More stories

  • in

    Digital initiatives across NSW gain funding boost from 2021-22 Budget

    The New South Wales government handed down its 2021-22 Budget on Tuesday, revealing that digital initiatives across the state will receive handsome handouts.Treasurer Dominic Perrottet said the state’s “secret weapon” to economic recovery from COVID-19 has been its digital government platform, which he claimed was “light-years ahead of the competition”. Off the back of this praise, the state government noted in its Budget papers [PDF] that it would pour an additional half a billion dollars over three years into its Digital Restart Fund, which is aimed at lifting whole-of-government digital capabilities. “That takes our investment to transform digital services for our citizens to AU$2.1 billion,” Perrottet said. Using the additional investment for the Digital Restart Fund, the Ministry of Health will be able to commence phase one of building its single digital patient record; Department of Customer Service will be able to establish its digital platform for certification registries as part of its eConstruction initiative; and the cybersecurity capabilities of the Department of Education, Planning Industry and Environment, Premier and Cabinet, Communities and Justice, Police, Transport for NSW, and the Ministry of Health will be lifted.Under the Digital Restart Fund, AU$500,000 will also be invested towards the design and development of a new database for the NSW Pet Registry.Meanwhile, the Data Analytics Centre will receive AU$38.3 million over four years to provide additional insight that will inform state policy decisions.The Department of Customer Service is set to benefit from a AU$130 million funding boost, the Budget showed. The largest share, according to Minister of Customer Service Victor Dominello, will go towards the work of Service NSW.

    “We want to save customers time and money when interacting with government, and technology is a critical part of the solution as we’ve seen with the Service NSW app, the NSW QR Code system, and Dine and Discover vouchers,” he said.”This funding also allows us to build on popular products like the Digital Driver Licence, FuelCheck, and Park’nPay, while also uplifting our cyber and information security systems.”The Budget also provides AU$660 million in funding to complete the state-wide rollout of the Critical Communications Enhancement Program (CCEP). Under the CCEP, the state government has been developing the public safety network to provide emergency services organisations with a single radio communications network. This latest funding will be the fourth tranche of funding the government has committed to the program since 2016.  “The final 318 (of 675) radio sites will be constructed and brought online delivering full state coverage. Network land coverage will increase from 47% to 85% of New South Wales and an increase in coverage of the state’s population from 96.0% to 99.7%,” the Budget papers said.At the same time, Investment NSW has been allocated AU$416 million, of which AU$35 million will be invested into an entrepreneurship and innovation fund to “promote new ideas, design, and investment while creating sustainable jobs in targeted sectors, precincts, and regional New South Wales”.The state government noted Tech Central and the Westmead Health and Innovation District will each receive AU$10 million. Tech Central will put the funds towards supporting investments, deep tech innovation infrastructure, and a program that will help develop talent needed to address the current tech skills gap. Westmead Health will use the cash to establish new infrastructure that will house a shared lab space and incubator for startups that are looking to commercialise research in biotechnology, diagnostics, and digital health. Furthermore, AU$500 million will be handed out to lift the spend on digital health initiatives, including virtual care and telehealth, while more than AU$214.3 million will be used to boost NSW Ambulance services by upgrading in-ambulance defibrillators that improve electronic medical record integration capabilities between NSW Ambulance and hospital emergency departments across the state. The state government has also signalled its support for regional and rural Australia with a AU$198 million digital connectivity package that will be invested into initiatives such as the Gig State project, the expanded Farms of the Future program, and the mobile coverage project.Looking at how NSW could better engage with the global community, the state government will fork out AU$87.5 million to target industry development programs in key industries such as space, medtech, cyber, fintech, regtech, and agtech. When it comes to education, New South Wales school teachers will soon have access to a new online portal designed to support them in delivering the school curriculum. The interactive digital portal is part of the NSW government’s move to overhaul the state curriculum under a four-year $196.6 million package.”The new portal will help teachers integrate syllabus materials and deliver lessons driven by the latest research and resources, meeting the needs of our students in a way we have never been able to do before,” Minister for Education Sarah Mitchell said.”The new curriculum and the portal will save time for teachers, improve clarity, and make the implementation of the syllabuses even easier. The investment will allow teachers to unlock the curriculum’s potential while arming them with the best resources, multiplying the positive impacts of the reform.”It will be the first major rewrite of the NSW curriculum in 30 years, according to the state government.The new platform currently under development is set to go live in Term 4, 2021 along with new kindergarten to year 2 English and mathematics syllabuses. Additionally, AU$19 million will be invested into refreshing video conferencing and computer facilities at TAFE campuses across the state. The state government has also set aside a further AU$268.2 million as part of its response to the NSW bushfire inquiry. Of that total package, AU$5.2 million will be used for additional drones for firefighting operations, AU$19.9 million will fund the upgrade of the NSW Rural Fire Service (NSWRFS) dispatch systems, and AU$10.6 million for the implementation of a new National Fire Danger Rating System.”This commitment will bolster the future of our fire agencies and preparedness of communities, many of whom of have personally witnessed the devastating effects of fire,” Perrotet said.This latest announcement follows the state government dedicating a total of AU$28 million over four years as part of the 2021-22 Budget into research and development of new technologies and industries to help NSW tackle future bushfires.Perrottet said the funding would be evenly split into AU$7 million chunks under the NSW Bushfire Response R&D Mission.Under the mission, the funding will be used to establish a bushfire technology network for researchers, investors, and industry, as well as work with local small businesses to develop and commercialise bushfire technologies through an early-stage Bushfire Technology Fund to ensure the new technologies are tested by NSW’s frontline bushfire services.Other funding announcements in the state Budget included an additional AU$1 million to enable the development of an interpreting mobile phone application, which will link police and emergency services in the field with on-the-spot interpreters in order to provide timely interpreting support when needed. Related Coverage More

  • in

    Ping Identity acquires SecuredTouch for bot detection

    Ping Identity on Monday announced it’s acquired SecuredTouch, a fraud and bot detection firm based in Tel Aviv. The terms of the deal were not disclosed. SecuredTouch, founded in 2015, has clients in multiple sectors globally. After the acquisition closes, they’ll be able to use SecuredTouch as a standalone product or as part of the PingOne Cloud Platform. The integration into the PingOne platform will give customers better visibility into potentially malicious activity across their digital properties. To detect and thwart bots and account takeover threats, SecuredTouch uses behavioral biometrics, AI, machine learning and deep learning. “Identity isn’t just about knowing who customers are, it’s about knowing when someone is pretending to be a customer,” Ping founder and CEO Andre Durand said in a statement. “As companies undergo massive digital transformation initiatives, the need for seamless, frictionless, and secure identity solutions to confidently understand both those situations is imperative.”Ping is one of several vendors in the competitive identity and access management (IAM) market, which also includes Okta, ForgeRock, IBM, Microsoft and others. The company also announced on Monday a significant expansion of the PingOne platform. Customers can now access the entire Ping Identity portfolio from a unified cloud admin for both workforce and customer identity use cases. Meanwhile, following its acquisition of Symphonic, Ping is enhancing its fine-grained authorization solution. Previously called PingDataGovernance, the updated PingAuthorize provides enterprises with dynamic authorization and attribute-based access control (ABAC). More

  • in

    Amazon Prime Day 2021: Best smart home device deals

    Smart home gadgets are all the rage, but it’s a slippery slope. As soon as you’re done installing your first gadget, you’re in the market for the next, and it can get pretty expensive.  Amazon Prime Day is a good time to pick up your next smart home device for less because there are some fantastic deals out there on a whole range of devices. With that in mind, I’ve trawled through the unbelievable number of deals that are available over Prime Day 2021 — tens of thousands! — and distilled them down into a handful of the best. Deals come and go over the two days, and I’ll be updating this post with fresh deals, so keep checking back. Also, if you find a good deal I’ve missed, feel free to drop me a note (a Twitter DM probably gets the quickest response). 

    70% off

    Add Alexa to your car – Connects to the Alexa app on your phone and plays through your car’s speakers via auxiliary input or your smartphone’s Bluetooth connection. Includes Vent Mount.Designed for the road – With 8 microphones and far-field technology, Echo Auto can hear you over music, A/C, and road noise.Do More with Auto Mode – Turn your phone into a driver-friendly display that complements your Echo Auto. See what’s playing and save time with easy-touch shortcuts to your favorite places, people, and content.

    $15 at Amazon

    62% off

    This bundle contains an Echo Dot (4th Gen) and Sengled Bluetooth Smart Color Bulb.Easily automate your home through smart lighting. Use your voice to turn on your lights, set schedules and change colors. Just say “Alexa, turn on my Lights.”

    $25 at Amazon

    47% off

    FORGET ABOUT VACUUMING FOR UP TO 45 DAYS: A bagless, self-emptying base holds up to 45 days of dirt and debris.FASTER MAPPING: Faster mapping speed for a quicker total home map compared to the previous model (RV1001AE)BETTER CARPET CLEANING: Improved carpet cleaning performance compared to the previous model (RV1001AE)MULTI-SURFACE CLEANING: Multi-surface brushroll pulls in all kinds of dirt and debris from carpets and floorsPHONE OR VOICE COMMAND: Schedule whole-home cleaning or target specific rooms or areas to clean right now with the SharkClean app or voice control with Amazon Alexa or Google AssistantPOWERFUL SUCTION: Deep-cleaning power to take on large debris, small debris, and pet hair on carpets and floors.ROW-BY-ROW CLEANING: Methodically cleans row by row and then navigates room to room for complete home coverage.

    $320 at Amazon

    40% off

    The bundle includes Stick up Cam Battery (White) 2PK and Echo Show 5 (2nd Gen).See, hear and speak to people from your phone, tablet or select Echo device with Stick Up Cam Battery, a battery-powered camera that can be mounted indoors or out.With Live View, you can check in on your home any time through the Ring app.With a Ring Protect Plan (subscription sold separately), record all your videos, review what you missed for up to 60 days, and share videos and photos.

    $169 at Amazon

    20% off

    Dimmable LED lights are great for setting the mood, whether you’re having a romantic night-in, watching a movie, or even playing your favorite video game. Gosund smart light bulbs support adjusting brightness (1%-100%) or set schedules to meet your various expectations.Gosund smart bulbs support voice control via Alexa and Google Assistant; just enjoy the convenience and comfort of automated lighting that you can control with your voice. Tell Alexa to turn off the lights on a cold winter night; you don’t need to get up.

    $22 at Amazon

    20% off

    Gosund smart plugs that work with Alexa and Google Home Assistant. Just give a simple voice command to control your home device with a smart outlet via Alexa or Google Home Assistant. No hub required to install the wifi plug. Gosund Alexa outlet plug works with a stable 2.4GHz network.By setting schedules and timers for your home smart wifi electrical plugs, you can prepare a crockpot meal and get home with dinner’s ready. Get ready to have a smart home and create a customized schedule to automatically turn on/off any home electronic appliances such as lamps, Christmas lights, coffee maker, etc. Please note that the Alexa outlet plug is not suitable for the appliances whose power is more than 10A,1200W (e.g., air conditioner, microwave oven, induction cooker etc.)Gosund Google smart plug can help you control your home appliances from anywhere. Even you are not at home; you also can control your Alexa wifi outlet via Gosund App directly, as long as your phone access a secure 2.4 GHz Wi-Fi network. Ideal for someone who cannot move around very well and needs easy access to turn on/off a deviceSet a group for all Google home outlets and control them in one command. Share your wifi plugs that work with Alexa with all family members in a minute. No more worries, everyone can control them easily.Just plug a device into the mini wifi smart outlet and connect to your secured 2.4GHz network with “Gosund” App. The smart plug uses high-quality materials and technology, such as V-0 flame-retardant thermoplastics, pure copper connectors and advanced PCBA boards. It can avoid fire hazards and provide overload protection to ensure the safety of family members. And ETL certification ensures complete protection.

    $19 at Amazon

    42% off

    See the time, alarms, and timers on the LED display. Tap the top to snooze an alarm.Ask Alexa to tell a joke, play music, answer questions, play the news, check the weather, set alarms, and more.Use your voice to turn on lights, adjust thermostats, and lock doors with compatible devices.

    $34 at Amazon

    33% off

    The Roomba 692 is a great way to begin cleaning your home smarter. Just schedule it to clean up daily dirt, dust, and debris with the iRobot HOME app or your voice assistant.3 Stage Cleaning system & Dual Multi-Surface brushes grab dirt from carpets & hard floors; an Edge-Sweeping brush takes care of corners & edges.Learns your cleaning habits to offer up personalized schedules, while Google Assistant & Alexa allow you to start cleaning with just the sound of your voice.A full suite of advanced sensors allows Roomba to navigate under & around furniture & along edges. Cliff Detect keeps it from falling downstairs.Dirt Detect Sensors alert your robot about dirtier areas of your home, like high-traffic spots, & cleans them more thoroughly.Auto-Adjust Cleaning Head automatically adapts its height to effectively clean carpets & hard floors.It runs for up to 90 minutes before automatically docking & recharging.

    $199 at Apple

    27% off

    Ring

    With its 8-inch HD touchscreen, adaptive color, and stereo speakers, the all-new Echo Show 8 is the perfect hub for your smart home setup.8.0-inch touchscreen 1280 x 800 resolution display.13 MP camera that uses auto-framing to keep you centered.Built-in camera shutter and microphone/camera off button.

    $94 at Amazon

    50% off

    Ring

    It might be tiny, but it packs all the power and punch of a full-sized Echo. There’s a reason why this is Amazon’s most popular smart speaker!Better speaker quality than Echo Dot Gen 2 for richer and louder sound. Pair with a second Echo Dot for stereo sound.Stream songs from Amazon Music, Apple Music, Spotify, Sirius XM, and others.Turn on lights, adjust thermostats, lock doors, and more with compatible connected devices. Create routines to start and end your day.Call almost anyone hands-free. Instantly drop in on other rooms in your home or announce to every room with a compatible Echo device.

    $19 at Amazon

    41% off

    Ring

    Blink Outdoor wireless battery-powered HD security camera with infrared night vision.It runs for up to two years on two AA lithium batteries (included).Store video clips and photos in the cloud with the Blink Subscription Plan or save locally to the Blink Sync Module 2 via a USB flash drive (sold separately).Built to withstand the elements.No wiring or professional installation required.Get motion detection alerts on your phone.See, hear, and speak to visitors with live view in real-time and two-way audio features on your Blink app.

    $224 at Amazon

    36% off

    Certified Refurbished Video Doorbell Pro has been refurbished, tested, and certified to look and work like new and also comes with the same limited warranty as a new device.1080p HD video doorbell lets you see, hear and speak to people from your phone, tablet, or select Echo device. Includes privacy features, such as customizable privacy zones and audio privacy, to focus only on what’s relevant to you.Get notifications whenever motion is detected by customizing your motion zones.With Live View, you can check in on your home any time through the Ring app.

    $89 at Amazon

    30% off

    Ring

    At the heart of any good smart home system is a solid, reliable Wi-Fi connection, and things don’t get much better than the Amazon eero Pro mesh.The Amazon eero Pro mesh WiFi kit (3 eero Pros) replaces the traditional WiFi router, WiFi extender, and internet booster.Capable of covering a 5+ bedroom home with fast and reliable internet powered by a mesh network.Unlike the common internet routers and wireless access points, eero automatically updates once a month, always keeping your home WiFi system on the cutting edge.Eero mesh WiFi network leverages multiple wireless access points to create an incredibly dependable internet experience, all on a single mesh WiFi system.Quick & easy setup.

    $349 at Amazon

    40% amount off

    Ring

    Quickly and easily set up your Ring Alarm by plugging in your base station, connecting to wifi via the Ring app, and placing your sensors in their ideal locations.A great fit for 1-2 bedroom homes.Kit includes one base station, one keypad, four contact sensors, one motion detector, and one range extender.Optional 24/7 professional monitoring with Ring Protect Plus for $10/month.

    $149 at Amazon

    More Prime Day 2021 deals

    We plan to update this guide with more smart home device deals as we spot them.

    Amazon Prime Day 2021

    The best Amazon Prime Day 2021 deals: Windows 10 laptops

    The best Amazon Prime Day 2021 deals: Robots, Raspberry Pi, Arduino, and electronic kits

    The best Amazon Prime Day 2021 deals: Webcams, mics, green screens, and video studio gear

    The best Prime Day 2021 deals: Storage, SSD, and flash drives

    The best Prime Day 2021 deals: Chromebook laptops

    The best anti-Prime Day deals: Sales from Walmart, Best Buy, and elsewhere

    Amazon Prime Day creates halo effect for large rival retailers, email marketing More

  • in

    Georgia fertility clinic discloses breach of patient SSNs and medical info after ransomware attack

    A fertility clinic in Georgia has notified about 38,000 patients that their medical information and other data like social security numbers had been accessed by cybercriminals during a ransomware attack in April.Matthew Maruca, general counsel for Reproductive Biology Associates and its affiliate My Egg Bank North America, wrote in a letter that a file server containing embryology data was encrypted on April 16 after attackers gained access to the company’s systems starting on April 7. 

    The attackers stole names, addresses, SSNs, laboratory results and “information relating to the handling of human tissue,” according to Maruca. Maruca said the company started an investigation in April that lasted until June 7, when they officially confirmed that patient data had been accessed and taken during the attack. While Maruca does not explicitly say that a ransom was paid, the company was eventually able to regain access to the encrypted data and were told by the attackers that “all exposed data was deleted and is no longer in its possession.””In an abundance of caution, we conducted supplemental web searches for the potential presence of the exposed information, and at this time are not aware of any resultant exposure,” Maruca said. “We are continuing to conduct appropriate monitoring to detect and respond to any misuse or misappropriation of the potentially exposed data.”The company offered free monitoring services for those affected and said it hired a cybersecurity company to secure its systems. 

    Multiple studies from cybersecurity firms have shown that even after being paid, ransomware gangs often keep or even post stolen information. A Coveware report from November showed that there have been a number of cases where victims have paid attackers and still had their data published online. Javvad Malik, a security awareness advocate at KnowBe4, told ZDNet that once data has been accessed by criminals, even if an organization can restore from backup or pay a ransom, there is no limitation to what the criminals can do with the stolen data. “This can include selling the data on to other criminals or using the data themselves to attack unsuspecting victims,” Malik said.”Organizations such as fertility clinics may consider themselves as lower risk than, say, hospitals, but the truth is that they have just as much sensitive personal information that is of value to criminals and can disrupt daily operations.”The incident caps off a whirlwind week where multiple healthcare institutions notified patients of breaches that leaked their personal information to attackers or the web. Minnesota Community Care, Cancer Centers of Southwest Oklahoma, San Juan Regional Medical Center, Little Hill Foundation for the Rehabilitation of Alcoholics and St. Joseph’s Hospital in Savannah, Georgia all reported breaches or ransomware attacks that led to the exposure of patient data over the last week. The notices came as US President Joe Biden implored Russian President Vladimir Putin last week to limit attacks on critical industries like healthcare and end protection for groups routinely ransoming hospitals across the US.  More

  • in

    New 'safety by design' toolkit to help the global tech industry care a little bit more

    Image: Office of the eSafety Commisioner
    The Office of the eSafety Commissioner has published a set of assessment tools that it hopes will be used by tech companies to ensure they are building safety into their products and services. While eSafety is an Australian agency, the “safety by design” assessment tools are available globally, as the majority of tech industry innovation occurs far away from Australia’s shores.Released today are two interactive assessment tools: The startup edition for early-stage technology companies and the enterprise edition for mid-tier or enterprise companies.”For tech companies developing platforms that enable social interaction, safety risks should be assessed upfront. Protective measures need to be put in at the start of the product design and development process. We call this ‘safety by design’,” eSafety said.The tools are aimed at helping organisations develop safe products, and assist them to embed safety into the culture, ethos, and operations of their business. The tools and accompanying guidance materials steps participants through five interactive and modules, each with a specific set of questions addressing core safety topics and issues: Structure and leadership; internal policies and procedures; moderation, escalation, and enforcement; user empowerment; and transparency and accountability.The user is served a report at the end of each module, which acts as a safety health check, but also, eSafety said, as a learning resource that can be drawn upon and used to help make refinements or innovations in the future.

    The online tool is around a seven-hour commitment. eSafety said it receives no personal or corporate information or data from those using the tools and it is completely voluntary.”Our entire mission is about helping Australians have safer and more positive experiences online, one of the ways we achieve that is by helping the industry lift their standards and achieve better levels of safety,” eSafety Commissioner Julie Inman Grant told ZDNet.The safety by design initiative kicked off in 2018 with the major tech platforms. In April, eSafety said it was engaged with about 180 different technology companies and activists through the initiative. 40 companies took part in the preview of the toolkit.Inman Grant previously called it a “cultural change issue”; that is, tweaking the industry-wide ethos that moving fast and breaking things gets results.The solution, she said, isn’t the government prescribing technology fixes, rather a duty of care should be reinforced when companies aren’t doing the right thing, such as through initiatives like safety by design. In a former life, Inman Grant was the director of public policy for Twitter in Australia and Southeast Asia; she was also Microsoft’s global director of privacy and internet safety.Speaking with media on the launch of safety by design, Inman Grant said she raised the idea during her time with the Windows-maker.”While I was there, I tried to introduce safety by design as an initiative for Microsoft to take on, they were doing security by design, privacy by design really well and I just wanted them to slip safety in,” she said.”But they felt like they were becoming an enterprise company and were never going to be a social media company, even when I pointed out that Xbox at the time was a bit toxic and Skype was a primary vector for child sexual abuse material, wasn’t something that was taken up.”It was a similar story at Twitter, she disclosed.While the ideal scenario would be to prevent the harms from happening in the first place, behavioural change takes a long time, so eSafety is hopeful initiatives like safety by design can “move the needle and minimise the threat surface for the future”. “Safety by design is fundamental because online safety is a shared responsibility and we needed to find a way to shift the responsibility back onto platforms themselves, just as product liability serves to do around toy and goods manufacturing, or food safety standards,” Inman Grant said.”None of these standards exist in the technology world and I also believe, philosophically, that mandating protections and innovations that companies should take is not going to achieve the right end. “We had to do this with the industry rather than to the industry.”We’d love to see a race to the top in terms of online safety standards and this is precisely what this tool is meant to do.”eSafety is also working with universities on how to insert a safety by design ideal into studies.”Creating that next generation of engineers and computer scientists … to code with conscience or to think ethically and responsibly about what they’re doing,” she said. “We’re working with four different universities right now in embedding elements of this curriculum into multi-disciplinary programs … safety by design won’t just be this tool, it will grow and evolve.”MORE FROM ESAFETYAustralia’s eSafety and the uphill battle of regulating the ever-changing online realmThe eSafety Commissioner has defended the Online Safety Act, saying it’s about protecting the vulnerable and holding the social media platforms accountable for offering a safe product, much the same way as car manufacturers and food producers are in the offline world.eSafety prepares for Online Safety Act with AU$3m software pilot and 20 new staffThe eSafety Commissioner has only been able to action 72 of the 3,600 adult cyber abuse complaints it has received, and it’s hopeful the new Online Safety Act will allow it to do more. More

  • in

    Best early Prime Day 2021 deals: Smart home devices

    Smart home gadgets are all the rage, but it’s a slippery slope. As soon as you’re done installing your first gadget, you’re in the market for the next, and it can get pretty expensive.  Amazon Prime Day is a good time to pick up  your next smart home device for less, because there are some fantastic deals out there on a whole range of devices. With that in mind, I’ve trawled through the unbelievable number of deals that are available over Prime Day 2021 — tens of thousands! — and distilled them down into a handful of the best. Deals come and go over the two days, and I’ll be updating this post with fresh deals, so keep checking back. Also, if you find a good deal I’ve missed, feel free to drop me a note (a Twitter DM probably gets the quickest response). 

    27% off

    Ring

    With its 8-inch HD touchscreen, adaptive color, and stereo speakers, the all-new Echo Show 8 is the perfect hub for your smart home setup.8.0-inch touchscreen 1280 x 800 resolution display.13 MP camera that uses auto-framing to keep you centered.Built-in camera shutter and microphone/camera off button

    $95 at Amazon

    50% off

    Ring

    It might be tiny, but it packs all the power and punch of a full-sized Echo! There’s a reason why this is Amazn’s most popular smart speaker!Better speaker quality than Echo Dot Gen 2 for richer and louder sound. Pair with a second Echo Dot for stereo sound.Stream songs from Amazon Music, Apple Music, Spotify, Sirius XM, and others.Turn on lights, adjust thermostats, lock doors, and more with compatible connected devices. Create routines to start and end your day.Call almost anyone hands-free. Instantly drop in on other rooms in your home or make an announcement to every room with a compatible Echo device.

    $20 at Amazon

    41% off

    Ring

    Blink Outdoor wireless battery-powered HD security camera with infrared night vision.Runs for up to two years on two AA lithium batteries (included).Store video clips and photos in the cloud with the Blink Subscription Plan or save locally to the Blink Sync Module 2 via a USB flash drive (sold separately).Built to withstand the elements.No wiring or professional installation required.Get motion detection alerts on your phone.See, hear, and speak to visitors with live view in real time and two-way audio features on your Blink app.

    $225 at Amazon

    36% off

    Certified Refurbished Video Doorbell Pro has been refurbished, tested, and certified to look and work like new, and also comes with the same limited warranty as a new device.1080p HD video doorbell that lets you see, hear and speak to people from your phone, tablet, or select Echo device. Includes privacy features, such as customizable privacy zones and audio privacy, to focus only on what’s relevant to you.Get notifications whenever motion is detected by customizing your motion zones.With Live View, you can check in on your home any time through the Ring app.

    $89 at Amazon

    30% off

    Ring

    At the heart of any good smart home system is a solid, reliable Wi-Fi connection, and things don’t get much better than the Amazon eero Pro mesh.The Amazon eero Pro mesh WiFi kit (3 eero Pros) replaces the traditional WiFi router, WiFi extender, and internet booster.Capable of covering a 5+ bedroom home with fast and reliable internet powered by a mesh network.Unlike the common internet routers and wireless access points, eero automatically updates once a month, always keeping your home WiFi system on the cutting edge.eero mesh WiFi network leverages multiple wireless access points to create an incredibly dependable internet experience, all on a single mesh WiFi system.Quick & easy setup.

    $349 at Amazon

    40% amount off

    Ring

    Quickly and easily setup your Ring Alarm by plugging in your base station, connecting to wifi via the Ring app, and placing your sensors in their ideal locations.A great fit for 1-2 bedroom homes.Kit includes one base station, one keypad, four contact sensors, one motion detector, and one range extender.Optional 24/7 professional monitoring with Ring Protect Plus for $10/month.

    $150 at Amazon

    More Prime Day 2021 deals

    We plan to update this guide with more smart home device deals as we spot them.

    Amazon Prime Day 2021 More

  • in

    Digital Health Agency says My Health Record risk mitigation work on-track

    Image: Getty Images/iStockphoto
    The system administrator of Australia’s oft-criticised My Health Record has agreed to a number of recommendations made by the Joint Committee of Public Accounts and Audit as part of its probe into the security resilience of the online medical file.The committee in 2019 scrutinised a report from the Australian National Audit Office (ANAO) which pointed out a number of security issues concerning the Australian Digital Health Agency’s (ADHA) My Health Record implementation that otherwise widely gave ADHA the tick as “largely effective”.In a response [PDF] to the committee, ADHA provided an update to its ANAO My Health Record Performance Audit Implementation Plan, which was developed in February 2020. One of the recommendations made by ANAO was that ADHA conduct an end-to-end privacy risk assessment of the operation of the My Health Record system under the opt-out model, including shared risks and mitigation controls. It also recommended for the agency to incorporate the results of this assessment into the risk management framework for the My Health Record system.The agency said it would work with public and private sector healthcare providers, professional associations, consumer groups, and medical indemnity insurers on an “overarching privacy risk assessment”, and incorporate results into the risk management plan for My Health Record. With a privacy risk assessment completed in September, and initial risk register updates flagged as done as of February, the ADHA has given itself until November to complete the risk management work.Another recommendation was that the ADHA, with the Department of Health and in consultation with the Information Commissioner, review the adequacy of its approach and procedures for monitoring use of the emergency access function within the online medical file.

    After delivering a compliance framework and an emergency access compliance plan in February, the ADHA said it will continue to monitor emergency access and engage with system participants to “promote a sound understanding of the legislative provision and relevant reporting arrangements, so that unauthorised use is recognised and reported to the Information Commissioner, as required”.It also flagged November as completion date for this work.ADHA was also asked by ANAO to develop an assurance framework for third party software connecting to the My Health Record system, including clinical software and mobile applications, in accordance with the federal government’s Information Security Manual.”An assurance framework exists for systems (including clinical software and mobile applications) connecting to the Healthcare Identifiers Service and the My Health Record system, including processes to confirm conformance,” ADHA said in response to the recommendation.”The agency will review the standards that apply to these systems, and alignment with the Information Security Manual. We will work with industry to update the assurance framework as required.”The agency also agreed to develop, implement, and regularly report on a strategy to monitor compliance with mandatory legislated security requirements by registered healthcare provider organisations and contracted service providers and develop and implement a program evaluation plan for My Health Record.While not requested by ANAO, ADHA said it is also working to ensure shared privacy risks are identified and appropriately managed between the agency and My Health Record stakeholders and that it is distributing guidance materials and other resources to help with this.It is also mandating software developers undertake a conformance process for the new Security Requirements for Connecting Systems, when requested by ADHA.RELATED COVERAGE More

  • in

    Labor Bill would force Aussie organisations to disclose when they pay ransoms

    Image: iStock
    The federal opposition has introduced a Bill to Parliament that, if passed, would require organisations to inform the Australian Cyber Security Centre (ACSC) before a payment is made to a criminal organisation in response to a ransomware attack. The Ransomware Payments Bill 2021 was introduced in the House of Representatives on Monday by Shadow Assistant Minister for Cyber Security Tim Watts.According to Watts, such a scheme would be a policy foundation for a “coordinated government response to the threat of ransomware, providing actionable threat intelligence to inform law enforcement, diplomacy, and offensive cyber operations”.The ransom payment notification scheme created by the Bill, Watts said, would be the starting point for a comprehensive plan to tackle ransomware. It follows his party in February calling for a national ransomware strategy focused on reducing the number of such attacks on Australian targets. At the time, Watts, alongside Shadow Minister for Home Affairs Kristina Keneally, declared that due to ransomware being the biggest threat facing Australia, it was time for a strategy to thwart it.The Bill introduced by Watts would require large businesses and government entities that choose to make ransomware payments to notify the ACSC before they make the payment. “This will allow our signals intelligence and law enforcement agencies to collect actionable intelligence on where this money is going so they can track and target the responsible criminal groups,” Watts said. “And it will help others in the private sector by providing de-identified actionable threat intelligence that they can use to defend their networks.”

    As laid out in the Bill’s explanatory memorandum [PDF], if an entity makes a ransomware payment, they must provide ACSC with their details, the details of the attacker, and information about the attack to the extent that it is known. Information about the attack includes cryptocurrency wallet details, the amount of the payment, and indicators of compromise. Failure to notify the ACSC would attract a penalty.The ACSC would be required to de-identify the information for the purpose of informing the public and private sector about the current threat environment and disclosing information to Commonwealth, state, or territory agencies for the purpose of law enforcement.Under the Bill, it would be an offence to disclose personal information except for use by law enforcement.”We should be clear … ransoms should not be paid. Ever,” Watts said. “Paying a ransom does not guarantee you’ll be able to quickly bring your systems back online or prevent further disruption, it does not guarantee your data won’t be leaked. “What it does do is provide further resources to the criminal organisations mounting these attacks and create an incentivise for them to carry out more attacks.”But where organisations feel compelled to make these payments, government should be involved.”Using the claim that there has been a 200% increase in ransomware attacks on Australian organisations, Watts pointed to the likes of JBS Foods, UnitingCare Queensland, the Eastern Health hospital network in Victoria, Lion brewers, the NSW Labor Party, Toll logistics — which copped two attacks, Bluescope, PRP Diagnostics, Regis Healthcare, Law In Order, Carnegie Clean Energy, coffee roaster Segafredo Zanetti, and Taylors Wine as examples of why such a Bill is required.JBS paid $11 million in ransom.”Talking to the incident responders combatting this tidal wave of attacks, it’s clear to me that for every ransomware incident you read about in the papers, there are a dozen happening outside public view,” he told the House of Representatives. “These attacks are an intolerable burden on Australian organisations.”According to Watts, the current trajectory of these attacks and the traditional response of asking organisations to implement an “ever-increasing uplift in cyber resilience” was inefficient and not sustainable.”A hospital shouldn’t be forced to use more and more of its scarce resources fighting cybercriminals, it should be using its resources to make sick people better,” he said. “The boards and executive teams of our nation should be able to focus on making investments in its core business that create new jobs and increase shareholder returns, rather than constantly ratcheting cybersecurity investments. “Tackling ransomware may begin with organisational security, but that is not the end of the conversation.”Unfortunately, that’s the state of the policy response to ransomware under the Morrison Government — blaming the victims.”The federal government in March provided advice on how to counter ransomware in Australia, encouraging the use of multifactor authentication and urging businesses to keep software up to date, archive data and back-up, build in security features to systems, and train employees on good cyber hygiene.At the time, Watts called the ransomware paper a missed opportunity. To Watts, it’s not good enough to tell businesses to defend themselves by “locking their doors to cyber-criminal gangs”.”Mandating reporting of ransom payments is far from a silver bullet for this national security problem, but it’s an important first step,” he said on Monday.RELATED COVERAGE More