Lead story
Pre-Positioned and Patient: Nation-State Actors Are Already Inside Australian Critical Infrastructure
Australian spy agencies have confirmed what defenders have long feared: nation-state actors have successfully compromised critical infrastructure networks with the explicit goal of being able to "cripple" them at a moment of geopolitical choosing. The disclosure, reported by The Register, comes with an unusually specific detail — Australian intelligence services had to contact foreign counterparts to warn them that one adversary operation had already been discovered, effectively burning the intrusion before it could be used.
That detail matters. It suggests Australian signals intelligence identified the operation early enough to neutralise it diplomatically, rather than waiting for an incident response call. It's a rare example of offensive intelligence being used to defuse a threat rather than simply attribute it after the fact.
The phrase "cripple it at a time of their choosing" is the key framing here. This isn't espionage for intelligence gathering. It's pre-positioning — planting persistent access inside power, water, communications, or transport systems so that when diplomatic or military tensions spike, the attacker already has a loaded weapon inside the perimeter. Think of it as the cyber equivalent of pre-deploying forces close to a border.
Australia is not alone in facing this. The US Cybersecurity and Infrastructure Security Agency (CISA) has spent the last two years warning about exactly this pattern from Chinese-linked group Volt Typhoon, which embedded itself inside US critical infrastructure networks — not to steal data, but to sit and wait. The Five Eyes alliance issued a joint advisory on this very threat pattern last year. What's new here is an Australian official confirmation that it isn't theoretical.
For Australian organisations operating under the Security of Critical Infrastructure (SOCI) Act, this is the scenario the legislation was designed to address. The 2022 amendments significantly expanded SOCI's scope to cover 11 sectors — from electricity and water to data storage and higher education — and introduced mandatory incident reporting and risk management obligations. The question worth asking now is whether those obligations are producing the kind of network visibility needed to find pre-positioned implants, not just respond to active attacks.
Finding this kind of access requires more than a good EDR deployment. Pre-positioned threats tend to be low-and-slow — minimal command-and-control traffic, careful use of living-off-the-land techniques, long dwell times. Detection typically requires network-level telemetry and threat hunting, not just alert triage.
The Home Affairs secretary's comments, published separately in The Mandarin, offer a glimpse at how the government is thinking about this: emphasis on clarity of purpose, fast-moving teams, and cross-agency coordination. That's the right instinct. But coordination frameworks only work if the underlying visibility exists in the first place.
Watch for whether this disclosure triggers any updated guidance from the Australian Signals Directorate (ASD) or new SOCI compliance posture expectations from the Department of Home Affairs. Given the current regulatory environment and the recent overhaul of the Essential Eight, the timing of this disclosure feels less like a coincidence and more like groundwork for something.
