Skip to document content
Westlink Intranet

Command Palette

Search for a command to run...

?
OFFICIAL

Cyber Security Procedure

Effective: 18/06/2026 | Review Due: 18/06/2027
Contents & downloads
On this page
    Related documents

    Nomenclature

    TermDefinition
    ACSCAustralian Cyber Security Centre.
    ASDAustralian Signals Directorate.
    BCSBecloudsmart — Westlink’s managed and cloud services provider.
    CISOChief Information Security Officer.
    ISMAustralian Government Information Security Manual.
    MCSPManaged and Cloud Services Provider.
    MSMicrosoft.

    Purpose

    This procedure sets out how Westlink Logistics protects its systems and data from cyber threats. It records Westlink’s standing cyber security posture: the framework it follows, who is responsible, how staff are trained, and the technical controls applied to devices, networks, media and email.

    Westlink follows the Australian Cyber Security Centre (ACSC) Information Security Manual (ISM) as its cyber security framework. The ISM provides a working guide for management and all personnel to apply the advice of the ACSC, part of the Australian Signals Directorate (ASD). The ACSC provides this advice under ASD’s designated functions in the Intelligence Services Act 2001 (Cth).

    The ACSC also publishes Australian Communications Security Instructions and other cyber security publications. Device and application-specific advice in those publications may take precedence over the ISM. These documents are available from the ACSC website at www.cyber.gov.au.

    Scope

    This procedure applies to all Westlink personnel — directors, officers, workers, contractors and consultants — and to all Westlink systems, devices and information. Westlink operates entirely in the cloud, using Microsoft Windows, Microsoft 365 and Azure, with no local servers or local data storage.

    Detection, classification, response, recovery and external notification for cyber security incidents are NOT covered here. Those activities are set out in TEC-PRO-001 Cyber Incident Response Procedure. This procedure covers the controls and governance that reduce the likelihood and impact of an incident; TEC-PRO-001 covers what to do when one occurs.

    Definitions

    Acronyms used in this procedure are listed in the Nomenclature table above. The following operational terms apply:

    • Cyber security event — an occurrence of a system, service or network state that indicates a possible breach of security policy, a failure of safeguards, or a previously unknown situation that may be relevant to security.

    • Cyber security incident — an unwanted or unexpected cyber security event, or a series of such events, that has compromised business operations or has a significant probability of doing so.

    • Cyber resilience — the ability to adapt to disruptions caused by cyber security incidents while maintaining continuous business operations, including the ability to detect, manage and recover from incidents.

    • Trusted insider — anyone with legitimate inside knowledge of how Westlink operates who could use that knowledge to cause harm, whether deliberately or through poor security practice.

    Responsibilities

    Security is everyone’s responsibility. All personnel must understand their part in protecting Westlink information and assets. Failure to follow security policies and plans increases the risk of a cyber security incident.

    RoleResponsibilityWhen
    Chief Information Security Officer (CISO)Reports cyber security matters to the senior executive or Board; oversees Westlink’s cyber security posture; develops and maintains the cyber security communications strategy; ensures consistent vendor management from discovery through ongoing management; manages relationships with third-party information system providers; and oversees the security awareness training program.Ongoing
    CISOMaintains the security awareness and insider-threat training packages and registers; maintains the managed services register; conducts the annual review of Westlink’s systems with the MCSP.Annual / ongoing
    Managed and Cloud Services Provider (Becloudsmart)Implements the ISM guidelines and Essential Eight controls with the CISO; monitors systems and alerts on suspected cyber security events; manages systems access to limit insider risk; maintains network and endpoint hardening.Ongoing
    All personnelComplete mandatory annual security awareness and insider-threat training; protect Westlink information and assets; follow security policies and plans; report concerning behaviour of colleagues; and report suspected cyber security incidents per TEC-PRO-001.Ongoing

    Security awareness and insider-threat training

    Westlink conducts annual security awareness training for all personnel. This training is mandatory and all personnel must complete it. The CISO maintains the training package, which is available from the Westlink intranet and the WMS, and keeps a register of completion in the Microsoft Dynamics platform.

    Westlink also runs mandatory annual insider-threat training. The CISO maintains this package and the matching completion register in the Microsoft Dynamics platform. A trusted insider can cause harm deliberately or inadvertently — for example by disclosing sensitive information, corrupting a process, enabling third-party access, or sabotaging systems. External threat groups may also target a trusted insider to gain access to information. Only authorised personnel may speak to the media.

    The best defence is for all personnel to recognise the threat and report concerning behaviour promptly. Behaviours of concern may include, but are not limited to:

    • appearing intoxicated or affected by a substance at work;

    • increased nervousness or anxiety;

    • a decline in work performance;

    • extreme and persistent interpersonal difficulties;

    • statements showing bitterness or resentment;

    • creditors calling at work;

    • sudden and unexplained wealth; and

    • unusual interest in sensitive or classified information.

    If you observe any of these indicators, show an interest in the person’s welfare and check that they are okay. Report observed changes in a colleague to your supervisor so that support can be offered before any harm occurs. The MCSP monitors systems for insider-risk indicators with live alerts to the CISO, and logs:

    • excessive copying or modification of files;

    • unauthorised or excessive use of removable media;

    • connecting data-storage devices to systems;

    • unusual system use outside normal business hours;

    • excessive data access or printing compared with peers;

    • data transfers to unauthorised cloud services or webmail; and

    • use of unauthorised virtual private networks, file-transfer applications or anonymity networks.

    Pre-employment screening

    Westlink screens candidates before employment in line with AS 4811-2022 Workforce Screening, verifying with the candidate’s consent their identity, integrity and credentials. Screening reduces the risk of a security breach by an employee and forms part of Westlink’s risk management strategy. The detailed process is set out in HR-PRO-001 Workforce Screening Procedure.

    Procedure

    Cyber security framework

    The ISM cyber security principles give strategic guidance on protecting systems and data. They are grouped into four key activities:

    ActivityPurpose
    GovernIdentifying and managing security risks.
    ProtectImplementing controls to reduce security risks.
    DetectDetecting and understanding cyber security events to identify incidents.
    RespondResponding to and recovering from cyber security incidents.

    The ISM cyber security guidelines give practical guidance and cover governance, physical security, personnel security, and information and communications technology security. Westlink has considered the guidelines relevant to each system it operates and implemented them with its managed and cloud services provider (MCSP).

    Points of contact

    Becloudsmart (BCS) — managed and cloud services provider

    Becloudsmart is a Microsoft Gold Partner and cloud computing specialist.

    Australian Cyber Security Centre (ACSC)

    Cyber security incidents

    The MCSP proactively improves Westlink’s cyber resilience and monitors for, and alerts on, suspected cyber security events and incidents. Detection, classification, response, recovery and external notification of cyber security incidents are handled under TEC-PRO-001 Cyber Incident Response Procedure, which also maintains the cyber incident register. All personnel must report suspected incidents through the channels in TEC-PRO-001.

    Managed and cloud services

    A managed service provider runs services on Westlink’s behalf — for example application, authentication, backup, desktop, mobility, gateway, hosting, network, procurement, security and support services. When assessing the security risk of a managed service, Westlink considers every provider with access to its facilities, systems or data.

    Westlink maintains a managed services register in the Microsoft Dynamics platform. For each service the register records:

    • the provider’s name;

    • the service’s name;

    • the purpose for using the service;

    • the sensitivity or classification of data involved;

    • the due date for the next security assessment;

    • the contractual arrangements;

    • the point of contact for users; and

    • 24/7 contact details for the provider.

    Westlink uses Microsoft Windows, and Microsoft cloud storage and platforms (OneDrive, SharePoint, Azure). Westlink operates entirely in the cloud, with no local servers or data storage. The CISO and MCSP review Westlink’s systems annually to confirm cyber security is maintained at the highest practical level.

    Mobile device management

    Phone security is enforced and requires biometrics and a passcode to access. All company information on phones is encrypted with Microsoft Intune, access is ring-fenced, and access is blocked immediately if a device becomes non-compliant with security policy. Phones can be locked or erased remotely.

    All laptops are encrypted with Microsoft BitLocker. The BIOS is password-protected, booting from external media is blocked, the bootloader is locked, and secure startup is enabled. Each laptop uses a trusted platform module (TPM) with current encryption technology. Laptops can be locked or erased remotely and will erase themselves after repeated failed access attempts when network access is unavailable.

    Westlink keeps detailed logs of access times, locations and device or user actions, and reports failed access attempts to the MCSP. Location filters block logins from places where the user is not expected to be, and high-risk countries and locations are blocked by default.

    Media usage

    External storage devices must be encrypted with Microsoft BitLocker and a password of minimum length and complexity before use, and are discouraged as a data-transport method. Email is encrypted and monitored for sensitive information, and is held for review before release if such information is found. All communication is encrypted to the highest practical level the device and medium allow.

    System hardening

    All company access requires two-factor authentication. The user must enter a code from an authorised company mobile phone, confirming they are present at the device being accessed. All company devices are encrypted, managed and monitored centrally, and can be disabled or erased remotely. Conditional access policies allow access only from company hardware that complies with security policy, identified by encrypted hardware identities. Location filters block logins from unexpected locations, and high-risk countries and locations are blocked by default.

    Westlink meets the ACSC Essential Eight at Maturity Level One, the level required under the Defence Industry Security Program (DISP) when Westlink was granted membership. DISP has since raised the requirement to Maturity Level Two; Westlink is scheduled to uplift to Maturity Level Two during 2027. The Maturity Level One controls in place are:

    • Application control is implemented centrally by the MCSP on all workstations to restrict execution to an approved set of executables.

    • Security vulnerabilities in applications and drivers assessed as extreme risk are patched, updated or mitigated within one month of identification. Applications no longer supported with security patches are updated or replaced with vendor-supported versions.

    • Microsoft Office macros execute only after prompting the user for approval, and users cannot change the macro security settings.

    • Web browsers are hardened to block web advertisements and Java content from the internet, and unsupported or unneeded browser plug-ins are disabled.

    • Privileged access to systems, applications and information is validated when first requested. Security controls prevent privileged users from reading email, browsing the web, and obtaining files via online services.

    • Security vulnerabilities in operating systems and firmware assessed as extreme risk are patched, updated or mitigated within one month of identification. Operating systems no longer supported with security patches are updated or replaced with vendor-supported versions.

    • Multi-factor authentication (MFA) authenticates all users of remote access solutions, using at least two factors. Automated voice calls for MFA are disallowed due to potential vulnerabilities.

    Network hardening

    Internet Protocol version 6 can introduce additional security risks, so Westlink uses Internet Protocol version 4 only and has disabled version 6. This reduces the network attack surface. Westlink frequently upgrades internet-exposed network hardware so that current security technology is used, including:

    • malicious-site blocking;

    • content and website filtering;

    • two-way intrusion prevention;

    • infected-device prevention and blocking;

    • denial-of-service protection;

    • traffic analysis and logging, including full packet inspection;

    • the latest Wi-Fi standard with protected management frames;

    • the latest available authentication protocol; and

    • alerts for security events.

    Westlink disables the username ‘admin’ on all hardware.

    System administration

    Compromise of a privileged account is one of the greatest threats to network security. Westlink provides system administrators with a separate privileged operating environment, in addition to their unprivileged environment, making privileged accounts and administrative activity much harder to compromise. Privileged access is validated when first requested, and security controls prevent privileged users from reading email, browsing the web, and obtaining files via online services.

    Email

    Through the MCSP, Westlink applies protective markings to email to help prevent data spills. Requiring the user to apply the marking ensures a conscious decision and limits the markings to those the system is authorised to handle, reducing both incorrect markings and over-classification. When replying to or forwarding email, users must apply a marking at least as high as the one received, so that content filters can prevent email reaching systems not authorised for its sensitivity.

    Content filtering of email bodies and attachments provides defence in depth against malicious code. All email is scanned for personal information, such as passport numbers, and the sender is warned about any such content before sending. The MCSP uses current Microsoft email security features, including threat identification and a quarantine for validating threats, with further checks and filters.

    Physical security and emergencies

    Visitors to the Perth office enter a waiting area and must sign in and out on the visitor register. Security doors protect entry to the main facility. The Brisbane facility is a service office and does not receive visitors.

    If a fire, civil disturbance or other event requires evacuation, staff should, where practicable, before leaving:

    • secure portable devices such as laptops and phones, and take them when evacuating where safe to do so;

    • secure all sensitive material in locked cabinets; or

    • take personal charge of the sensitive material until relieved of that responsibility by the custodian or CISO.

    Applicable Standards and Legislation

    This procedure operates within the framework of the following external standards and legislation referenced in its content:

    • Australian Government Information Security Manual (ISM) — Australian Cyber Security Centre / Australian Signals Directorate;

    • ACSC Essential Eight Maturity Model (Maturity Level One);

    • AS 4811-2022 Workforce Screening; and

    • Intelligence Services Act 2001 (Cth).

    Related WMS documents are listed in the Related Documents table in the front matter. Cyber security incident response is set out in TEC-PRO-001 Cyber Incident Response Procedure.

    John A. Di Giovanni
    Chief Executive Officer
    Date:
    18/06/2026
    Compliance coverage — cited by 6 requirements across 2 frameworks

    Essential Eight Maturity Model — Maturity Level Two(5)

    RequirementClauseCoverageSeverityNotes
    E8-ML2-MFA-07ML2-MFA-07Full§System administration / System hardeningMFA for privileged users — all company access requires two-factor authentication; privileged access validated.
    E8-ML2-MFA-08ML2-MFA-08Full§System hardeningMFA for unprivileged users — all company access requires a code from an authorised company mobile phone.
    E8-ML2-RAP-05ML2-RAP-05PartialHigh§System administrationSecurity controls prevent privileged users from reading email, browsing the web and obtaining files online (enforced via Conditional Access; now documented).
    E8-ML2-AC-01ML2-AC-01PartialHigh§System hardening / ResponsibilitiesMCSP centrally implements application control on all workstations, restricting execution to an approved set (operationally embedded; now documented).
    E8-ML2-MAC-05ML2-MAC-05PartialHigh§System hardeningUsers cannot change Office macro security settings (Group Policy/Intune enforced; now documented).

    JOSCAR-AU 2026(1)

    RequirementClauseCoverageSeverityNotes
    JOSCAR-Q2.11.11Q2.11.11Full§Security awareness and insider-threat trainingMandatory annual security-awareness and insider-threat training for all personnel; CISO-maintained packages and completion registers.
    Declared compliance references (6)
    • E8-ML2-AC-01
    • E8-ML2-MAC-05
    • E8-ML2-MFA-07
    • E8-ML2-MFA-08
    • E8-ML2-RAP-05
    • JOSCAR-Q2.11.11
    Document Revision Summary
    Rev Issued Document Ref Document Title Author Approved
    1 2026-06-08 TEC-PRO-002 Cyber Security Procedure FTM (CF) CEO (JDG)
    2 2026-06-18 TEC-PRO-002 Cyber Security Procedure FTM (CF) CEO (JDG)
    Document Revision Details
    Rev Purpose of revision and changes made
    1 Initial release under the WMS. Migrated as-is from WLK-GBL-PRO-FIT-001 Cyber Security (rev 1, 22/06/2023). Content preserved; reformatted into the WMS Document Template. Essential Eight compliance wiring deferred to a later ML2 uplift. Singapore service-office reference removed (subsidiary deregistered); security classification set to INTERNAL.
    2 Standards-conformance rewrite. Restructured into the WMS procedure section order (Purpose, Scope, Definitions, Responsibilities, Procedure), with records listed within the relevant Procedure subsections and references under Applicable Standards and Legislation. Incident detection, reporting and response content that duplicated TEC-PRO-001 Cyber Incident Response Procedure removed and re-pointed to TEC-PRO-001 by code. Language tightened to the WMS writing standards. Corrected the Essential Eight maturity statement (Maturity Level One met under DISP; DISP requirement since raised to Maturity Level Two, uplift scheduled 2027) and replaced the obsolete Adobe Flash browser-hardening control. Essential Eight / ML2 traceability wiring remains deferred to the Becloudsmart engagement (no traceability matrix).
    TEC-PRO-002 Rev 2 — Cyber Security Procedure Uncontrolled when printed