A decade after the last census disaster, the security of this year’s count is at risk. The Australian Bureau of Statistics (ABS) is facing scrutiny over its preparedness for the upcoming 2026 census, with a recent audit revealing critical cybersecurity vulnerabilities that have yet to be addressed. This comes as a stark reminder of the 2016 census failure, where hackers launched a series of distributed denial-of-service (DDoS) attacks, causing the online form to be shut down for 40 hours. The ABS is now under pressure to ensure the 2026 census is more resilient.
The audit, conducted by the Australian National Audit Office, highlights several concerns. Firstly, the ABS has strengthened its cyber defenses but has left important work late, failing to take a comprehensive view of risks across its technology systems. This has led to the deployment of significant cybersecurity experts for an extended period beyond the original plan, indicating a lack of proactive risk management. The auditor emphasizes the need for earlier action to identify and address vulnerabilities, ensuring the ABS can effectively detect and prevent malicious cyber activity.
One of the key issues is the ABS's governance arrangements, which did not always provide senior decision-makers with a clear and up-to-date picture of emerging threats. Oversight committees were found to receive incomplete or inaccurate information on cybersecurity risks, and there were inconsistencies between strategic and operational risk assessments. This lack of clarity and coordination raises concerns about the ABS's ability to make informed decisions and implement effective security measures.
The audit also criticizes the ABS's planning process, suggesting that cybersecurity considerations were not given sufficient attention. Similar concerns were raised in a previous review of the 2021 census, indicating a recurring pattern of issues. The auditor's recommendation to strengthen risk management, bring forward cyber advisory arrangements, improve security architecture oversight, and address vulnerabilities in the broader technology environment is a call for immediate action.
The ABS has acknowledged the findings and agreed to all four recommendations. It reassures the public that it continuously reassesses cyber threats, prioritizes controls for critical systems, and adjusts its approach as vulnerabilities emerge. However, the ABS must now translate these intentions into concrete actions to ensure the 2026 census is secure and reliable. The stakes are high, as the census is expected to be the most digitally dependent yet, with 85% of Australians completing the form online.
This situation raises important questions about the ABS's preparedness and the potential risks associated with the increasing reliance on digital platforms for critical national surveys. It is crucial for the ABS to address these vulnerabilities promptly to maintain public trust and ensure the integrity of the census process. As the deadline approaches, the ABS must demonstrate its ability to safeguard the census from potential cyber threats and deliver a successful and secure counting event.