DrochaidHorizon3.ai
NodeZero/Industries/Defence & DISP
The state of play — Defence & DISP, 2026

State actors are targeting the Australian Defence industrial base.

Not just the primes — the subcontractors, engineers, and professional services firms that hold the data. Both publicly documented Australian Defence supply chain compromises on record started with a single exposed, unpatched internet-facing service.

83%
year-on-year increase in ASD cyber activity notifications to Australian entities — more than 1,700 in FY2024–25.
ASD Annual Cyber Threat Report 2024–25
30%
of all breaches globally now involve a third party — double the prior year. Defence supply chains are the primary target.
Verizon 2025 DBIR
22%
of vulnerability-exploitation breaches target edge devices and VPNs — an eightfold jump. Only 54% of those vulnerabilities are fully remediated.
Verizon 2025 DBIR
The trend

Why Defence is in the crosshairs

Five shifts shaping the Defence threat environment — what attackers are now doing, and what regulators now expect in response.

State actors are targeting the industrial base, not just the prime

ASD's 2024–25 report is explicit that state-sponsored actors target government, critical infrastructure, and Australian businesses for "state goals" — including espionage, positioning for disruption, and theft of data that supports targeting of firms further up the supply chain. Defence subcontractors are in scope because the data they hold maps directly onto allied military programmes.

The attack pattern is not sophisticated — it is persistent

The 2016 "APT Alf" compromise of an Australian aerospace firm used an unpatched IT helpdesk server and default credentials. The 2025 IKAD Engineering incident used an outdated VPN. Almost a decade apart, the root causes are identical: exposed edge services that continuous validation would have surfaced. Verizon's data shows this is now the dominant initial access pattern globally.

AUKUS raises the stakes

AUKUS Pillar II expands technology collaboration across US, UK, and Australian industry. Each new collaborative programme adds a tier of subcontractors — and each tier is a potential attack surface. The UK MoD/SSCL breach (~270,000 personnel affected via a third-party payroll provider) and the US OPM breach (22 million records via contractor credentials) both happened through outsourced providers, not the agencies themselves.

Compliance-only security is no longer enough

DISP Level 1 required Essential Eight ML1. The November 2025 uplift to ML2 raises the bar again. But Essential Eight is a control framework — it specifies what should be in place, not whether controls actually block today's attacker tradecraft. ASD itself has said entities should "assume compromise" and validate controls accordingly.

The regulatory trajectory is towards continuous evidence

Mandatory ransomware reporting (effective 30 May 2025, for entities over $3M turnover and CI entities) and ongoing SOCI Rule 10 refinements signal the direction of travel: regulators want evidence that controls are working, not just that they exist on paper.

On the record

What regulators and experts are saying

State-sponsored cyber actors continue to pose a serious and growing threat to our nation. They target networks operated by Australian governments, critical infrastructure and businesses for state goals.
Australian Signals Directorate
Annual Cyber Threat Report 2024–25
October 2025·cyber.gov.au
Businesses and organisations must operate with a mind-set of "assume compromise" and consider which assets or systems they cannot afford to lose.
ASD ACSC
Fact sheet for businesses and organisations
October 2025·cyber.gov.au
We do worry about what we call in the jargon supply chain risk, or the soft underbelly of professional services firms doing this type of thing, often more cheaply and arguably more efficiently than perhaps they are done in government.
Ciaran Martin
Former founding CEO, UK National Cyber Security Centre
May 2024·The Register
What is now required

ML2 is now mandatory for all DISP members

Since 15 November 2025, all DISP members must achieve Essential Eight ML2 across corporate ICT systems used to correspond with Defence. Non-compliance can result in membership suspension or loss.

All DISP members must achieve Essential Eight Maturity Level 2 across corporate ICT systems used to correspond with Defence. This has been mandatory since 15 November 2025, replacing the previous Top 4 at ML1 requirement. The Essential Eight comprises eight mitigation strategies, each assessed to ML2 across a detailed set of technical and process controls — covering application control, patching, MFA, privilege management, hardening, macros, and backups. DISP assessors verify compliance through a combination of self-assessment and evidence review. Companies involved in AUKUS programmes may also need to demonstrate alignment with NIST 800-171 and future CMMC requirements.

Source: Defence.gov.au — DISP Cyber and Assurance
Frameworks that apply
ASD Essential Eight Maturity Level 2

The full set of ML2 controls across eight strategies. Required for all DISP members since 15 November 2025.

Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

Cyber Security Act 2024

30 May 2025

Mandatory ransomware reporting within 72 hours for entities over $3M turnover. Defence contractors are high-value targets — they hold IP, engineering specs, and classified data that ransomware operators and nation-state actors specifically seek. NodeZero identifies the attack paths ransomware would use: exposed RDP, weak admin credentials, unpatched edge devices.

Source: Cyber Security Act 2024

Privacy Act statutory tort

10 Jun 2025

Direct class action exposure for data breaches. Defence contractors hold security-sensitive employee data — clearance status, family information, medical records, vetting documentation. A breach doesn't just trigger Privacy Act liability. It compromises clearance holders and can trigger DISP sanctions.

Source: Privacy Amendment Act 2024

AUKUS ITAR exemption

Dec 2025

Australian contractors now handle US-controlled Defence technology directly — submarine designs, weapons software, space technology. This increases both the attack surface and compliance requirements. NIST 800-171 alignment and future CMMC certification both apply to AUKUS participants.

Source: Federal Register — ITAR final rule

CMMC cascade to Australian contractors

2026-2027 (projected)

US Cybersecurity Maturity Model Certification is expected to apply to Australian contractors handling US Defence information. Australian companies bidding on US DoD subcontracts will need to demonstrate CMMC readiness. NodeZero maps to NIST 800-171 control families that underpin CMMC.

Source: US DoD CMMC programme
Beyond the platform

NodeZero tests your controls. Drochaid bridges the gap to full compliance.

Essential Eight ML2 spans eight strategies with a detailed set of technical and process controls. NodeZero directly validates roughly a third — the technical controls where assessors need proof they work under attack. The remaining controls cover governance, process documentation, and configuration management. Drochaid helps you bridge from NodeZero's testing evidence to the full compliance package your DISP assessor needs.

ML2 gap analysis
We map NodeZero findings against the full set of ML2 controls and show you exactly where you have evidence and where you still need work.
Remediation guidance
Prioritised remediation plans addressing both the technical gaps NodeZero found and the governance gaps it can't test.
Assessment preparation
We assemble the full evidence package — NodeZero reports, policy documentation, process evidence — ready for your DISP assessor.
Platform credentials

The only autonomous pentesting platform that is:

DISP
Control-by-control
Defence supply chain
Essential Eight
Mapped ML1–3
Mandatory for DISP
NSA CAPT
Powered by NodeZero
US defence industrial base program
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

See your ML2 gaps before your assessor does

Book a baseline assessment and get a clear picture of where you stand against all eight Essential Eight strategies