The Report That Should End the Debate
The Australian Signals Directorate's Annual Cyber Threat Report 2024-25 is not ambiguous. ASD notified entities more than 1,700 times about potentially malicious cyber activity during the year — an 83 per cent increase on the year before. Reported incidents rose 11 per cent, and attacks on critical infrastructure rose by 111 per cent. For large businesses, the average cost of cybercrime jumped 219 per cent.
The foreword names the strategic driver plainly: state-sponsored cyber actors, led by China and Russia, are targeting Australian networks for espionage and potential disruption. This is not opportunistic crime. It is preparation.
Pre-Positioning Is the Strategy
Since early 2024, Five Eyes agencies have been warning about the same pattern: PRC state-sponsored actors compromising critical infrastructure operators — communications, energy, water, transport — and maintaining persistent access. The intelligence community's assessment is that this access is intended to enable disruptive effects during a crisis, not merely to steal information today.
Think about what that means for the defence supply chain. An adversary does not need to attack Defence directly. It needs access to the logistics provider moving materiel, the engineering firm holding classified drawings, the MSP administering a prime contractor's network. The softest point in the chain is rarely the prime — it is the small and mid-tier supplier with a flat network and an unpatched firewall.
Why This Is the DISP Threat Model
This is the context that makes the Defence Industry Security Program's cyber requirements coherent. The full Essential Eight at Maturity Level 2 — mandatory for every DISP member since 30 September 2024 — is not an arbitrary compliance bar. The eight strategies (application control, patching, macro restriction, application hardening, restricted admin privileges, operating system patching, multi-factor authentication, and backups) map directly onto the techniques state actors use to gain and keep access.
When Defence asks for ML2 across the systems you use to correspond with Defence, it is asking whether your organisation could be the quiet entry point into a classified program. When the Annual Security Report asks your Chief Security Officer to declare ongoing compliance, it is asking whether that posture held for twelve months, not just on assessment day.
The Uncomfortable Question for Boards
The ACTR's 111 per cent rise in attacks on critical infrastructure should put a hard question on every defence-adjacent board agenda: if a state actor spent twelve months inside your network, would you know? Most organisations cannot honestly answer yes. ML2's logging, MFA and privilege controls are precisely the controls that convert "we hope not" into "we would detect it."
Compliance programs built to pass an assessment on a single day fail this test. Continuous compliance — evidence collected as a byproduct of operations, not assembled before an audit — is the only posture that matches a persistent adversary.
What Serious Defence Recommends
Start with an honest Essential Eight ML2 gap assessment — not a vendor attestation, but a control-by-control review against ACSC's maturity criteria. Then close gaps in the order an attacker would exploit them: MFA and privilege restriction first, patching discipline second, application control third. Our DISPulse platform automates exactly this — continuous ML2 evidence collection across all eight strategies, with your Annual Security Report generated from live data. And if you are building toward DISP for the first time, DISPath structures the whole program. The threat is patient. Your compliance posture has to be just as persistent.
Image: BalticServers data center, via Wikimedia Commons (CC BY-SA 3.0).
