Cyber security
Cyber security is a shared responsibility across Queensland Health. As a manager, you play a key role in safeguarding sensitive patient data, organisational systems and your team from cyber threats.
Understand your role
Managers play a vital role in fostering a culture of cyber awareness. While technical expertise isn't required, your leadership is essential to help your team understand the importance of cyber security and adopt safe practices.
Your responsibilities:
-
Set clear expectations for secure behaviour.
-
Lead by example by following cyber security policy and best practices and completing mandatory cyber security training.
-
Normalise cyber security discussions in team meetings and day-to-day operations.
Why it's important
Cyber security is not just an IT issue - it's also a people and process issue. Your actions and messaging directly influence how your team behaves online and how they respond to potential threats.
Key cyber security behaviours to reinforce
Consistently reinforcing safe behaviours helps prevent cyber incidents and protects sensitive information.
Be vigilant and report suspicious emails
Phishing and social engineering target sensitive information. Spot and report suspicious emails to protect Queensland Health.
Keep devices and passwords safe
Protect devices and login credentials to prevent unauthorised access to Queensland Health systems. This will reduce the risk of cyber-attacks like ransomware or identity theft.
Only use approved tools and systems
Using approved solutions helps manage risk, protect data and meet compliance requirements.
Manage access controls
Ensure access to systems and data is limited to only those who need it to prevent unauthorised access to sensitive data and systems.
Handle data with care
Queenslanders trust us with sensitive information and proper handling is essential to prevent data breaches and protect our reputation.
Encourage reporting
Encourage early reporting of errors or suspicious activity to prevent small issues from escalating. Foster a no-blame culture where employees feel safe to speak up.
Use AI responsibly
Ensure AI tools are used in a way that aligns with ethical standards and protects sensitive information.
Manage vendors, suppliers and external services
Third-party products, services and vendors can introduce cyber risks if they are not assessed and managed appropriately.
Stay informed
Cyber risks are always changing. Stay up to date with current threats, alerts and training opportunities.
Respond effectively to cyber incidents
As a manager, your response to a cyber incident is crucial. Acting quickly and decisively can minimise harm and prevent further damage.
Examples of potential issues that should be reported immediately:
- A phishing email has been clicked, or a suspicious link has been accessed.
- Sensitive information has been shared with the wrong recipient.
- A device or user account credentials is lost, stolen or compromised.
- You notice unusual activity or something doesn't feel right.
Manager role in reporting an incident
Steps to escalate effectively:
Contact the Cyber Security Culture and Awareness team for more information. They can help support you in raising awareness within your team.
Website: Cyber Security - ehealth Queensland