Medibank accepts findings of hack review, refuses to say what those findings are

Medibank accepts findings of hack review, refuses to say what those findings are
Medibank says it’s accepting all the suggestions of a evaluate into final 12 months’s cyberattack that uncovered the delicate private particulars of tens of millions of Australians, however will not reveal what these suggestions are.

In a press release on Friday, the medical insurance big stated it had obtained the findings of an investigation by Deloitte into the hack.

“Deloitte has made recommendations to enhance Medibank’s IT processes and systems,” the assertion learn.

Medibank says it’s accepting all the suggestions of a evaluate into final 12 months’s cyberattack. (Steven Siewert)

“A number of recommendations have already been implemented, and Medibank intends to implement all recommendations not already undertaken, along with other enhancements previously planned by Medibank.

“Medibank will even proceed to evaluate its cyber safety governance preparations, recognising the growing prevalence of cybercrime and the necessity to meet the continuing expectations of our clients.”

However, a spokesperson confirmed to 9news.com.au the company won’t be making the findings of the review, or the review itself, public, sighting security concerns.

“The Deloitte incident evaluate contains confidential and delicate details about the cybersecurity measures that Medibank has in place to guard clients and different knowledge from malicious cyberattacks,” the spokesperson said.

People walk past a Medibank outlet in Sydney.
While it is accepting the findings of the report, Medibank isn’t making the report or its recommendations public. (AFR / Louise Kennerley)

“We do not suppose it is within the pursuits of our clients or the broader Australian group to publicly launch their findings given the safety dangers this might pose, not solely to Medibank however different Australian companies.

“We will continue to share lessons from the cybercrime with other Australian businesses, where we can.”

The cyberattack in October led to the non-public data of as much as 9.7 million of the well being insurer’s present and former clients being dumped on the darkish net.

Surprise title takes crown on Australia’s ‘most trusted’ manufacturers checklist

The data stolen ranged from clients’ names and dates of beginning to medical knowledge.

Deloitte was commissioned by Medibank to conduct its evaluate into the assault in November.

The well being insurer is at present going through two class motion lawsuits over the cyberattack, one introduced on behalf of present and former clients, the opposite from the corporate’s shareholders.

It stated it intends to defend the proceedings in each circumstances.

Sign up right here to obtain our every day newsletters and breaking news alerts, despatched straight to your inbox.

Source: www.9news.com.au