top of page

Search Results

221 results found with an empty search

  • Data Breach Costs Escalate in 2024 | GSA

    < News Data Breach Costs Escalate in 2024 14 Aug 2024 $4.26M! That’s the average cost of a data breach in Australia in 2024, according to new research released by IBM. The figure – a record high – represents a whopping 27% increase since 2020. However, while the average cost of a data breach continues to escalate, the types of cyber breaches experienced by Australian organisations continue to be the usual suspects. Under Attack IBM’s research found that Phishing continues to be the most common type of attack vector , with 22% of breaches starting this way. Stolen or compromised credentials were the second most common, accounting for 17% of breaches. Malicious insiders were responsible for the most costly attacks, at 8% of incidents. It took Australian companies on average 266 days to identify/contain cyber incidents. This lengthy period contributed to high detection and escalation costs , which remain the most expensive aspect of a breach, with post-breach response and lost business the second most costly. Almost a third of data breaches involved data stored across multiple environments : public cloud, private cloud, and on-premises systems. Breaches across multiple environments took 13% longer to identify and contain. Organisations with too few cybersecurity staff paid the heaviest price, with an average cost per breach $2.7M higher than organisations with less exposure. However, involving law enforcement saved some ransomware victims as much as $1.5M in costs. Automated Defences Help Companies which didn’t use security AI and automation experienced significantly higher breach costs ($5.21M) than those which did, and it also took them an additional 99 days to identify and contain breaches. The research found that 65% of surveyed Australian organisations leveraged these technologies. However, attackers too are exploiting new opportunities presented by AI. For example, increasingly convincing deepfakes are enabling ever more effective social engineering attacks. Avoiding Costly Cyber Breaches To protect an organisation’s valuable data, it must be protected when it’s stored and while it’s “in motion”. As the research found, automation can ensure this takes place with the entirety of an organisation’s data transfers. Managed File Transfer (MFT) solutions such as the class-leading GoAnywhere MFT encrypt data at rest and in transit, complying with the highest data security standards (including the US’s and Europe’s HIPAA, HITECH, PCI DSS, SOX, and GDPR). MFT manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols such as SFTP, FTPS, and AS2 to send files securely, and encryption standards such as Open PGP and AES to protect data in transit and at rest. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection enables safe collaboration with external parties, preventing malware from entering your organisation, and reducing opportunities for employees to lose or mishandle sensitive data. Local Expertise Ready to Help Generic Systems Australia are your local experts in Managed File Transfer and Advanced Threat Protection. We’ve assisted hundreds of organisations across the Asia-Pacific region to secure their data and keep cybercriminals at bay. If you’d like to discuss improving your cybersecurity, please feel welcome to contact me , Bradley Copson. I’m always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. Previous Next

  • Why LOCAL Support Matters | GSA

    < News Why LOCAL Support Matters 15 Apr 2025 When you’re researching which software solution to invest in, it’s easy to become fixated on the minutiae of product features and technical specifications. Sure, these are important. However, experience has taught many Australian and New Zealand businesses the value of a further consideration that’s equally as important – the availability of local customer support and technical expertise. A key question to ask – especially for those of us operating businesses in a distant time zone on the far side of the planet – is: “Who do I turn to if there’s a problem?” Because that’s the moment when the value of true local customer support becomes really apparent! Beyond FAQs, Reddit & Chatbots FAQs, social media forums and chatbots can be helpful. But when it comes to IT systems, this kind of self-service can only help you so far. In a crisis, having genuine local human expertise and support available is invaluable . This is particularly true when it comes to integrative solutions such as Managed File Transfer (MFT). These often require expert configuration to integrate with the other software your organisation depends upon for daily operations. While the best MFTs can have your team up and running quickly for even complex, multi-step workflows, some scenarios – for example, establishing a disaster recovery environment, or setting up hybrid file transfer approaches – may require MFT vendor support. That’s why the breadth and depth of local support should be a key consideration when choosing an MFT solution. The Tyranny of Distance Access to local expertise and support is even more important for Australian and New Zealand businesses, operating as we do in what the rest of the world views as a smaller market in remote location and time zone. That can lead some vendors to – deliberately, or by omission – deprioritise customer support for Australian and New Zealand businesses. (How many times – either as consumers or business owners – have you needed support during our local business hours… only to realise that overseas customer support and technical support personnel are still sound asleep, or clocked off for the weekend?) A vendor which provides “boots on the ground” in Australia and New Zealand - ready and willing to service local customers’ needs – is a real advantage. Beyond Emergencies The value of having human experts available locally extends far beyond those critical moments when IT systems have failed. Professional services – such as end user training, and knowledge transfer to your IT own support personnel – are also valuable advantages. Key Customer Support Questions for Software Vendors Here are some important support questions I recommend you ask a software vendor when assessing which software solution will be best for your organisation: What hours do you provide customer support? Are technical experts available locally ? Are your technical staff expert in this specific solution? How many times have your technical staff deployed your solution to A/NZ businesses? What training do you offer? Can it be customised? Is it interactive or demonstration-led? Can I review a course outline before purchasing sessions? Is certification available for my team? What professional services are available, and how do you deliver them? Is Migration Assistance available? How are customer issues prioritised within your Customer Support team? What is the process for submitting a Support Request? Is there a Customer Portal available for downloading the latest updates, release notes, and documentation? Learning from Others’ Experiences The experiences of fellow customers can help bring the advantage of local support into sharp focus. Browsing third-party review sites such as G2, Software Reviews, and Capterra, you’ll find many reports from MFT customers about their dealings – positive and negative – with various MFT vendors’ support services. They make for thought-provoking reading! In addition, here are some expert reports and summaries comparing MFT offerings and customer service arrangements. Info-Tech Managed File Transfer Category Report : The Info-Tech Research Group evaluated the most popular managed file transfer software and vendors in the market – GoAnywhere MFT, MOVEit, IBM MFT, and more. Their detailed analysis includes a deep dive into vendor satisfaction for ease of vendor support, implementation, and product strategy. The report also provides head-to-head comparisons of leading solutions. G2’s MFT Grid Report : This report provides an analysis of providers in the MFT arena and covers satisfaction ratings, feature comparisons, market presence data, and more. G2 MFT Reviews Software Reviews PeerSpot Reviews The Best MFT, with the Best Local Support At Generic Systems Australia, we have decades of experience installing and supporting the world’s premier MFT , GoAnywhere, across Australia and New Zealand. Founded in 1993, we’re proud to count among our clients some of the region’s most iconic brands. Leveraging our unique skills and readily available local support, they rely on us to make their IT systems more secure and efficient, in turn, making their teams more productive. A long-term partner of Fortra (formerly Help Systems, and Linoma Software, the original authors of GoAnywhere MFT), our in depth understanding of GoAnywhere’s capabilities - including Advanced Workflows, data translation, auditing and compliance, automation and security - enables us to devise optimal deployment solutions, provide rapid Proofs of Concept, and move ahead quickly with implementation. In fact, we have exclusively managed GoAnywhere deployments for some of the region’s largest multinational corporations and Government departments, as well as small- to medium-sized businesses. Our Australia-based technical experts provide clients with the reassurance that local help will always be on-hand. If you’re exploring how to boost your efficiency and bottom line by leveraging Secure Managed File Transfer technology, please feel welcome to contact me for an obligation-free discussion. Or, if you’d prefer to read more, you can check out the many resources on our Generic Systems Australia website, including our exclusive Local MFT Buyer’s Guide . At Generic Systems Australia, we’re your local experts in MFT. Previous Next

  • New Cyber Laws Passed – What Australian Businesses Need to Know and Do | GSA

    < News New Cyber Laws Passed – What Australian Businesses Need to Know and Do 27 Nov 2024 Earlier this week, the Australian Parliament passed a suite of legislative reforms designed to enhance Australia’s cyber security. The reforms include a raft of new requirements and obligations on Australian businesses. About the Legislation Based on recommendations by the Parliamentary Joint Committee on Intelligence and Security, the new legislation addresses a number of proposals initially set out in Australia’s 2023 – 2030 Cyber Security Strategy, and spans three separate Acts: 1. the Cyber Security Act 2024 (Cyber Security Act); 2. the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 ; and 3. the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (SOCI Amendment Act). Mandatory reporting of ransom payments, and the introduction of a new voluntary information sharing regime, will have the most immediate impact on organisations. Mandatory Reporting of Ransomware Payments Ransomware attacks are rife across Australia. The Australian Signals Directorate (ASD) reported that this form of cyber extortion accounted for 11% of all cyber incidents to it in 2023-2024, up from 8% in the previous year. The Government had previously pursued a ban on ransom payments. However, its position has since moderated somewhat. The Cyber Security Act only requires organisations to report ransomware payments to the Department of Home Affairs and the ASD. This new reporting obligation will commence at latest six months after the Act receives royal assent (potentially earlier by proclamation) and applies broadly to: · organisations which are a responsible entity for a critical infrastructure asset; and · other private sector organisations which conduct business in Australia with an annual turnover exceeding a threshold (to be specified - likely to be A$3M). Ransomware reports are required to be made within 72 hours of making a payment (not the receipt of a demand or the discovery of a ransomware attack). Difficult Decisions The requirement to report payments will need to be taken into account by Boards when considering whether to pay a ransom. The Government’s general view on ransoms continues to be that organisations should not pay them. It reasons that payments don’t guarantee the recovery or confidentiality of stolen data, but do encourage cyber attacks to proliferate. Organisations in receipt of ransom demands are left to ponder several competing considerations… · Paying a ransom could potentially contravene sanctions (such as the one imposed on Aleksandr Ermakov, the individual responsible for the 2022 Medibank data breach) or anti-money laundering laws. · Company Directors fulfilling the duty of care to act in the best interests of their organisation will need to balance the risks of payment - commercial damage, incentive to re-target, uncertainty of data recovery – against the risks of not paying - loss of systems data, reputational damage, third party claims, lost customers and business disruption. If a ransom payment is made, then the new mandatory reporting obligation will be in addition to other applicable reporting requirements an organisation is subject to. These could include the Privacy Act 1988 , the SOCI Act , and continuous disclosure obligations under the ASX Listing Rules and CPS 234. In fact, it’s important that Cyber Incident Response plans developed by organisations specifically address these overlapping requirements, taking into account the various regulators and timeframes of each. Be aware that, for any entities regulated under the SOCI Act , it’s also conceivable that the Government could use its directions power to direct an entity to pay - or not pay - a ransom. An organisation which fails to comply with mandatory ransom reporting will incur a civil penalty of 60 penalty units (currently A$93,900). Voluntary reporting regime A new National Cyber Security Coordinator (NCSC) is being established under the Cyber Security Act to lead a whole-of-government response to significant cyber security incidents. The Act provides a framework for the voluntary disclosure of information by any organisation operating in Australia, or any responsible entity under the SOCI Act , to the NCSC relating to cyber security incidents. However, it imposes various limitations on how the NCSC may further use and disclose information voluntarily provided by entities, depending on the significance of the incident. Non-significant cyber security incidents: Information can be used for limited purposes such as directing the reporting entity to assistance services, coordinating a government response, and informing Ministers. Significant cyber security incidents: Information can be used for broader ‘Permitted Cyber Security Purposes’. These include preventing or mitigating risks to critical infrastructure or national security, and supporting intelligence or enforcement agencies. A cyber security incident is deemed “significant” if: there is a material risk that the incident has seriously prejudiced, is seriously prejudicing or could reasonably be expected to prejudice the social or economic stability of Australia or its people, the defence of Australia or national security; or the incident is, or could reasonably be expected to be, of serious concern to the Australian people. Information voluntarily provided by organisations to the NCSC is subject to limited use protections similar to those which apply to information disclosed as part of a ransomware payment report. The new voluntary reporting regime and corresponding limited use protection has come into immediate effect. Limited use protection The Cyber Security Act outlines how businesses should work with the NCSC and other government agencies to obtain assistance and guidance when responding to cyber incidents. It also provides businesses with certain limited use protections when collaborating with the government’s cyber security agencies - a legislative foundation for the CISA Traffic Light Protocol government agencies have recently offered when assisting organisations. Such protections were requested by business lobby groups. They provided feedback during the public consultation period that disclosing information about a data breach could risk exposing an organisation to further regulatory or enforcement action, adverse publicity and litigation. Further, if disclosing a cyber incident was determined to be against an organisation’s best interests, its directors could potentially be in breach of their duties in approving the disclosure. That could in turn expose directors to enforcement action from ASIC. Counterweighing these concerns, the Government believes that sharing information on current threats and incidents can help other organisations avoid similar incidents. In balancing these competing interests, the Cyber Security Act limits the purposes for which information contained in a ransomware payment report or voluntarily report provided to the NCSC can be used or disclosed. The NCSC (and any Government agency it coordinates with) cannot record, use or disclose the information provided for the purposes of investigating or enforcing or assisting in the investigation or enforcement of any contravention of a Commonwealth, State or Territory law. An important exemption from the limited use protections are that crimes and breaches of the limited use protections created by the Act. In this way, the protections stop short of being a full “safe harbour”. Information provided under these protections isn’t admissible in evidence against the disclosing entity, including criminal, civil penalty and civil proceedings (including a breach of the common law). And the provision of information to the NSCS does not affect any claim of legal professional privilege over the information contained in that information. These limited use protections will be of value to organisations disclosing information to the Government about cyber incidents. However, directors should bear in mind the notable gaps in the protection they provide. For example: Information provided can’t be used or disclosed for the purposes of investigating or enforcing any contravention by the reporting entity of another law (whether federal, state or territory), other than a law that imposes a penalty or sanction for a criminal offence. This means that if the ransomware report indicates that a payment was made in breach of relevant sanctions laws, then the limited use protection will not prevent the use of the report in a subsequent investigation or enforcement action. While information provided to the NCSC cannot be obtained from the NSCS by regulators or government agencies, the protection offered under this Act does not prevent regulators from obtaining the underlying information through other means, including via regulatory investigatory powers or where provided under other mandatory reporting regimes, such as those in the Privacy Act 1988 , the SOCI Act, the Telecommunications Act 1997 and the ASX Listing Rules continuous disclosure obligations. So, cyber incident notifications provided to the ACSC under the SOCI Act are not captured by the limited use protection, even if that information is also voluntarily provided to the NCSC or detailed in a mandatory ransomware report. A similar limited use protection has been introduced via the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 for cyber incident information voluntarily shared with the ASD. Other Inclusions in the Legislation This article has focused on developments within the new Cyber Security legislative reforms which will most impact companies and organisations. However, in the interests of completeness, here is a brief overview of other key developments covered in the legislation: Mandated Security Standards for Internet of Things (IOT) Devices. These standards will be detailed in legislative rules, with suppliers required to provide a statement of compliance for devices supplied to the Australian market. New Cyber Incident Review Board. This independent advisory body will be empowered to conduct no-fault, post-incident reviews of significant cyber security incidents and provide recommendations and information to both the private and public sector. It will have the power to compel entities to provide information about significant cyber security incidents. Critical Infrastructure definition expanded. Data storage systems which hold business critical data have been added to the definition of critical infrastructure assets. This closes a gap in the regulations which became apparent in the aftermath of the Optus and Medibank data breaches. Expanded Incident Response Powers. The Government will now have the power to direct an entity to take, or not take a specific action, in the event of a cyber incident affecting critical infrastructure. Security and incident notification obligations moved from the Telecommunications Act 1997 to the SOCI Act , consolidating the cyber obligations of telecommunication carriers and carriage service providers under a single piece of legislation. What Organisations Should Do Cyber security response plans should now be reassessed and upgraded to ensure they align to the new mandatory ransomware reporting requirements. Playbooks and procedures should take account of how an organisation plans to engage with cyber security authorities, bearing in mind the extent - and limitations - of the defined limited use protections. Focus on preventing cyber incidents - not just responding to them . A Managed File Transfer (MFT) solution such as GoAnywhere MFT can encrypt data at rest and in transit, complying with the highest data security standards. It manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols and encryption to protect your data. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection facilitates safe collaboration with external parties, helping to prevent malware from entering an organisation, and reducing the risk of employees losing or mishandling sensitive data. Finally, organisations should seek professional legal counsel in determining and responding to their obligations and responsibilities under the new Cyber Security legislative reforms. The information provided in this article has been general in nature, and the interpretations and advice outlined above should not be interpreted as professional legal advice. Previous Next

  • 2026 World Cup: Unprecedented Cyber Target | GSA

    < News 2026 World Cup: Unprecedented Cyber Target 18 June 2026 Major global sporting events are always an attractive target for malicious cyber actors. However, the 2026 FIFA World Cup’s expansive approach - three countries, 16 cities, and a vast digital ecosystem, during conflicts involving Russia, Ukraine, Iran, Israel, and the US, and America’s 250th anniversary – makes it a cyber target of unprecedented proportions. According to Nikita Shah, senior fellow with the Intelligence, National Security, and Technology program at the Center for Strategic and International Studies, the tournament’s cyber risk comprises three layers: the core digital infrastructure which the event relies upon; the wider digital infrastructure that supports the millions of spectators attending the matches; and the personal devices carried by players, officials, VIPs, and fans. Each of these layers introduces its own vulnerabilities. Together, they create what she describes as a “cumulative set of risks that makes securing this tournament somewhat unique.” Cybercrime at Scale The most immediate threat is cybercrime. In the lead up to the event, authorities saw evidence criminal groups were preparing their attacks. Malicious infrastructure was staged and waiting, including more than 1,000 suspicious domains and hundreds of cloned FIFA websites designed to harvest personal data. The World Cup is a perfect environment for fraud: fast transactions, unfamiliar vendors, and high‑value targets. Fake ticketing sites, bogus livestream apps loaded with malware, counterfeit merchandise stores, and even fraudulent job offers aimed at stealing credentials. Even athletes are not immune. Witness Bologna FC’s 2024 ransomware incident, which leaked 200GB of sensitive data. Disruption as a Political Tool Beyond profit‑driven crime, the tournament is a tempting stage for politically motivated disruption. Past events demonstrate the risk. The 2018 Winter Olympics suffered a major cyberattack by Russian military hackers, while the 2024 Euros saw DDoS attacks interrupt match coverage. State actors may target critical infrastructure - transit, water, power, emergency services - because these systems are often under‑resourced. With U.S. - Iran tensions high, and Russia seeking opportunities to undermine Western credibility, the World Cup becomes a symbolic and strategic target. Espionage in Plain Sight Where world leaders, senior officials, athletes, and global businesses gather, espionage follows. Shah warns that the World Cup offers an extremely attractive target set for intelligence collection. Russia, China, and Iran are expected to be the most active, seeking insights into diplomatic negotiations, dissidents, and high‑value organisations. Hybrid Threats Beyond Cyber Cyber operations won’t be the only tool in play. Disinformation campaigns, deepfakes, and social‑media manipulation will attempt to “pollute the information space,” as Shah puts it. Physical sabotage - such as the cable‑cutting incident during the Paris 2024 Olympics - remain a possibility. Preparedness The United States has designated most matches as nationally significant security events, enabling enhanced intelligence‑sharing and emergency planning. The Center for Strategic and International Studies has conducted extensive training and stadium assessments. Ultimately, resilience is the goal. MFT: an essential defence Major sporting events are, at their core, giant data‑exchange machines. Behind the spectacle of athletes, crowds, and broadcast cameras sits an enormous operational engine moving rosters, medical files, accreditation records, logistics manifests, vendor contracts, security briefings, and real‑time performance data between hundreds of organisations. That’s why Managed File Transfer (MFT) is one of the unsung heroes of such events. These events aren’t just big - they’re interconnected. Every partner needs to exchange sensitive information quickly, reliably, and in a way that won’t collapse under pressure. MFT shines in this environment because it replaces the messy patchwork of ad‑hoc file sharing with a single, governed, auditable system. It provides guaranteed delivery, automated workflows, and encryption that meets the scrutiny of international regulators. Local MFT Experts At Generic Systems Australia, we have decades of experience helping Australian and New Zealand organisations take advantage of the security and efficiency that MFT provides. If you’d like a no-cost, no-obligation discussion about how we could help you simply and affordably adopt an advanced MFT solution, please feel welcome to get in touch with me. Previous Next

  • MFT Lends Small IT Teams a Big Hand! | GSA

    < News MFT Lends Small IT Teams a Big Hand! 29 Sept 2025 Small and medium-sized organisations face the same escalating cyber threats as large corporations. However, they need to deal with those threats with much smaller IT teams and resources. Installing a Managed File Transfer (MFT) solution can help lift a heavy load from your stretched IT team, freeing them up to focus on other business needs. Your Davids vs The Cyber Goliaths Hackers are increasingly forming large, decentralised syndicates to attack and exploit vulnerabilities worldwide. This enables them to attempt phishing, malware deployment and credential theft across a vast number of organisations simultaneously. What makes these syndicates especially dangerous is their resilience: even if parts of their network are shut out, others remain active to reconfigure and attempt a different attack. By further leveraging automation and remote access tools, hackers can scale their operations with minimal effort, making their networks a formidable threat to organisations of all sizes. Small IT teams need powerful IT allies. And one such ally is an MFT solution, such as GoAnywhere MFT." MFT in a nutshell Managed File Transfer is a secure, automated solution for exchanging data—internally and externally—across systems, employees and partners. Unlike traditional file transfer methods (like FTP or email attachments), MFT offers encryption, access controls, audit trails, and automation, all within a centralised platform. MFT offers both effectiveness and efficiency boosts to small IT teams. Tough Encryption MFT encrypts files both in transit and at rest, reducing the risk of interception and unauthorised access. Sensitive data—financial records, customer information, intellectual property—remains protected even when transferred across public networks. Automate Repetitive Tasks With limited manpower, automation is key. MFT enables IT teams to schedule and monitor file transfers without manual intervention. This reduces human error and frees up time for strategic tasks like threat monitoring and system updates. Access & Authentication MFT offers granular user permissions and multi-factor authentication, ensuring only authorised personnel can access or send files. This minimises insider threats and accidental data exposure. Audit Trails & Compliance MFT logs every file transfer, creating a detailed audit trail that supports compliance with regulations like GDPR, HIPAA, and ISO 27001. For small teams, this built-in reporting saves hours of manual tracking and simplifies audits. Centralised Management Instead of juggling multiple file-sharing tools, MFT consolidates transfers into a single dashboard. This streamlines oversight, reduces shadow IT activity, and makes it easier to spot anomalies or unauthorised activity. Scalable Security Support MFT doesn’t just protect data—it empowers small IT teams to enforce enterprise-grade security without needing enterprise-sized resources. By automating secure transfers, reducing manual errors, and centralising control, MFT acts as a force multiplier for your IT Team’s cybersecurity efforts. And for small IT teams, it’s not just a tool—it’s a strategic upgrade to their cyber resilience. Local Help on Hand At Generic Systems Australia we’re Australia’s and NZ’s experts in deploying Managed File Transfer solutions. We’ve assisted businesses of all sizes to protect their customer data and secure their file transfers, while keeping their operations running smoothly. If you’d like to discuss how we can help you, please feel welcome to contact me . I’m always happy to have an obligation-free chat and explain how simply we can help you maintain your customers’ trust. Previous Next

  • How to Secure Online Data Acquisition with Secure Forms | GSA

    < News How to Secure Online Data Acquisition with Secure Forms 3 Feb 2026 Whenever you ask someone to complete a form online, you’re asking for their trust. They’re handing over details that your organisation needs. In return, they expect your organisation to handle those details in confidence and with care. From payment methods to sensitive medical histories, people want assurance that their information won’t fall into the wrong hands. Earn Trust with Secure Forms Using HTTPS to transmit form data is a solid baseline. However, there’s an even stronger and more structured alternative - Secure Forms. An add‑on module for GoAnywhere Managed File Transfer , Secure Forms not only protect the information being submitted but also streamline how that information moves through your business. Secure Forms offer far more than encrypted submissions. You gain control over how forms look, how they’re accessed, and how the collected data flows into your internal systems. Public or private URLs, automatic encryption for uploaded files, and seamless workflow integration all come standard. Why It’s Worth Upgrading Choosing a purpose‑built Secure Forms solution doesn’t just improve protection - it boosts efficiency across your processes. With GoAnywhere Secure Forms, you can: Build tailored forms for authenticated users or open access Let users upload supporting documents as needed Support drag‑and‑drop file attachments, automatically encrypted with AES‑256 Define your preferred media types Add Data Loss Prevention (DLP) and Threat Protection Embed forms directly into your website Use Advanced Workflows to route submitted data into platforms like Salesforce or other business systems Trigger email notifications when submissions are received Insert submitted data straight into a database table. How Secure Forms Work At Generic Systems Australia we have years of experience designing custom Secure Forms for organisations. Or, you can DIY… Build and configure: design a form with the fields and options your process requires. Then share access through either a public or restricted URL, giving you full control over who can submit information. Complete and protect: Users fill out the form and attach any necessary files. Every uploaded item is encrypted automatically using AES‑256, ensuring sensitive content stays protected from the moment it’s submitted. Submit and automate: Once the form is sent, GoAnywhere triggers the workflow you’ve defined. This removes manual steps and ensures the information moves quickly to the right system or team. Customisation Without Compromise Secure Forms are built to adapt to your needs. You can fine‑tune nearly every element, from field labels to file‑upload rules, giving you complete control over the data you collect. You’re able to: Configure fields, dropdowns, tooltips, and default values Accept a wide range of file types Submit forms via SOAP or REST APIs, or directly through a URL Display personalised confirmation messages and provide downloadable follow‑up files (such as PDFs) Redirect users to additional forms after submission Enable or disable submission notifications Set limits on file size, type, and quantity Receive alerts via email or SMS Transform submitted data as needed Allow users to save drafts and finish later. Trust the Secure Forms with a Track Record Recognising GoAnywhere’s advanced capabilities, some software vendors have recently sought to emulate the tried-and-tested Secure Forms approach within their less fully-featured MFT solutions. However, trust is established over a long time. GoAnywhere’s Secure Forms were introduced 2016, and so benefit from a decade of refinement and successful implementation. Here to Help Whether it’s designing and implementing your Secure Forms, or talking more broadly about how MFT can help your business become more secure and efficient, Generic Systems Australia is here to help. No need to do deal with hands-off multinationals and their odd time zones - we’re right here in Australia, right now, ready to help. Previous Next

  • Why Your Business Can't Rely on Employee Cybersecurity Training | GSA

    < News Why Your Business Can't Rely on Employee Cybersecurity Training 29 Oct 2025 The employee cyber security training programs implemented by most large companies don’t reduce the risk of their employees falling for phishing scams. That’s the shocking conclusion of recent research evaluating the effectiveness of two common types of cybersecurity training.  Phishing is a deceptive tactic in which attackers impersonate trusted entities to trick individuals into revealing sensitive information like passwords, credit card numbers, or personal data.  It continues to be the most common form of cyber attack, and leads to the greatest number of cyber infiltrations. Testing the Defences To test the effectiveness of anti-phishing training, researchers sent 10 different phishing email campaigns to 19,500 employees at UC San Diego Health over an eight month period.  They found that there was no significant relationship between whether an employee had recently completed mandated cybersecurity training and whether they then fell victim to a phishing email. Researchers also tested whether sharing anti-phishing information after an employee fell for a phishing scam improved the employee's ability to detect a subsequent phishing attempt. However, once again, they observed very little difference in repeat failure rates. In fact, embedded phishing training only reduced the likelihood of an employee clicking on a phishing link by a mere 2%. Why training fails Research study co-author Grant Ho said a key reason the anti-phishing training isn’t effective is that most employees don’t engage with embedded training materials.  75% of users in the study engaged with embedded training materials for a minute or less, and a third closed embedded training pages immediately, without reading them. He recommended that organisations refocus their efforts to combat phishing on technical countermeasures. Technical Countermeasures One of the first and best lines of defence against phishing is to prevent malware and suspicious links before they can reach employees’ devices.  At Generic Systems Australia we combine the world’s leading Managed File Transfer solution, GoAnywhere , with Advanced Threat Protection to deliver a proactive, multilayered defence against both external threats and internal data leakage.  GoAnywhere provides secure encryption, access controls and audit trails for file transfers, while ATP enables your organisation’s email system to automatically detect and prevent phishing links and other malware from entering your organisation. Here to Help At Generic Systems Australia we have decades of experience helping Australian and New Zealand organisations protect themselves against malware and other cyber attacks. Our Migration Service makes the transition even easier for organisations who prefer to let their team get on with their regular work rather than taking time out to improve their IT plumbing. If you’d like a no-cost, no-obligation discussion about how we could help you simply and affordably adopt an advanced MFT and ATP solution, please feel welcome to get in touch with me. At Generic Systems Australia, we’re your local experts in Secure Managed File Transfer. Previous Next

  • 5 Eyes Cyber Spooks Issue Urgent A.I. Warning | GSA

    < News 5 Eyes Cyber Spooks Issue Urgent A.I. Warning 1 July 2026 The allied intelligence‑sharing agencies of Australia, Canada, New Zealand, the UK and USA have issued a joint warning on the risks to business from Artificial Intelligence. In a statement this week, the so-called “Five Eyes” agencies – which includes the Australian Signals Directorate – urged business leaders to act immediately to make their organisations resilient to AI-led cyber incursions. “Frontier Al models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities,” the statement said. “The timeline is not years, it is months.” “A whole-of-organisation and whole-of-society response is required.” The Five Eyes partners urged leaders to: understand and assess risk, readiness and accountability; prioritize foundational cyber security practices and controls; empower cyber leaders with authority and resources; and stay actively engaged as threats and guidance evolve. Practical actions include: Reduce your attack surface by limiting unnecessary system access and external connectivity Accelerate patching processes, as AI is shortening the time between vulnerability discovery and exploitation. Address legacy systems, as unsupported systems are easy targets and strategic liabilities. Review and strengthen identity and access controls, limiting who can access critical systems. Prepare for incidents, by testing response plans, training teams, and assuming breaches will occur. Use AI to strengthen defence. “Success will come from getting the basics right, acting quickly, and integrating cyber security into core business strategy,” the agencies added. Managed File Transfer is a foundational solution to better manage access to and transfer of organisations’ data. If you’d like to explore potentially deploying it in your organisation, please feel welcome to get in touch with us. Previous Next

  • Accountability Gap Creates Cyber Risk | GSA

    < News Accountability Gap Creates Cyber Risk 22 Oct 2024 New research has revealed a concerning gap in accountability for cyber security in many Australian organisations. Security firm Trend Micro polled 100 Australian IT leaders to better understand their attitudes toward Attack Surface Risk Management. They found that most organisations lacked clear leadership buy-in and sufficient resources to measure and mitigate cyber risks. The top three gaps in cyber resilience were: Insufficient staffing for round-the-clock cybersecurity coverage. Inadequate techniques to measure and manage attack surface risks. Not using proven regulatory and other frameworks, such as the NIST Cybersecurity Framework. Only 37% of those surveyed said their organisation had satisfactorily closed each of these exposures. The buck stops… nowhere? Seeking root causes for unclosed gaps in organisational cyber resilience, Trend found that the failures could be traced back to a lack of leadership and accountability at the top of the organisation. More than a third of respondents claimed their leadership didn’t consider cybersecurity to be their responsibility. When asked who does or should hold responsibility for mitigating business risk, respondents gave a variety of answers, indicating a lack of clarity on reporting lines. Nearly a third (32%) said the buck stopped with organisational IT teams. Trend spokesperson, Srujan Talakokkula, said the “lack of clear leadership on cybersecurity, can have a paralysing effect on an organisation, leading to reactive, piecemeal and erratic decision making”. “A lot of that comes down to collaboration and communication across the business,” he said. “Companies need CISOs to clearly communicate in terms of business risk to engage their boards. “Ideally, they should have a single source of truth across the attack surface from which to share updates with the board, continually monitor risk, and automatically remediate issues for enhanced cyber-resilience,” he added. ASIC Cracking Down Trend’s warning comes on the heels of reports that Australia’s corporate regulator is preparing legal actions against some company directors for their lack of governance relating to cyberattacks. ASIC has previously cautioned directors that they need to prepare for hacks, and that sanctions would be applied to those who didn’t. They told The Australian Financial Review that companies wouldn’t get away with paying lip service to cyber defence and must provide evidence they had performed their duties if their organisation was breached by cybercriminals. “With one cyberattack reported every six minutes in Australia, ASIC’s message for directors is to make sure your organisations have appropriate cybersecurity measures in place – this is your responsibility,” a spokesperson said. Not just “an IT Issue” ASIC’s heightened investigations show that cyber security is no longer a fringe issue that can be relegated to technical staff. However, a survey of in-house lawyers by Herbert Smith Freehills recently found many boards are not yet engaged on the topic of cyber resilience. 58% said it would take an actual cyberattack to motivate their organisation to meaningfully improve their data risk management. Owning and managing the risk Rather than letting cyber resilience slip between the cracks in org charts, directors need to put cyber resilience at the top of their companies’ board agendas. Executive management should be requested to report on the measures and investments they’re making to keep cyber thieves at bay. A Managed File Transfer (MFT) solution such as the class-leading GoAnywhere MFT can encrypt data at rest and in transit, complying with the highest data security standards. It manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols and encryption to protect data in transit and at rest. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection enables safe collaboration with external parties, preventing malware from entering an organisation, and reducing the risk of employees losing or mishandling sensitive data. Local Experts On Hand Generic Systems Australia are local experts in Managed File Transfer and Advanced Threat Protection. We’ve assisted hundreds of organisations across the Asia-Pacific region to secure their data and keep cybercriminals at bay. If you’d like to discuss how we can help improve your company’s cybersecurity, please feel welcome to contact me , Bradley Copson. I’m always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. Previous Next

  • New Cyber Laws Impose New Business Obligations | GSA

    < News New Cyber Laws Impose New Business Obligations 16 Oct 2024 Australia’s federal government last week introduced much-anticipated legislation to parliament which will revolutionise Australia’s cyber security preparedness. If passed as expected, the new laws will impose new compliance and reporting requirements on local businesses. Govt Intent Designed to protect businesses and consumers from the growing scourge of cyber crime, the Cyber Security Act 2024 is Australia’s first standalone cyber security legislation. Introducing the Act, Minister for Cyber Security, Tony Burke, said that – like IT systems themselves - legislation needed to be hardened to protect national security and economic stability. He described the package as providing a clear legislative framework for contemporary, whole-of-economy issues which would identify and respond to new and emerging cyber threats. Seven Initiatives There are seven initiatives under the 2023-2030 Australian Cyber Security Strategy which collectively address gaps in current legislation to: Mandate minimum cyber security standards for smart devices; Introduce mandatory ransomware reporting for certain businesses to report ransom payments; Introduce a ‘limited use’ obligation for the National Cyber Security Coordinator and the Australian Signals Directorate; and Establish a Cyber Incident Review Board. SOCI Reforms The legislation will also progress and implement reforms under the Security of Critical Infrastructure Act 2018 (SOCI Act): Clarifying existing obligations in relation to systems holding business critical data; Simplifying information sharing across industry and Government; Introducing Government powers to direct entities to address serious deficiencies within their risk management programs; and Moving regulation for the security of telecommunications into the SOCI Act. The SOCI Act reforms will also expand current Government assistance measures to ensure Government can step in as a last resort to manage the consequences of significant incidents. Govt Empowered Changes to government assistance measures will empower the Government to gather information or direct entities to take or refrain from certain actions, on authorisation from the Minister for Home Affairs, in response to a serious incident. Characterising the legislation as a significant step towards his government’s vision of becoming a world leader in cyber security by 2030, Tony Burke said: “We know government has to lead the way on cyber, but we also know we can’t do it alone. This is why these new laws have been consulted extensively with business. “To achieve Australia’s vision of being a world leader in cyber security by 2030, we need the unified effort of government, industry and the community.” New Business Obligations Legal firm A&O Shearman cautioned that the new Cyber Bill will introduce several new critical areas of compliance and reporting. It said businesses must take heed of these new obligations, and ensure they put in place robust cyber security measures. • Ransomware Reporting Obligations : Entities impacted by cyber security incidents and making ransomware payments must report these payments within 72 hours. The aim of this obligation is to improve the detection and response to ransomware incidents, thereby reducing their impact. Failure to report can result in civil penalties. • Security Standards for Smart Devices : The Cyber Bill mandates that manufacturers and suppliers of smart devices comply with specified security standards. This is crucial for businesses involved in the production or distribution of smart devices. Non-compliance can result in compliance notices, stop notices, and recall notices. These measures are designed to ensure that smart devices are secure and do not pose a risk to users. • Protected or Limited Use of Incident Information : The Cyber Bill includes provisions to ensure that information provided about cyber security incidents is used or disclosed only for permitted purposes, with strict limitations on using this information for civil or regulatory actions against the reporting entity. • Cyber Incident Review Board : The Cyber Bill establishes a Cyber Incident Review Board tasked with reviewing certain cyber security incidents and making recommendations. The Board has the authority to request and require documents from entities. Non-compliance may result in civil penalties. A&O Shearman said organisations should make sure they implement security standards in compliance with the specified security measures currently provided for in the Cyber Bill, and make sure they can comply with the ransomware reporting obligations, including the timelines foreseen in the Cyber Bill. Meeting New Requirements Criminal syndicates target organisations which haven’t adequately protected their data transfers and systems access. Defending against them requires a multi-layered strategy which includes robust data transfer protection, multifactor authentication and employee training. Managed File Transfer (MFT) solutions such as the class-leading GoAnywhere MFT encrypt data at rest and in transit, complying with the highest data security standards - including the US’s and Europe’s stringent HIPAA, HITECH, PCI DSS, SOX, and GDPR. MFT manages inbound and outbound file transfers across an organisation, using industry-standard file transfer protocols such as SFTP, FTPS, and AS2 to send files securely, and encryption standards such as Open PGP and AES to protect data in transit and at rest. GoAnywhere MFT also provides audit reports, which will help organisations meet new reporting and compliance needs. All file transfer and administrator activity is stored and easily searchable. To help organisations report on file transfer activity and remain compliant with the new legislation, these audit logs can be automatically generated and provided as PDFs. Advanced Threat Protection and Adaptive Loss Prevention add a further layer of defence. SFT Threat Protection enables safe collaboration with external parties, preventing malware from entering an organisation, and reducing the risk of employees losing or mishandling sensitive data. Local Expertise on Hand Generic Systems Australia are your local experts in Managed File Transfer solutions. We’ve assisted dozens of organisations across the Asia-Pacific region to secure their data and keep cybercriminals at bay. If you’d like to discuss improving your cybersecurity, please feel welcome to contact me , Bradley Copson. I’m always happy to have an obligation-free discussion, explain how simply we can transition you from outdated software and approaches, and offer you a zero-cost Proof of Concept. Previous Next

bottom of page