Skip to the record
The definitive source for Noosa Council transcripts.
Item 11.1.3.2025-10-16 · OrdinaryOfficial item record

Ict Cyber Risk Report

← Meeting agenda & transcript

See the votes on this matter →

What was decided?

The minuted decision sequence

No separately labelled carried Council Resolution has been identified here. Read each formal event and the complete item minutes; a lost motion is not necessarily the final outcome.

Read complete item-specific minutes
That Council note the report by the Acting ICT Manager to the Audit and Risk Committee Meeting dated 30 September 2025 regarding ICT Cyber Risk Report.


This summary follows this item’s minutes. The established voting totals use their existing method while differences are checked against the full records.

What was said?

Named discussion on NoosaWatch TV

These actual transcript passages match the item’s wording. The start and end of the item’s discussion are not yet confirmed; these excerpts are not measured item airtime or exact decision moments.

Frank Wilkie38:31
We're back everybody. The meeting's been reopened. It brings us to item 9. There are no Mayoral minutes. We have no notified motions. It brings us to consideration of committee reports. 11.1 Audit and Risk Committee recommendations. 11.1.1 governance and policy update, 11.1.2 risk management and BCP update, 11.1.3 ICT Cyber Risk Report, 11.1.4 internal audit update, 11.1.5, 24, 25. Draft financial statements, NANDA financial year update, 11.1.6 is the Queensland Audit Office KPMG combined interim report, and there's a summary report of this one directed to Council on the subject later in the agenda at item 12.3. And the 11.1.7 is the Audit and Risk Committee recommendations en bloc. I have a move and a seconder for the Audit and Risk Committee recommendations, Councillor Wilson. I have a seconder, Councillor Wegener. All in favour? It's carried unanimously. 11.2 Planning & Environment Committee recommendations. 11.2.1 planning applications decided by delegated authority for August. 11.2.2 it's an MCU development application for other change to develop an approval for Commercial Business Type 1 office, Commercial Business Type 2, medical to healthcare centres, hospital and infusion centre, and RAL19000407 reconfiguration lot at 36.40 Huffington Noosaville, 11.2.3. As it's an MCU development application for Material Change of Use for short-term accommodation, backpackers accommodation at 17 Russell Street, Noosaville. 11.2.4, Planning & Environment Committee recommendations en bloc. Now we have a mover and seconder for planning the and environment committee recommendations to be adopted. Councillor Lorentson, seconded by Councillor Phillips. All in favour? That's unanimous, 11.3, Services & Organisation Committee Recommendations. 11.3.1.1 is Minor Amendments to Fees and Charges Register for Commercial Fees. 11.3.2, Noosa Shire Council's solar specialised supplier lists. Councillor Phillips. Thank you.
Margaret Gatt74:17
Through the Chair, as part of Council's enterprise risk management framework and also business continuity and disaster response, so policies and processes, whenever an incident like this occurs, whether it be cyber or anything else, there is a requirement for an incident, a crisis incident response team to basically stand up like we would with any natural disaster, where there is those processes of leaning forward, sitting up and standing up. So when I commenced with Council and became aware of the event that had occurred in the prior year, I stood up that incident crisis response team and chaired that team. And the first action that we took was to engage that external ICT forensic company to do that vulnerability testing and penetration testing of our systems. And thankfully, as is noted in the report, it revealed that we had not been compromised in any way whatsoever in terms of accessing our systems proper and data. And/or in-person related information was not breached. I don't know if I answered that. Question.
Larry Sengstock147:39
Yes. So just in terms of the cybersecurity cyber security, we've seen on the report of last month's meeting, or last quarterly meeting of the Audit and Risk Committee, that we did have a specific item where we do a deep dive each time on cyber security. So that information is provided into that group. And then also, every six months, we do a review. Do a review of our Council strategic risks as part of the audit committee as well. So just making everyone aware that it's not glossed over. It is absolutely part of the audit risk committee on a regular basis.

The supporting record

Open full page ↗

My Comparisons

Choose two to four records of the same kind. Drag using a handle or use the “Compare” buttons.

Your selected records are saved in this browser for your account. Results use the filters on the page where you choose “Compare selected”.