Skip to main content
The Markets by Proactive
Go to Proactive UK
Proactive UK has moved. Proactive’s coverage of London’s small caps continues on proactiveinvestors.com Go there →
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Coverage of London’s small caps continues on proactiveinvestors.com
Go to Proactive UK
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK
Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK

Tech

CSIRO and Google partner to protect critical Australian infrastructure from hazardous software components

In light of the recent Crowdstrike incident which saw 8.5 million Windows devices temporarily disabled due to a bad software update, the CSIRO has formed a research partnership with Google to protect crucial infrastructure (CI) from vulnerable software.

The two organisations will work together as part of Google’s Digital Future Initiative and CSIRO’s Critical Infrastructure Protection and Resilience mission, developing tools and frameworks to help Australia meet critical obligations around software supply chain security.

“Software supply chain vulnerabilities are a global issue, and Australia has led the way in legislative measures to control and combat the risks," Google Cloud's Australia & New Zealand security practice lead Stefan Avgoustakis said.

“The tools and frameworks we’re developing will give Australia’s CI operators a clear and consistent roadmap towards software supply chain maturity, based on the in-depth industry knowledge that CSIRO has built up over years of research.

“Making these resources openly available to CI operators will help establish greater resilience throughout critical infrastructure nationwide and reflects our longstanding interest in teaming up with industry and academia to enhance the effectiveness of our years of work in open-source security.”

Bespoke AI tools

CSIRO’s project lead Dr Ejaz Ahmed said the creation of new and homegrown technologies would enhance the security of software used in Australian critical infrastructure.

“Software developed, procured, commissioned and maintained within Australia will also be better aligned with local regulations, promoting greater compliance and trustworthiness,” Dr Ahmed said.

“This partnership builds upon a successful track record of AI-powered innovation, demonstrating the transformative power of Google and CSIRO's expertise.”

The partnership intends to develop novel AI-powered tools for automated vulnerability scanners and data protocols that can “quickly and precisely identify and assess the impact of open-source vulnerabilities on Australian CI operators’ software supply chains.”

These new tools will leverage Google’s OSV database for the most up-to-date intelligence on vulnerabilities and CSIRO’s applied research, including methods to test for responsible AI usage and tools for analysing software packages.

The two organisations will also collaborate to develop a framework offering CI operators clear guidance on how to meet current requirements and a baseline for future ones, based on Google’s Supply-chain Levels for Software Artifacts (SLSA) framework.

Advertisement
The Markets
by Proactive
Proactive UK has moved.
Small-cap coverage continues on .com
Go to Proactive UK