Skip to content
DPS: Audit report finds major cyber security shortcomings

DPS: Audit report finds major cyber security shortcomings

Canberratimes.Au June 11, 2026

High staff turnover within the Department of Parliamentary Services has contributed to myriad shortcomings in the cyber security processes expected to protect parliamentarians and their staff.

or signup to

The Australian National Audit Office on Thursday found the department was only partly effective in its oversight of cyber security measures, months after revelations it had handed a tranche of emails to a law firm that had recently been targeted in a major attack.

In 2023, now secretary Jaala Hinchcliffe ordered a number of departmental staff emails be provided to law firm, HWL Ebsworth, as part of an investigation into senior staff.

The decision was made despite a draft risk assessment raising concerns the removal of data from the parliamentary system and the security of the firm, after it was targeted earlier in 2023.

Ms Hinchcliffe said she thought the risk assessment was "overrated" because the necessary mitigation measures were already in place.

It was later revealed that a subcontractor brought in under this arrangement did not have the necessary security clearance.

The audit office focused instead on the department's broad approach to cyber security and found that it had not sufficiently implemented seven of the eight mitigation measures considered to be crucial by the Australian Signals Directorate.

Known as the "essential eight", these criteria include steps such as requiring multi-factor authentication for online services, regularly backing up data, patching vulnerabilities within 48 hours and disabling features of web browsers that may pose security risks.

While the Department of Parliamentary Services self-assessed that it had implemented all of these strategies to the standard required, the audit office contradicted this.

"The department is relying on risk-management approaches to address the gap between implemented and required controls," its report found.

The audit office also singled out the department's high turnover in ICT areas, noting it "creates risk that essential cyber security strategies may not be managed consistently and effectively".

"The department has experienced considerable staff movement in recent years, with both the [Chief Information Officer and and Chief Information Security Officer] commencing in their roles in 2025," the report reads.

"As of February 2026, 55 per cent of staff in the Cyber Security Branch had been with the department for less than 12 months."

The report also refers to a "high-profile cyber security incident" in 2019, in which Australia's major political parties were targeted during a cyber attack on the department's computer network.

Liberal Nationals senator James McGrath said the findings should serve as a "wake-up call" for Parliamentary Services.

"The report paints a troubling picture of outdated risk registers, high staff turnover in key ICT roles, and a failure to adequately comply with cyber security frameworks," Senator McGrath, the Coalition's shadow special minister of state, said.

"Of particular concern is the finding that DPS has not appropriately reflected the differing security requirements of parliamentarians, staff and other users within its IT environment."

The department agreed to two recommendations for improvements and said it had begun a review of its cyber security governance and risk assessment processes in December 2025.

It received additional funding in the 2026 budget to "address critical cyber, information security and operational resilience risks" in the Parliamentary Computing Network.

Miriam Webber is a federal politics and public sector reporter, with an interest in integrity, transparency and accountability in government. She has been a member of the federal political bureau since 2023, and previously worked as the city reporter. Reach her on Signal at miriamwebber.01 or at [email protected]

Miriam Webber is a federal politics and public sector reporter, with an interest in integrity, transparency and accountability in government. She has been a member of the federal political bureau since 2023, and previously worked as the city reporter. Reach her on Signal at miriamwebber.01 or at [email protected]

Extracted Entities