State actors are targeting the Australian Defence industrial base.
Not just the primes — the subcontractors, engineers, and professional services firms that hold the data. Both publicly documented Australian Defence supply chain compromises on record started with a single exposed, unpatched internet-facing service.
Why Defence is in the crosshairs
Five shifts shaping the Defence threat environment — what attackers are now doing, and what regulators now expect in response.
State actors are targeting the industrial base, not just the prime
ASD's 2024–25 report is explicit that state-sponsored actors target government, critical infrastructure, and Australian businesses for "state goals" — including espionage, positioning for disruption, and theft of data that supports targeting of firms further up the supply chain. Defence subcontractors are in scope because the data they hold maps directly onto allied military programmes.
The attack pattern is not sophisticated — it is persistent
The 2016 "APT Alf" compromise of an Australian aerospace firm used an unpatched IT helpdesk server and default credentials. The 2025 IKAD Engineering incident used an outdated VPN. Almost a decade apart, the root causes are identical: exposed edge services that continuous validation would have surfaced. Verizon's data shows this is now the dominant initial access pattern globally.
AUKUS raises the stakes
AUKUS Pillar II expands technology collaboration across US, UK, and Australian industry. Each new collaborative programme adds a tier of subcontractors — and each tier is a potential attack surface. The UK MoD/SSCL breach (~270,000 personnel affected via a third-party payroll provider) and the US OPM breach (22 million records via contractor credentials) both happened through outsourced providers, not the agencies themselves.
Compliance-only security is no longer enough
DISP Level 1 required Essential Eight ML1. The November 2025 uplift to ML2 raises the bar again. But Essential Eight is a control framework — it specifies what should be in place, not whether controls actually block today's attacker tradecraft. ASD itself has said entities should "assume compromise" and validate controls accordingly.
The regulatory trajectory is towards continuous evidence
Mandatory ransomware reporting (effective 30 May 2025, for entities over $3M turnover and CI entities) and ongoing SOCI Rule 10 refinements signal the direction of travel: regulators want evidence that controls are working, not just that they exist on paper.
What regulators and experts are saying
State-sponsored cyber actors continue to pose a serious and growing threat to our nation. They target networks operated by Australian governments, critical infrastructure and businesses for state goals.
Businesses and organisations must operate with a mind-set of "assume compromise" and consider which assets or systems they cannot afford to lose.
We do worry about what we call in the jargon supply chain risk, or the soft underbelly of professional services firms doing this type of thing, often more cheaply and arguably more efficiently than perhaps they are done in government.
ML2 is now mandatory for all DISP members
Since 15 November 2025, all DISP members must achieve Essential Eight ML2 across corporate ICT systems used to correspond with Defence. Non-compliance can result in membership suspension or loss.
All DISP members must achieve Essential Eight Maturity Level 2 across corporate ICT systems used to correspond with Defence. This has been mandatory since 15 November 2025, replacing the previous Top 4 at ML1 requirement. The Essential Eight comprises eight mitigation strategies, each assessed to ML2 across a detailed set of technical and process controls — covering application control, patching, MFA, privilege management, hardening, macros, and backups. DISP assessors verify compliance through a combination of self-assessment and evidence review. Companies involved in AUKUS programmes may also need to demonstrate alignment with NIST 800-171 and future CMMC requirements.
Source: Defence.gov.au — DISP Cyber and AssuranceThe full set of ML2 controls across eight strategies. Required for all DISP members since 15 November 2025.
ASD's comprehensive security controls manual. DISP members handling classified information must align with ISM controls relevant to their security level.
Where NodeZero appliesInternational information security standard. Often required by Defence primes as a supply chain prerequisite alongside DISP membership.
Where NodeZero appliesService organisation controls for security and availability. Relevant for Defence contractors providing managed services or cloud-hosted solutions to Defence.
Where NodeZero appliesApplies to Defence contractors handling personal information of Defence personnel, veterans, or subcontractors.
Where NodeZero appliesMandatory ransomware reporting and security standards for critical infrastructure entities, which includes many Defence suppliers.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
Cyber Security Act 2024
30 May 2025Mandatory ransomware reporting within 72 hours for entities over $3M turnover. Defence contractors are high-value targets — they hold IP, engineering specs, and classified data that ransomware operators and nation-state actors specifically seek. NodeZero identifies the attack paths ransomware would use: exposed RDP, weak admin credentials, unpatched edge devices.
Source: Cyber Security Act 2024Privacy Act statutory tort
10 Jun 2025Direct class action exposure for data breaches. Defence contractors hold security-sensitive employee data — clearance status, family information, medical records, vetting documentation. A breach doesn't just trigger Privacy Act liability. It compromises clearance holders and can trigger DISP sanctions.
Source: Privacy Amendment Act 2024AUKUS ITAR exemption
Dec 2025Australian contractors now handle US-controlled Defence technology directly — submarine designs, weapons software, space technology. This increases both the attack surface and compliance requirements. NIST 800-171 alignment and future CMMC certification both apply to AUKUS participants.
Source: Federal Register — ITAR final ruleCMMC cascade to Australian contractors
2026-2027 (projected)US Cybersecurity Maturity Model Certification is expected to apply to Australian contractors handling US Defence information. Australian companies bidding on US DoD subcontracts will need to demonstrate CMMC readiness. NodeZero maps to NIST 800-171 control families that underpin CMMC.
Source: US DoD CMMC programmeNodeZero tests your controls. Drochaid bridges the gap to full compliance.
Essential Eight ML2 spans eight strategies with a detailed set of technical and process controls. NodeZero directly validates roughly a third — the technical controls where assessors need proof they work under attack. The remaining controls cover governance, process documentation, and configuration management. Drochaid helps you bridge from NodeZero's testing evidence to the full compliance package your DISP assessor needs.
Find your organisation
See how the changes affect you specifically
DISP members
Active or applying. Must prove ML2 across corporate ICT systems used to correspond with Defence.
View details →Prime contractors
Your suppliers must meet ML2. Defence expects you to verify it — not take their word for it.
View details →Supply chain SMEs
Same ML2 requirements, fraction of the budget. DIDG grants may cover up to 50% of costs.
View details →AUKUS readiness
Essential Eight is your foundation. AUKUS demands interoperability with US and UK cyber security standards. Start proving it now.
View details →The only autonomous pentesting platform that is:
References
Everything cited on this page — regulator reports, incident coverage, and official framework documentation.
See your ML2 gaps before your assessor does
Book a baseline assessment and get a clear picture of where you stand against all eight Essential Eight strategies


