9">The Hon. S.C. MULLIGHAN:</by>  Members may recall that on 10 December last year, just after 2 o'clock on the Friday afternoon of that day, the former Liberal government announced publicly that there had been a cyber attack on Frontier Software, the software provider looking after the majority of the South Australian public sector payroll. As it turned out, more than 80,000 current and former state government employees had their personal details illegally accessed.</text>
        <text id="20221201930fd59a238c474590000613">I provided an update to the house on this issue on 18 May this year, giving clarity on the actions of both the former government, in trying to rush this extraordinary information out late on a Friday afternoon towards the end of the week, but particularly the impact on the affected people, the level of data illegally accessed and the actions of the Department of Treasury and Finance dealing with the issue.</text>
        <page num="2668" />
        <text id="20221201930fd59a238c474590000614">I am pleased to report that all affected employees identified as having suffered a data breach from Frontier have been directly notified now and they have had assistance provided to them. The Department of Treasury and Finance has also worked with key third parties, including the Australian Taxation Office and Super SA to mitigate the resultant identity risks.</text>
        <text id="20221201930fd59a238c474590000615">As of Monday this week, agreement was reached with Frontier Software on a compensation amount of approximately $1.75 million to the state government from Frontier. This compensation is in recognition of the ongoing consequences and impacts of the cybersecurity incident in late 2021. It also includes the recovery of direct third-party costs incurred by the department in responding to the cyber incident in the previous financial year.</text>
        <text id="20221201930fd59a238c474590000616">Some of this amount will be received by the state in a lump sum before the end of the calendar year, and the rest will be progressively recouped contractually through reduction in fees charged by Frontier for the provision of payroll software and services until 30 June 2024.</text>
        <text id="20221201930fd59a238c474590000617">I am pleased to report that, since November, Frontier has made significant investment in improving its cybersecurity capability, over the last 12 months. This is including implementing 15 improvement recommendations made by CyberCX, which was engaged by Frontier in an advisory capacity following the incident.</text>
        <text id="20221201930fd59a238c474590000618">The Department of Treasury and Finance is also working closely with Frontier to implement a number of other cybersecurity enhancements recommended by PricewaterhouseCoopers following the independent review into the data breach. These enhancements can be summarised as the eight key recommendations made by PwC requiring action by Frontier.</text>
        <text id="20221201930fd59a238c474590000619">It is important for me to report that five of these recommendations have been addressed, including the secure deletion of all South Australian government personal information previously held on Frontier's corporate network. It is important to remind the house that this was a breach of Frontier's network not a breach of the South Australian government's payroll systems. The three remaining recommendations are expected to be resolved by the end of this calendar year.</text>
        <text id="20221201930fd59a238c474590000620">Importantly, there are still no confirmed cases of any impacted individual suffering the consequences of identity theft or fraud as a consequence of this 2021 cyber incident.</text>
      </talker>
    </subject>
  </proceeding>
</hansard>