Australia’s Critical Infrastructure Is Less Cyber-Resilient Than the Risk Demands

Australia’s critical infrastructure does not need to be uniformly insecure for the nation to be at risk. It is enough that too many essential services remain dependent on ageing, interconnected and poorly understood technology; that security uplift is treated as a time-limited project rather than an operational discipline; and that adversaries need find only one weak path into a system whose failure affects millions.
This is the uncomfortable reality behind Australia’s cyber-security posture. The country has made real investments, created new regulation and improved national coordination. Yet the protection of essential services—energy, water, transport, telecommunications, health, logistics, meteorology and government—still falls short of what the strategic environment demands.
The problem is not a lack of strategies, frameworks or capable people. It is that Australia’s approach has too often measured activity rather than resilience: money committed, policies published, tools purchased, maturity assessments completed. None of those things necessarily proves that a utility can detect an intruder using legitimate credentials, isolate an affected network without stopping a service, or safely restore operations after a destructive attack.
Cyber security in critical infrastructure is not principally an IT problem. It is a national-resilience problem.
The consequence of failure is physical, economic and human
Most Australians experience cyber incidents as scams, leaked customer data or unavailable websites. Critical-infrastructure incidents are different. They can interrupt fuel supply, delay food and medicine, impede emergency response, prevent water treatment, affect rail signalling, degrade weather warnings or disrupt the movement of freight through ports.
ASD has made this point plainly: a sustained energy-sector failure can cascade into shortages of essential medical supplies, disruption to food and groceries, telecommunications, transport, traffic management and fuel supply. Critical infrastructure is interconnected, so a disruption in one sector rarely stays contained within it. ASD’s 2023–24 Annual Cyber Threat Report
The exposure is not theoretical. In 2024–25, ASD responded to more than 1,200 cyber-security incidents, with critical-infrastructure entities accounting for 13 per cent. Denial-of-service activity was present in 31 per cent of incidents involving critical infrastructure—almost twice its prevalence across all incidents responded to by ASD. ASD’s 2024–25 Annual Cyber Threat Report
These figures are useful, but they are not a complete measure of the problem. They reflect reported incidents and those that reach ASD’s attention. ASD itself has cautioned that apparent declines in reporting may indicate under-reporting. Quiet compromises, especially those involving valid accounts and “living off the land” techniques, can remain invisible for months or years.
Australia’s threat landscape has changed
Australia’s critical infrastructure has become a more attractive target because it is digitally connected, commercially valuable and strategically important. The old assumption—that a regional water authority, logistics provider or energy distributor is too small or obscure to interest a sophisticated adversary—is no longer credible.
The principal threats differ in intent, but all exploit the same underlying weaknesses.
Threat actor | Primary motivation | What it means for Australian infrastructure |
State-sponsored actors | Espionage, strategic advantage, coercion and pre-positioning for future disruption | Long-term, stealthy access to networks that support essential services |
Cybercriminal groups | Ransomware, data theft and extortion | Disruption creates leverage because operators cannot tolerate prolonged outages |
Hacktivists | Publicity, political messaging and disruption | DDoS, defacement and opportunistic attacks against high-profile targets |
Insiders and compromised suppliers | Access, negligence, fraud or coercion | Trusted access can bypass perimeter controls and bridge IT, OT and contractor environments |
The most concerning development is the growing evidence of state actors seeking persistent access rather than immediate disruption.
ASD has warned that PRC-linked actors, including Volt Typhoon, have targeted critical-infrastructure environments overseas to establish access that could be used to disrupt services during a geopolitical crisis. ASD assesses that Australian critical infrastructure could be vulnerable to similar activity. ASD advisory on Volt Typhoon
This matters because such activity does not necessarily look like a conventional attack. An adversary may exploit an unpatched appliance, steal administrator credentials, move through ordinary remote-management tools, map the environment and then wait. No ransom note appears. No systems are encrypted. The intrusion may be discovered only when the adversary chooses to act—or when a separate incident exposes it.
ASD has also stated that the PRC-linked group APT40 conducts regular reconnaissance against Australian networks, seeking opportunities to compromise targets. ASD advisory on APT40
Russian state-sponsored actors remain relevant because they have demonstrated the capacity to maintain long-term access, exfiltrate IT and operational-technology data, and disrupt industrial-control systems with destructive malware. ASD advisory on Russian cyber threats Criminal groups, meanwhile, do not need geopolitical motives. They simply need a victim for whom downtime is expensive enough to make extortion profitable.
The Bureau of Meteorology intrusion was an early warning
The 2015 Bureau of Meteorology intrusion remains one of Australia’s most important cyber-security case studies. It demonstrated how a compromise of an organisation that appears, at first glance, to be a scientific or public-information service can have national-security and critical-service implications.

ASD detected suspicious activity on two Bureau computers. Its investigation identified remote-access-tool malware associated with state-sponsored adversaries, evidence that the attacker had searched for and copied documents, a password-dumping utility, and malicious use of at least one legitimate domain-administrator account. The official report did not publicly attribute the intrusion to a particular country. ASD’s 2016 Threat Report
The lesson is not simply that a foreign actor breached a government agency. It is that the attacker was able to operate inside the environment using the privileges and tools that defenders themselves depend on. This is precisely the kind of intrusion that conventional, perimeter-focused security programs struggle to identify.
The government funded a five-year remediation program after critical cyber vulnerabilities were identified in the Bureau’s ICT infrastructure. ANAO audit of the Bureau That response was necessary. But it also exposes a recurring pattern: investment follows a serious incident, is framed as a remediation project, and must compete with every other operational and transformation priority. The harder task is ensuring that the uplift becomes permanent operational capability rather than a program that ends when its funding line does.
DP World showed how a cyber event becomes a national supply-chain event
The 2023 cyber incident at DP World Australia illustrates a different but equally important risk: disruption can occur even where incident responders make a sound containment decision.

After detecting unauthorised access to its Australian corporate network on 10 November 2023, DP World disconnected the network from the internet. This contained the incident but affected landside port operations. Operations recommenced on 13 November, and the company cleared a backlog of 30,137 containers by 20 November. DP World reported that no ransomware was deployed, although some employee data was accessed and exfiltrated. DP World’s incident update
The important point is not to second-guess that containment decision. It was responsible. The point is that a compromise of a corporate network affected the physical movement of freight. The boundary between “IT” and “operations” was not a meaningful boundary for the country’s supply chain.
This is a defining feature of modern critical infrastructure. Email, identity services, remote access, scheduling, billing, vendor support, monitoring and operational technology may be logically separated in architecture diagrams, yet remain operationally dependent on one another.
Why major cyber-security improvement programs fail
Most cyber-security uplift programs do not fail because organisations do nothing. They fail because the work is mismatched to the nature of the risk.
First, many programs are funded and governed as projects. They deliver a new security platform, a revised policy suite, a completed asset register or a maturity score. But security is never “delivered.” Vulnerabilities return, suppliers change, credentials are stolen, systems are reconfigured and staff turnover. A project can buy capability; only sustained operational funding, ownership and testing make that capability dependable.
Second, organisations often do not know their own critical paths well enough. They may have a corporate IT asset register but lack a current understanding of which remote-access pathway reaches a control system, which vendor account has privileged access, which Windows server supports a safety system, or which cloud identity can administer multiple environments. An organisation cannot defend what it has not discovered, classified and mapped.
Third, operational technology is difficult to secure safely. Industrial systems are designed for availability, safety and long service life. Patching or replacing a device may require an outage, vendor involvement, regulatory approval or a carefully controlled maintenance window. As ASD notes, these systems are often difficult to patch and increasingly connected to corporate IT and the internet. ASD’s critical-infrastructure threat assessment Security teams must therefore work with engineers, control-room operators and safety specialists—not impose generic IT controls from outside the operational context.
Fourth, compliance can become a substitute for assurance. A board can receive a green dashboard, an Essential Eight self-assessment and confirmation that a risk-management plan exists, while the organisation still lacks reliable log coverage, tested recovery procedures or visibility of privileged supplier activity. Compliance is useful as a baseline. It is not evidence that an organisation can withstand a determined adversary.
Fifth, the incentives are misaligned. The cost of meaningful resilience is borne by individual asset owners, while much of the benefit accrues to the public and the nation. A water provider may struggle to justify replacing legacy remote-access infrastructure when the avoided consequence is a low-probability but high-impact public-health incident. This is why government intervention and regulation are necessary—but they must be focused on measurable resilience outcomes, not paperwork.
Sixth, too many organisations buy tools before solving the operating model. A security operations centre cannot detect what is not logged. A vulnerability-management platform cannot manage unidentified assets. Multifactor authentication is not enough if privileged access, break-glass accounts, service identities and contractor pathways sit outside it. Technology is vital, but it does not compensate for unclear accountability or an incomplete view of the environment.
Finally, recovery is under-engineered. Backups are not resilience unless they are protected from the attacker, tested at realistic scale and capable of restoring the service that matters. An incident-response plan is not readiness unless executives, engineers, suppliers and government counterparts have exercised the decision to isolate a network while maintaining essential services.
Investment matters—but where it goes matters more
It would be wrong to suggest that governments have ignored cyber security. The 2020 Cyber Security Strategy committed $1.67 billion over ten years. 2020 Cyber Security Strategy The 2023–2030 strategy has added further investment, strengthened the focus on critical infrastructure and set out a multi-horizon approach to improving national cyber resilience. 2023–2030 Cyber Security Strategy
Those investments have value: ASD’s capability, threat sharing, incident response, regulation and sector coordination all improve Australia’s position.
But national investment does not automatically remediate every ageing system, resolve fragmented state and federal responsibilities, create experienced OT-security engineers, or make third-party suppliers accountable for secure remote access. Funding can strengthen the national shield while significant weak points remain inside individual operators.
The objective should not be a claim of perfect security. It should be a demonstrable ability to prevent common intrusions, detect sophisticated ones, safely contain an incident and restore essential services quickly.
What credible resilience would look like
Australia should expect every critical-infrastructure operator to demonstrate—not merely attest—that it can do five things:
Identify the systems and dependencies whose failure would affect essential services.
Control and continuously monitor privileged access across employees, contractors, vendors, IT and operational technology.
Detect adversaries using legitimate credentials and ordinary administration tools, not only malware signatures.
Isolate compromised systems without blindly shutting down safety-critical operations.
Restore critical services through rehearsed, independently tested recovery plans.
Boards and regulators should demand evidence in the form of technical exercises, recovery tests, adversarial assessments and service-impact scenarios. A mature organisation should be able to answer a simple question: “If this system, supplier or identity were compromised tonight, what would stop functioning, who would know, and how would we restore it?”
That is the standard Australians should expect. Essential services underpin national security, economic security and public safety. They cannot be protected by strategies alone.





Comments