DrochaidHorizon3.ai
NodeZero/Industries/Government
The state of play — Government & Public Sector, 2026

State actors are targeting Australian Government networks for "state goals".

39% of the ransomware incidents the ACSC responded to in FY2024–25 were only discovered because ASD itself contacted the affected entity. HWL Ebsworth's April 2023 compromise cascaded across 62 Commonwealth entities.

83%
year-on-year increase in ASD cyber activity notifications to Australian entities — more than 1,700 in FY2024–25. ACSC responded to over 1,200 cyber security incidents, an 11% increase.
ASD Annual Cyber Threat Report 2024–25
39%
of the 138 ransomware incidents the ACSC responded to in 2024–25 were only discovered because ASD itself contacted the affected entity.
ASD Annual Cyber Threat Report 2024–25
13%
of Australian notifiable data breaches in H1 2025 came from Government agencies — the third-most-breached sector, behind health (18%) and finance (14%).
OAIC Notifiable Data Breaches Report, Jan–Jun 2025
The trend

Why Government is in the crosshairs

Five shifts shaping the government threat environment — what attackers are doing and what regulators now expect agencies to demonstrate.

Government is the third-most-breached sector — and the gap is closing

OAIC data shows government consistently in the top three NDB-notifying sectors, reaching 17% in H2 2024. ASD's 83% year-on-year increase in malicious-activity notifications and 1,700+ notification count reflect a sustained, intensifying operational tempo.

State-sponsored actors are the persistent adversary

The ASD 2024–25 report is explicit that state-sponsored cyber actors target Australian government networks, critical infrastructure, and businesses for "state goals" — espionage, malign influence, positioning for disruption. The 2019 Parliament House attack (publicly attributed by then-PM Morrison to a "sophisticated state actor"), the US OPM breach (22 million records), and the UK MoD/SSCL breach (~270,000 personnel) all sit in the same threat category.

Third-party contractors are the common entry point

OPM was breached via contractor KeyPoint Government Solutions. UK MoD was breached via Shared Services Connected Ltd. HWL Ebsworth's compromise affected 62 Commonwealth government entities through a single law firm breach. Service NSW lost 104,000 customers' data from 47 phishing-compromised staff email accounts.

DDoS and disruption — not just theft — are rising

ASD recorded a 280% year-on-year increase in DDoS against critical infrastructure, with hacktivist groups increasingly targeting government websites. Cyble's 2025 Threat Landscape report flagged government and law enforcement as the most-targeted sector globally by hacktivist groups. Adversary objectives now include visible disruption around geopolitical events, not only data theft.

Detection is lagging discovery

ASD's finding that 39% of ransomware incidents in 2024–25 were only discovered because ASD contacted the affected entity tells you what the sector-wide detection gap looks like. Controls that look strong on paper are missing attacks in operation. Continuous validation is how "assume compromise" becomes operational, not rhetorical.

On the record

What regulators and experts are saying

Businesses and organisations must operate with a mind-set of "assume compromise" and consider which assets or systems they cannot afford to lose.
ASD ACSC
Fact sheet for businesses and organisations
October 2025·cyber.gov.au
Individuals often don't have a choice but to provide their personal information to access government services. This makes it even more important that agencies keep personal information secure and have an action plan in place should a breach occur.
Carly Kind
Australian Information Commissioner and Privacy Commissioner
2025
The longstanding failure of OPM's leadership to implement basic cyber hygiene, such as maintaining current authorities to operate and employing strong multi-factor authentication, despite years of warnings from the Inspector General, represents a failure of culture and leadership.
US House Committee on Oversight and Government Reform
The OPM Data Breach report
September 2016
What is now required

PSPF 2025 mandates zero trust

The PSPF 2025 Annual Release requires all Commonwealth agencies to implement zero trust architecture — while ASD's Commonwealth Cyber Security Posture 2025 report shows only 22% of entities at overall Essential Eight ML2

Non-corporate Commonwealth entities must achieve Essential Eight Maturity Level 2 as the baseline for ICT security under the PSPF and ISM. The PSPF 2025 Annual Release adds a mandatory zero trust architecture requirement on top. Maturity is tracked publicly through ASD's annual Commonwealth Cyber Security Posture report — the 2025 report found only 22% of entities at overall ML2 — and ANAO performance audits repeatedly probe the same controls. The Essential Eight comprises eight mitigation strategies, each assessed to ML2 across a detailed set of controls. State and territory governments operate under separate frameworks but are increasingly aligning to federal standards.

Frameworks that apply
ASD Essential Eight Maturity Level 2

The full set of ML2 controls across eight strategies. The Commonwealth Cyber Security Posture 2025 report shows only 22% of entities at overall ML2.

Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

PSPF 2025 — zero trust mandate

Mar 2025

The PSPF 2025 release requires Commonwealth agencies to develop and maintain a zero trust strategy. Not guidance — a policy requirement, applying to non-corporate Commonwealth entities and those handling government information. NodeZero proves zero trust principles are actually enforced.

Cyber Security Act 2024

30 May 2025

Mandatory ransomware payment reporting within 72 hours for businesses over $3M turnover and responsible entities for critical infrastructure. Government-owned corporations and government service providers can be in scope — and government remains a high-value ransomware target due to citizen data and service criticality.

Privacy Act statutory tort

10 Jun 2025

Class action exposure for data breaches affecting citizens and employees. A breach affecting 1 million citizen records creates statutory tort liability to 1 million individuals. Government entities handling tax, health, and identity data face enormous exposure.

Smart Device Security Standards

4 Mar 2026

Minimum security standards for IoT and smart connected devices in government procurement. Covers building management, surveillance, SCADA, and network appliances. NodeZero validates whether compromised IoT devices can move laterally to critical systems.

Platform credentials

The only autonomous pentesting platform that is:

ISM / PSPF
Control-by-control
ASD controls
Essential Eight
Mapped ML1–3
Mandatory for Cth
NSA CAPT
Powered by NodeZero
US defence industrial base program
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Prove your compliance posture before your next audit

See how NodeZero maps to PSPF, ISM, and all 8 Essential Eight strategies in your environment