Australian critical infrastructure and civilian networks are increasingly vulnerable to sophisticated cyberattacks, according to the Australian Signals Directorate (ASD). State-funded hackers, particularly those linked to Russia, are actively targeting communications, energy grids, financial services, and healthcare systems. Because the internet lacks physical borders, individual businesses and home users now act as the front line of the nation’s digital defense.
The Escalating Risk to Critical Infrastructure
The threat to infrastructure is no longer theoretical. In 2021, hackers breached a water treatment facility in Oldsmar, Florida, by exploiting remote-access software. An employee witnessed the attacker remotely controlling the mouse to manipulate sodium hydroxide levels in the drinking water to toxic concentrations. Lincoln Goldsmith, director of the digital security firm Semperis, warns that this “is not a case of if, but a case of when,” urging organizations to operate under the assumption that their security has already been breached.
The danger extends well beyond water. Last year, Russian hackers targeted the Polish electricity grid by probing digital “doorknobs” and hinges. They gained remote access to over 30 wind and solar farms that relied on default factory usernames and passwords, successfully cutting power to roughly half a million people during the winter months. These attacks aim to create chaos, confusion, and public pressure, often by targeting the supply chains of nations supporting Ukraine.
Did you know?
The first recorded cyberattack on critical infrastructure occurred during Operation Desert Storm in 1990. US intelligence agents intercepted French-made desktop printers destined for Iraq, installing corrupted chips that subsequently crippled the nation’s air defense network.
The Weakest Link: Legacy Technology and IoT
Modern digital security is often undermined by “legacy technology”—older systems that remain in use long after they have been forgotten or stop receiving security patches. According to Mr. Goldsmith, while software layers are frequently updated, the core code of the internet—such as the 25-year-old Active Directory—remains a primary target. Because Active Directory manages user identities and access, if it is compromised, an entire organization can be paralyzed.
The “Internet of Things” (IoT) has further expanded the attack surface. Devices like smart speakers, televisions, and even household appliances are often connected directly to international data centers. “With consumer products, there is no data sovereignty,” Mr. Goldsmith notes. When these devices are left unpatched or use outdated operating systems, they provide “side entrances” for hackers to infiltrate larger corporate or government networks.
The Human Factor in Cyber Defense
The Five Eyes intelligence alliance—comprising Australia, the US, the UK, New Zealand, and Canada—has issued warnings for organizations to conduct comprehensive audits of their networks. The goal is to determine which devices are truly necessary and ensure all software is current. However, the responsibility often falls on individuals, such as mechanics or small business owners, who may not realize their personal devices serve as gateways to major industrial systems.
The introduction of Artificial Intelligence (AI) into daily operations adds another layer of risk. Semperis research indicates that a majority of organizations believe AI will increase attacks on identity infrastructure, yet only a minority are very confident in their ability to regain control if administrator credentials are exposed. Many organizations continue to install AI-enabled tools “out of the box” without proper authentication, leaving them open to exploitation.
Pro Tips for Digital Security
- Audit Your Connections: Regularly check which devices are connected to your network. If a device does not need to be online, disconnect it.
- Patch Everything: Prioritize updating legacy software and operating systems. If a device is no longer supported by the manufacturer, it is a significant security liability.
- Use Free Tools: Organizations can utilize resources like Semperis’s Forest Druid or Purple Knight to identify security gaps and attack paths within their Active Directory environments.
Frequently Asked Questions
Why are hospitals and local councils being targeted?
State-funded hackers target healthcare and local services to cause public disruption and panic. According to Mr. Goldsmith, the high stakes—human lives—often pressure organizations into paying ransoms, though this rarely solves the underlying security breach.
What is the “digital arms race”?
It is a cycle where organizations upgrade their security (the “castle walls”), only for attackers to develop more sophisticated methods (the “cannons”) to breach them. This constant evolution makes maintaining digital sovereignty an ongoing, active process rather than a one-time setup.
Can I protect myself from IoT-based attacks?
Yes. Start by changing default factory usernames and passwords on all smart devices. Ensure your router is updated and isolate critical devices from unnecessary public-facing network access.
Are you concerned about your organization’s digital security posture? Explore our resource center for more guides on hardening your network, or subscribe to our newsletter for the latest updates on emerging cyber threats.
Worth a look