State actors are targeting Australian Government networks for "state goals".
39% of the ransomware incidents the ACSC responded to in FY2024–25 were only discovered because ASD itself contacted the affected entity. HWL Ebsworth's April 2023 compromise cascaded across 62 Commonwealth entities.
Why Government is in the crosshairs
Five shifts shaping the government threat environment — what attackers are doing and what regulators now expect agencies to demonstrate.
Government is the third-most-breached sector — and the gap is closing
OAIC data shows government consistently in the top three NDB-notifying sectors, reaching 17% in H2 2024. ASD's 83% year-on-year increase in malicious-activity notifications and 1,700+ notification count reflect a sustained, intensifying operational tempo.
State-sponsored actors are the persistent adversary
The ASD 2024–25 report is explicit that state-sponsored cyber actors target Australian government networks, critical infrastructure, and businesses for "state goals" — espionage, malign influence, positioning for disruption. The 2019 Parliament House attack (publicly attributed by then-PM Morrison to a "sophisticated state actor"), the US OPM breach (22 million records), and the UK MoD/SSCL breach (~270,000 personnel) all sit in the same threat category.
Third-party contractors are the common entry point
OPM was breached via contractor KeyPoint Government Solutions. UK MoD was breached via Shared Services Connected Ltd. HWL Ebsworth's compromise affected 62 Commonwealth government entities through a single law firm breach. Service NSW lost 104,000 customers' data from 47 phishing-compromised staff email accounts.
DDoS and disruption — not just theft — are rising
ASD recorded a 280% year-on-year increase in DDoS against critical infrastructure, with hacktivist groups increasingly targeting government websites. Cyble's 2025 Threat Landscape report flagged government and law enforcement as the most-targeted sector globally by hacktivist groups. Adversary objectives now include visible disruption around geopolitical events, not only data theft.
Detection is lagging discovery
ASD's finding that 39% of ransomware incidents in 2024–25 were only discovered because ASD contacted the affected entity tells you what the sector-wide detection gap looks like. Controls that look strong on paper are missing attacks in operation. Continuous validation is how "assume compromise" becomes operational, not rhetorical.
What regulators and experts are saying
Businesses and organisations must operate with a mind-set of "assume compromise" and consider which assets or systems they cannot afford to lose.
Individuals often don't have a choice but to provide their personal information to access government services. This makes it even more important that agencies keep personal information secure and have an action plan in place should a breach occur.
The longstanding failure of OPM's leadership to implement basic cyber hygiene, such as maintaining current authorities to operate and employing strong multi-factor authentication, despite years of warnings from the Inspector General, represents a failure of culture and leadership.
PSPF 2025 mandates zero trust
The PSPF 2025 Annual Release requires all Commonwealth agencies to implement zero trust architecture — while ASD's Commonwealth Cyber Security Posture 2025 report shows only 22% of entities at overall Essential Eight ML2
Non-corporate Commonwealth entities must achieve Essential Eight Maturity Level 2 as the baseline for ICT security under the PSPF and ISM. The PSPF 2025 Annual Release adds a mandatory zero trust architecture requirement on top. Maturity is tracked publicly through ASD's annual Commonwealth Cyber Security Posture report — the 2025 report found only 22% of entities at overall ML2 — and ANAO performance audits repeatedly probe the same controls. The Essential Eight comprises eight mitigation strategies, each assessed to ML2 across a detailed set of controls. State and territory governments operate under separate frameworks but are increasingly aligning to federal standards.
The full set of ML2 controls across eight strategies. The Commonwealth Cyber Security Posture 2025 report shows only 22% of entities at overall ML2.
ASD's comprehensive controls manual. Federal agencies must implement ISM controls proportionate to their information classification level.
Where NodeZero appliesRelevant for government agencies procuring cloud or managed services — vendors are increasingly expected to provide SOC 2 reports.
Where NodeZero appliesAll federal government agencies are bound by the Australian Privacy Principles when handling personal information.
Where NodeZero appliesMandatory ransomware reporting obligations and minimum security standards apply to government entities and their suppliers.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
PSPF 2025 — zero trust mandate
Mar 2025The PSPF 2025 release requires Commonwealth agencies to develop and maintain a zero trust strategy. Not guidance — a policy requirement, applying to non-corporate Commonwealth entities and those handling government information. NodeZero proves zero trust principles are actually enforced.
Cyber Security Act 2024
30 May 2025Mandatory ransomware payment reporting within 72 hours for businesses over $3M turnover and responsible entities for critical infrastructure. Government-owned corporations and government service providers can be in scope — and government remains a high-value ransomware target due to citizen data and service criticality.
Privacy Act statutory tort
10 Jun 2025Class action exposure for data breaches affecting citizens and employees. A breach affecting 1 million citizen records creates statutory tort liability to 1 million individuals. Government entities handling tax, health, and identity data face enormous exposure.
Smart Device Security Standards
4 Mar 2026Minimum security standards for IoT and smart connected devices in government procurement. Covers building management, surveillance, SCADA, and network appliances. NodeZero validates whether compromised IoT devices can move laterally to critical systems.
Find your organisation
See how the changes affect you specifically
Federal agencies
Non-corporate Commonwealth entities must achieve Essential Eight ML2 — the 2025 posture report shows only 22% have. Maturity is reported and published annually.
View details →State departments
NSW, Victoria, Queensland, and other states operate under separate frameworks but are increasingly aligned with federal Essential Eight and PSPF standards.
View details →Local councils
500+ councils across Australia with growing ransomware exposure. Cyber insurance now requires testing evidence. Cost-effective continuous validation without the consulting price tag.
View details →The only autonomous pentesting platform that is:
Prove your compliance posture before your next audit
See how NodeZero maps to PSPF, ISM, and all 8 Essential Eight strategies in your environment


