The Threat Is Named Now
Australia's intelligence leadership has stopped being coy. ASIO's annual threat assessments have warned that foreign intelligence services are actively targeting AUKUS — the technology, the workforce, and the supply chain — and that espionage and foreign interference now cost the Australian economy billions each year. Defence industry is not a peripheral target; it is the target. The same pattern shows up in ASD's Annual Cyber Threat Report 2024-25, which recorded an 83 per cent jump in notifications of potentially malicious activity and named state-sponsored actors as the drivers.
The methods are unglamorous and effective: approaches to engineers on professional networks, recruitment consultants who are not recruiters, joint ventures structured for access rather than profit, research partnerships with strings, and patient cultivation of people with clearances. None of it looks like a spy film. All of it looks like business.
Espionage Economics
It helps to think of industrial espionage as a procurement strategy. Developing an advanced capability domestically might take a foreign program a decade and billions of dollars. Acquiring the key design documents through a cultivated insider costs a fraction of that — and the person holding those documents is usually an employee of a subcontractor, not a prime. The economics guarantee the targeting: mid-tier suppliers hold classified information but historically invested the least in security culture.
This is precisely the gap the Defence Industry Security Program's personnel security domain was built to close.
Personnel Security Is Counter-Intelligence, Not HR
Read the DISP personnel security requirements through that lens and they stop looking arbitrary:
- AGSVA clearances are not a vetting tax — they are a structured look at whether a person with access to classified material is vulnerable to pressure, coercion or cultivation.
- FOCI declarations exist because foreign ownership, control or influence is the cleanest channel to the inside of a company. Defence is not asking out of nationalism; it is asking because ownership is leverage.
- Foreign contact and travel reporting maps the approaches. Intelligence services are patient; the pattern only becomes visible when contacts are recorded over time.
- Security awareness training works when it teaches the actual playbook — the flattering approach, the conference invitation, the too-generous consulting offer.
AUKUS Raises the Stakes — and the Standard
AUKUS concentrates exactly the technologies foreign programs most want: nuclear propulsion, hypersonics, quantum, advanced undersea systems. It also triples the number of cleared people and connected companies across three countries. Every new AUKUS supplier is a new potential entry point, which is why DISP obligations flow down through AUKUS contracts with unusual rigour, and why export control reforms like the ITAR exemption keep their eligibility conditions attached.
The uncomfortable implication for company leaders: if your business touches AUKUS work, assume your staff will be approached. The question your security plan must answer is not "would our people betray us?" — it is "would our people recognise the approach, and would they know to report it?"
What Serious Defence Recommends
Build the personnel security domain as a living system, not a folder: clearance registers with expiry tracking, foreign contact reporting that people actually use, FOCI monitoring as ownership changes, and training built on real approach scenarios. DISPulse tracks clearances, reporting obligations and awareness training continuously; DISPath builds the governance and personnel domains of your Security Plan to assessment standard. Our DISP requirements checklist covers the full personnel domain — and our research-sector guide addresses foreign interference risk specifically.
Image: CCTV cameras, via Wikimedia Commons (CC0).
