<!--The Official Report of Parliamentary Debates (Hansard) of the Legislative Council and the House of Assembly of the Parliament of South Australia are covered by parliamentary privilege. Republication by others is not afforded the same protection and may result in exposure to legal liability if the material is defamatory. You may copy and make use of excerpts of proceedings where (1) you attribute the Parliament as the source, (2) you assume the risk of liability if the manner of your use is defamatory, (3) you do not use the material for the purpose of advertising, satire or ridicule, or to misrepresent members of Parliament, and (4) your use of the extracts is fair, accurate and not misleading. Copyright in the Official Report of Parliamentary Debates is held by the Attorney-General of South Australia.-->
<hansard id="" tocId="" xml:lang="EN-AU" schemaVersion="4.0" xsi:noNamespaceSchemaLocation="hansard_1_0.xsd" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2007/XMLSchema-instance" xmlns:mml="http://www.w3.org/1998/Math/MathML">
  <name>House of Assembly</name>
  <date date="2023-10-18T10:30:00+10:30" />
  <sessionName>Fifty-Fifth Parliament, First Session (55-1)</sessionName>
  <parliamentNum>55</parliamentNum>
  <sessionNum>1</sessionNum>
  <parliamentName>Parliament of South Australia</parliamentName>
  <house>House of Assembly</house>
  <venue></venue>
  <reviewStage>published</reviewStage>
  <startPage num="5669" />
  <endPage num="5784" />
  <dateModified time="2024-07-24T15:38:49+09:30" />
  <proceeding continued="true">
    <name>Question Time</name>
    <subject>
      <name>Super SA Cybersecurity Incident</name>
      <text id="20231018f7891d3e4f154b10b0000428">
        <heading>Super SA Cybersecurity Incident</heading>
      </text>
      <talker role="member" id="5377" referenceid="84fdb62c8e6644ce93a7ff01f8e92c3d" kind="question">
        <name>Mr COWDREY</name>
        <house>House of Assembly</house>
        <electorate id="">Colton</electorate>
        <questions>
          <question date="2023-10-18T00:00:00+10:30">
            <name>Super SA Cybersecurity Incident</name>
          </question>
        </questions>
        <startTime time="2023-10-18T14:17:16+10:30" />
        <text id="20231018f7891d3e4f154b10b0000429">
          <timeStamp time="2023-10-18T14:17:16+10:30" />
          <by role="member" id="5377" referenceid="84fdb62c8e6644ce93a7ff01f8e92c3d">Mr COWDREY (Colton) (14:17):</by>  My question is again to the Treasurer. What steps has the Treasurer taken since being informed of this cyber incident?</text>
      </talker>
      <talker role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9" kind="answer">
        <name>The Hon. S.C. MULLIGHAN</name>
        <house>House of Assembly</house>
        <electorate id="">Lee</electorate>
        <portfolios>
          <portfolio id="">
            <name>Treasurer</name>
          </portfolio>
          <portfolio id="">
            <name>Minister for Defence and Space Industries</name>
          </portfolio>
        </portfolios>
        <questions>
          <question date="2023-10-18T00:00:00+10:30">
            <name>Super SA Cybersecurity Incident</name>
          </question>
        </questions>
        <startTime time="2023-10-18T14:17:23+10:30" />
        <text id="20231018f7891d3e4f154b10b0000430">
          <timeStamp time="2023-10-18T14:17:23+10:30" />
          <by role="member" id="4842" referenceid="78a22826e43d4639bdfa63b5f3ef73f9">The Hon. S.C. MULLIGHAN (Lee—Treasurer) (14:17):</by>  My understanding is that the lead agency for responding to the cybersecurity breach is that business unit within DPC which is responsible for the government's across-government cybersecurity and ICT coordination efforts. I certainly made clear to my department that I expected that we firstly would have a thorough understanding for all of the agencies that were impacted about what the breach was, how many people were impacted, what notification had been taken not only to those agencies but more specifically and more importantly to those South Australians, or indeed other parties, if there were other parties, but particularly to those South Australians who might have had their data accessed.</text>
        <page num="5698" />
        <text id="20231018f7891d3e4f154b10b0000431">As I referred to I think in my first or second answer on this topic, it was able to be made clear to people who may have been affected what steps were being undertaken to firstly secure or resecure their data and, secondly, provide them avenues to make sure that they could go about securing their own personal information or their other data which might have been accessed. If there were remedial efforts that needed to be taken—either by the government agencies, by the service provider or the individuals themselves—that all of that was being set out. So my initial reaction was going to the heart of those issues, putting those questions, making those demands to my department.</text>
      </talker>
    </subject>
  </proceeding>
</hansard>