Australia’s strategic planners have spent decades contemplating conflict scenarios anchored in kinetic warfare: submarines, aircraft, naval engagements and territorial defence across the Indo-Pacific.
Yet the most consequential conflict Australia might face could begin not with missiles or bombardment, but with the collapse of digital infrastructure and the weaponisation of the systems on which modern society depends.
Glenn Maiden, chief security officer and director of threat intelligence for Fortinet Australia and New Zealand, frames this starkly: in any future conflict with peer competitors, cyber weapons will fire first, not as a prelude to conventional warfare, but as the primary mechanism to degrade military response capacity and civilian resilience simultaneously.
This is not theoretical risk. It is the operational calculus that underpins strategic planning across every major defence establishment confronting peer competitors. Australia’s preparedness for this scenario remains dangerously incomplete.
The asymmetric advantages of cyber warfare
The attraction of cyber weapons to state and non-state actors flows from three advantages that conventional military systems cannot match.
First, cyber operations are not constrained by distance. An adversary does not need proximity to an opposing force to inflict disruption.
An attacker operating from a different continent can compromise systems with the same effect as an actor positioned in-theatre.
Second, attribution remains sufficiently ambiguous that an aggressor can maintain plausible deniability regarding their identity and intent.
This opacity creates a buffer against immediate retaliation, transforming cyber operations into a weapon of choice for states that cannot afford the political cost of overt military confrontation.
Third, cyber weapons are extraordinarily cost-effective compared to kinetic alternatives.
The investment required to conduct a nation-state-scale cyber campaign bears no comparison to the budgetary requirements for long-range strike systems, submarine-launched weapons or aerial bombardment. For any actor seeking to impose strategic effect at minimal cost and risk, cyber represents an obvious avenue.
For Australia, these attributes create a specific vulnerability. An adversary intent on degrading military response capacity and civilian resilience across the continent could achieve that objective without deploying conventional forces.
As Maiden observes, disrupting a single pumping station or water utility using cyber means could impose consequences equivalent to kinetic attack populations without water after a matter of days.
The scope of effect is disproportionate to the investment required. And for Australia, it is increasingly probable rather than speculative.
The blurring of state and criminal threat
What complicates Australian threat assessment is no longer the traditional distinction between state-sponsored and criminal cyber operations. Investigations of recent conflicts reveal persistent blurring between these categories.
Wiper malware deployed against Ukrainian infrastructure exhibited simultaneous evidence of military and financially motivated criminal attribution. In the Israel–Palestine conflict, issue-motivated groups claiming ideological alignment rather than state sponsorship have conducted cyber attacks against Australian businesses perceived as sympathetic to one side or the other.
This convergence is not accidental.
State actors increasingly subsume criminal methodologies and tooling into their offensive operations. Criminal networks adopt state-grade capabilities. The result is a threat landscape where attribution is far more complex and motivation is far more diffuse than traditional strategic frameworks assume.
For Australian defence and national security architecture, this blurring creates a profound analytic problem.
Traditional threat assessment categorises state actors separately from criminal networks because the political calculus governing each is assumed to be different. State actors face retaliation risks and diplomatic consequences.
Criminal networks face law enforcement interdiction but operate without political restraint.
That distinction is collapsing in cyber space. The tools are now identical. The methodologies are now identical. And the targeting patterns show increasing convergence.
Australia’s strategic planning has not yet absorbed this reality into its threat models or response frameworks.
AI as accelerant: The weaponisation timeline
The integration of artificial intelligence and machine learning into cyber operations represents a multiplication rather than a transformation. Maiden identifies two critical impacts of AI integration on the threat side.
First, social engineering has become so sophisticated that human defenders can no longer reliably distinguish authentic communications from fabricated ones.
The malicious signal increasingly mimics legitimate traffic with fidelity sufficient to defeat visual inspection.
Second, and more operationally significant, the weaponisation timeline has collapsed catastrophically. Weaponisation, in technical terms, is the interval between public disclosure of a vulnerability and the appearance of exploitation code in active attacks by threat actors.
That interval has compressed from months to days. Current standard is 24 hours. For organisations attempting to patch deployed systems, 24 hours is an operationally impossible time frame. The result is a persistent window of vulnerability during which systems remain exposed to active exploitation.
The implications for Defence are severe. Patch management is foundational to cyber hygiene and network defence. When weaponisation occurs within 24 hours of disclosure, traditional patch cycles become inadequate.
Defence and critical infrastructure operators must operate under the assumption that publicly disclosed vulnerabilities will be actively exploited before patching can be completed. This is not a governance failure; it is a structural constraint imposed by accelerated threat cycles.
The countermeasure is not faster patching alone, but architectural resilience that assumes vulnerability exploitation will occur and ensures that exploitation does not translate into system compromise or capability loss.
This represents a fundamental shift in defensive philosophy from “prevent all intrusions” to “survive intrusion and restore capability rapidly”.

The missing demand signal for critical infrastructure
Australia has made substantive progress in establishing frameworks for critical infrastructure cyber security.
The Security of Critical Infrastructure legislation provides regulatory authority. The Essential 8 framework, published by the Australian Signals Directorate (ASD), offers prescriptive guidance for minimum viable security controls.
The Department of Home Affairs has driven messaging up to board level within critical infrastructure organisations, establishing clear accountability for cyber risk management. These are not trivial achievements.
They represent genuine institutional commitment to hardening the attack surface across water, electricity, telecommunications and transport infrastructure.
Yet Maiden identifies a critical constraint: the absence of explicit demand signals regarding the scale and urgency of cyber resilience investments. Critical infrastructure organisations understand the risk exists.
They have implemented minimum viable controls. But investment in advanced security architecture, threat intelligence integration and resilience-focused design requires capital allocation that boards justify based on explicit threat scenarios and risk quantification.
These demand signals have not been articulated at a level that translates into aggressive capital deployment.
The result is a critical infrastructure base that has implemented Essential 8 compliance but often lacks the advanced architecture necessary to withstand sophisticated, sustained cyber attack by state-capable actors.
This is particularly acute in regional and remote Australia. Maiden acknowledges that cyber resilience implementation degrades significantly beyond Sydney, Melbourne and Canberra.
As geographic distance increases, technical expertise becomes scarcer, technology investment becomes more economically challenging, and infrastructure becomes more exposed.
An adversary seeking to inflict maximum disruption at minimum risk would rationally target critical infrastructure operators in Australia’s north and west, where defensive capability is demonstrably thinner and recovery resources are more constrained.
The SME vulnerability cascade
Australia’s economy is structurally dependent on small and medium-sized businesses. This economic reality creates a cyber vulnerability cascade that has received insufficient policy attention. Small enterprises lack the resources to implement enterprise-grade security technology.
They lack dedicated cyber security personnel. They lack formal incident response plans. Yet they are frequently embedded within critical supply chains, manufacturing components, providing services or operating as logistics partners to organisations far larger than themselves. A vulnerability in a three-person manufacturing operation producing a component essential to power plant operations becomes a vulnerability in the power plant infrastructure itself.
Maiden emphasises the unquantified scale of this problem. Ransomware attacks have surged nearly 400 per cent year-on-year.
Yet only organisations with turnover exceeding 10 million dollars are subject to mandatory breach reporting legislation. Smaller organisations have no obligation to report compromise. This creates a massive blind spot in national threat assessment.
The cumulative impact of ransomware, credential theft and extortion targeting small businesses is not known.
The dependencies created by small business vulnerability are not mapped. The risk that a catastrophic national-scale incident could be triggered by compromise of ostensibly minor supply chain participants has not been systematically assessed.
Addressing this requires not technology solutions alone, but a fundamentally different approach to defensive democratisation. Advanced security technology must be accessible to small business at price points and complexity levels that do not demand in-house expertise to deploy and operate.
Managed service providers must absorb the technical burden of implementation and maintenance. This is not a market that currently exists at necessary scale. Creating it requires policy incentives and potentially direct government investment in capacity building.
Assume compromise: Reframing defensive architecture
Maiden articulates a defensive philosophy that represents a fundamental reorientation of how military and critical infrastructure organisations should approach cyber resilience.
Rather than attempting to prevent all intrusions – a goal that has proven unachievable and increasingly unrealistic – defenders should assume compromise as a base case scenario. Intrusions will occur.
Adversaries will gain initial access to networks. The question is not whether compromise happens, but whether compromise can be detected, contained and remediated before it translates into operational impact.
The question is not whether compromise happens, but whether compromise can be detected, contained and remediated before it translates into operational impact.”
This reframing has profound implications for architecture and operations. It means investing in detection and response capability with equal or greater priority than access prevention.
It means designing networks with segmentation that assumes perimeter breach and ensures that lateral movement is constrained even after adversary ingress.
It means developing incident response playbooks that can execute at speed sufficient to identify and neutralise threats before they degrade critical capability.
It means creating operational culture where a detected and contained intrusion is classified as a success, not a failure. Defence’s cyber operations centre and the ASD have implemented this philosophy within classified networks.
That same philosophy must now extend to Defence networks overall and to critical infrastructure operators who have historically attempted to maintain air-gaps or perfect perimeters that no longer exist in an interconnected world.
The AI harness: Containing uncontainable systems
As AI capabilities become embedded in both offensive and defensive cyber operations, a new challenge emerges – how to direct AI systems to perform beneficial functions while preventing unintended consequences. The concept of “AI harnesses” or guardrails represents an emerging defensive approach.
Rather than deploying AI agents with unrestricted access and capabilities, defenders define explicit boundaries: what the system can do, what it explicitly cannot do and what consequences trigger operator intervention. This is conceptually simple but technically complex to implement.
Maiden notes that Fortinet participates in Project Glasswing, an initiative in which leading global security vendors collaboratively test advanced AI systems against their defensive infrastructure before those systems are fielded to government or defence.
This approach allows defenders to identify AI-enabled vulnerabilities before operational deployment. Yet this is reactive by definition. It responds to AI systems that have already been developed and released.
The more difficult challenge is establishing governing frameworks that allow Australia and its defence establishment to engage AI capabilities as a force multiplier while maintaining control. Maiden is candid: the genie has left the bottle.
No policy framework will restore absolute containment. The task ahead is not prevention, but channelled engagement.
The sovereignty imperative
Maiden identifies an underappreciated strategic vulnerability: Australia’s reliance on international software-as-a-service platforms and hyperscale cloud providers. Defence systems depend on capabilities provided by multinational corporations whose infrastructure and decision-making authority reside outside Australia.
Should access to these services be restricted, either through vendor decision, geopolitical conflict or deliberate interdiction, Australia’s defence and critical infrastructure capability would degrade materially.
This is a sovereignty question that sits alongside cyber resilience. Australia must ensure not merely that its systems are secure, but that critical capability does not depend on continuous access to foreign-controlled infrastructure.
The near-term path forward requires three converging efforts. First, explicit demand signals from Defence regarding scale and speed of required cyber resilience. Second, investment in democratising advanced security technology to small and medium-sized business.
Third, deliberate decoupling of critical national systems from external dependencies where possible. None of this is achievable through technology procurement alone.
All of it requires sustained strategic commitment and willingness to accept costs in complexity, expense and operational friction as the price of genuine sovereignty and resilience in an era where cyber weapons precede kinetic ones.