Home Politics Digital threats are crossing domains. Our responses should, too
Politics

Digital threats are crossing domains. Our responses should, too

Share
Digital threats are crossing domains. Our responses should, too
Share

As digital threats increasingly span across domains, cross-institutional cooperation is becoming central to national security. Australia needs to fuse cyber, physical and information-based threat indicators into one operational picture before crises emerge.

Australia’s national-security system is built for a world where military threats, criminal activities, network intrusions and infrastructure failures arrive separately as discrete problems and crises. In that world, threats can be neatly categorised by bureaucratic frameworks, placed under separate institutions and contained within certain domains.

But that world no longer exists. Contemporary digital threats blend cyber intrusion, physical sabotage, economic pressure and disinformation into single, sequenced operations. These operations deliberately exploit the seams between defence, intelligence, police, regulators and industry in a way that means none of those bodies is mandated, resourced or positioned to see the whole picture as it unfolds.

This issue was discussed at the fourth Digital Defence Symposium in Singapore, which I attended on 21 and 22 July. The symposium, hosted by the Association of Southeast Asian Nations Defence Ministers’ Meeting Cybersecurity and Information Centre of Excellence, brought together more than 300 military officers, government officers, researchers and industry representatives from 35 countries. Despite different angles, one message was clear: cooperation across institutions is becoming central to military readiness and national resilience.

Australia currently distributes digital responsibilities across distinct communities. Defence prepares for military threats. Intelligence agencies collect and assess. Police investigate crime. Cyber agencies protect networks. Regulators oversee critical sectors, while private firms own and run most of the infrastructure society depends on. But adversaries ignore these boundaries. A hostile campaign might begin by mapping critical infrastructure and telecommunications to harvest data and plant malware before moving through compromised suppliers, disrupting operational-technology systems and spreading coordinated disinformation to exploit public perception.

The convergence of cyber and physical risk is clearest in issues involving undersea cables. As Minister for Defence Richard Marles said at the Shangri-La Dialogue in May, Australia is among the nations most exposed  to this threat.  Around 95 percent of international data traffic travels through these cables, the physical infrastructure of which depends on landing stations, network-management systems, maintenance vessels and commercial providers. Their protection can’t be left to navies, border commands or telecommunications companies alone. It demands coordination across defence, intelligence, cyber authorities, regulators, police, border force, industry and international partners. Australia’s Security of Critical Infrastructure Act 2018 already covers 11 sectors, reflecting how interdependent essential services are. But regulating each sector separately does little to reveal how a failure in one could cascade into the others.

Australia should also move from reactive cybersecurity measures to pursue intelligence-led national resilience, supported by greater information-sharing. Many organisations concentrate activities and resources inside their own networks, including monitoring, firewalls and incident responses. The latter typically reveals only the end of a much longer campaign. Before alarms are raised, adversaries may have spent months on reconnaissance, supplier compromise, credential theft or mapping of social divisions they intend to exploit.

The Australian Signals Directorate’s latest threat assessment outlined that state-sponsored actors continued to target Australian governments and infrastructure. In response, the organisation recommended better logging, legacy-system replacement and third-party risk management. But this missed the anticipatory questions underneath those technical fixes: who is preparing to target Australia, which suppliers are being probed, and are threat activities being coordinated with coercion or information operations? Answering those will require the fusion of cyber intelligence with geopolitical analysis, law-enforcement data, open-source research and industry reporting, which need to exist before a crisis. This could be supported by joint exercises that bring national security specialists, military officers, intelligence, police and infrastructure operators into a shared operating language.

The real targets of cyber operations are the people behind the technology. Military commanders, public service officers, analysts, business leaders and members of the public are targets of identity leaks and influence operations. Malicious actors can manipulate digital service providers, corrupt what decision-makers see or convince the public that authorities have lost control. Australia’s resilience agenda should therefore include building cognitive resilience. This includes training society to recognise manipulated information, deepfakes, coordinated influence attempts and conspiracy theories.

It’s also important to understand how AI is being used. At the Digital Defence Symposium, Singapore’s Permanent Secretary for Defence, Joseph Leong, warned that technology was shifting from a tool into an actor. This was seen in a late July espionage operation in which malicious actors used autonomous AI to spy on the Thai Ministry of Finance. While AI could assist adversaries by automating reconnaissance and boosting information campaigns, it could also strengthen our defence through anomaly detection and predictive maintenance. Nevertheless, Australia must ensure human judgement remains part of high-impact decisions, as algorithms can’t be held accountable.

Adversaries are more likely to strike when they expect prolonged disruption and public panic. A prepared Australia with a crisis-response playbook – one that streamlines coordination between government bodies and private sectors to sustain essential services, restore systems quickly and communicate credibly – makes that calculation less attractive.

Source link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *