<!--The Official Report of Parliamentary Debates (Hansard) of the Legislative Council and the House of Assembly of the Parliament of South Australia are covered by parliamentary privilege. Republication by others is not afforded the same protection and may result in exposure to legal liability if the material is defamatory. You may copy and make use of excerpts of proceedings where (1) you attribute the Parliament as the source, (2) you assume the risk of liability if the manner of your use is defamatory, (3) you do not use the material for the purpose of advertising, satire or ridicule, or to misrepresent members of Parliament, and (4) your use of the extracts is fair, accurate and not misleading. Copyright in the Official Report of Parliamentary Debates is held by the Attorney-General of South Australia.-->
<hansard id="" tocId="" xml:lang="EN-AU" schemaVersion="4.0" xsi:noNamespaceSchemaLocation="hansard_1_0.xsd" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2007/XMLSchema-instance" xmlns:mml="http://www.w3.org/1998/Math/MathML">
  <name>House of Assembly</name>
  <date date="2023-10-18T10:30:00+10:30" />
  <sessionName>Fifty-Fifth Parliament, First Session (55-1)</sessionName>
  <parliamentNum>55</parliamentNum>
  <sessionNum>1</sessionNum>
  <parliamentName>Parliament of South Australia</parliamentName>
  <house>House of Assembly</house>
  <venue></venue>
  <reviewStage>published</reviewStage>
  <startPage num="5669" />
  <endPage num="5784" />
  <dateModified time="2024-07-24T15:38:47+09:30" />
  <proceeding continued="true">
    <name>Question Time</name>
    <subject>
      <name>Super SA Cybersecurity Incident</name>
      <text id="20231018c47f902e95a8462c90000423">
        <heading>Super SA Cybersecurity Incident</heading>
      </text>
      <talker role="member" id="5377" referenceid="84fdb62c8e6644ce93a7ff01f8e92c3d" kind="question">
        <name>Mr COWDREY</name>
        <house>House of Assembly</house>
        <electorate id="">Colton</electorate>
        <questions>
          <question date="2023-10-18T00:00:00+10:30">
            <name>Super SA Cybersecurity Incident</name>
          </question>
        </questions>
        <startTime time="2023-10-18T14:15:22+10:30" />
        <text id="20231018c47f902e95a8462c90000424">
          <timeStamp time="2023-10-18T14:15:22+10:30" />
          <by role="member" id="5377" referenceid="84fdb62c8e6644ce93a7ff01f8e92c3d">Mr COWDREY (Colton) (14:15):</by>  My question is again to the Treasurer. When was the cybersecurity incident discovered, and how many current or former public sector employees have been impacted by the cybersecurity incident?</text>
      </talker>
      <talker role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9" kind="answer">
        <name>The Hon. S.C. MULLIGHAN</name>
        <house>House of Assembly</house>
        <electorate id="">Lee</electorate>
        <portfolios>
          <portfolio id="">
            <name>Treasurer</name>
          </portfolio>
          <portfolio id="">
            <name>Minister for Defence and Space Industries</name>
          </portfolio>
        </portfolios>
        <questions>
          <question date="2023-10-18T00:00:00+10:30">
            <name>Super SA Cybersecurity Incident</name>
          </question>
        </questions>
        <startTime time="2023-10-18T14:15:35+10:30" />
        <text id="20231018c47f902e95a8462c90000425">
          <timeStamp time="2023-10-18T14:15:35+10:30" />
          <by role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9">The Hon. S.C. MULLIGHAN (Lee—Treasurer) (14:15):</by>  I thank the member for Colton for his question. They are appropriate questions and they deserve a thorough and accurate answer, and I will provide those to him. But I hope that I have made it clear to him and to the rest of the house that it is my understanding that the breach happened at least in the first instance sometime ago, and certainly sometime before I was advised.</text>
        <text id="20231018c47f902e95a8462c90000426">The other agencies or the people responsible for ICT or cybersecurity management in those agencies may well have been advised in a more timely manner. Regardless, that doesn't excuse the basically unacceptable situation that at least this minister, if not other ministers of those other agencies, weren't appropriately advised at the time in real time so we could do what we are here for and make sure that the way in which government agencies are responding to this is appropriate, timely and thorough.</text>
        <text id="20231018c47f902e95a8462c90000427">My understanding is, given the number of different agencies and hence the number of different types of records that were accessed, that there was potentially a significant number of South Australians who had their data accessed, but I will come back and provide the particulars and the specifics on how many that is and, in particular, what type of data that might be. I would expect that, given the effluxion of time since this incident occurred, there should have been a thorough reconciliation of that by now.</text>
      </talker>
    </subject>
  </proceeding>
</hansard>