DrochaidHorizon3.ai
NodeZero/Industries/Mining & Resources
The state of play — Mining & Resources, 2026

Reported cyber incidents in mining tripled in 2024 — and that is only what is reported.

Australian mining-related incidents kept surfacing through 2025, with attackers increasingly targeting contractors and METS suppliers to reach larger operator networks. Rio Tinto (Cl0p via GoAnywhere, 2023) and Northern Minerals (BianLian, 2024) are the named anchor cases.

30 vs 10
reported attacks on mining in 2024 versus 2023 — a tripling year-on-year, and MM-ISAC emphasises massive under-reporting sits behind that figure.
MM-ISAC, via Mine Australia
71% / 55%
of mining participants reported more disruptive attacks in the past 12 months; 55% worried about their ability to manage a cyber threat.
EY Global Information Security Survey
~80%
of cyberattacks in the mining industry are financially motivated — the goal is operational disruption for ransom, not just data theft.
Rob Labbé, MM-ISAC, via Mine Australia
The trend

Why Mining and Resources are in the crosshairs

Five shifts shaping the Australian mining threat environment — what attackers are doing, and what regulators now expect of operators and their suppliers.

Reported incidents tripled in 2024, and under-reporting hides the rest

MM-ISAC's 10-to-30 jump year-on-year is the cleanest sector-specific metric available, and Rob Labbé has been explicit that it reflects only the incidents MM-ISAC knows about. Australian mining has historically under-reported; mandatory ransomware reporting from 30 May 2025 and the Cyber Incident Review Board will tighten visibility, but ground truth is likely materially higher than the 30.

Automation and IT/OT convergence keep expanding the attack surface

Rio Tinto's Koodaideri "intelligent mine" is emblematic of what is happening across the sector — autonomous haul trucks, remote operations centres, digital twins, predictive-maintenance sensors, and integrated ERP-to-pit systems. Each new connection blurs the IT/OT boundary and adds ground that a compromised corporate credential can now reach.

Contractors and METS suppliers are now the primary entry path

Recent Australian incidents confirm what MM-ISAC has said for years — attackers target smaller contractors to reach larger mining networks. The June 2025 DragonForce compromise of Pressure Dynamics International, a resources contractor, fits this pattern. It is the mining-specific instance of the third-party breach trend Verizon's 2025 DBIR records doubling year-on-year.

Double-extortion exposes payroll, employee, and family data — not just IP

Rio Tinto's March 2023 Cl0p/GoAnywhere incident exposed payroll data, overpayment letters, and employee family information. Northern Minerals (BianLian, March 2024) lost corporate, operational, financial, employee, shareholder, and executive email data. This is the concrete PII exposure that triggers OAIC notification and class-action exposure, on top of any operational impact.

Regulators now expect evidence that controls work

SOCI applies to critical-minerals and energy-adjacent mining. The Cyber Security Legislative Package 2024 introduced mandatory ransomware reporting and a Cyber Incident Review Board. DISP-aligned suppliers face Essential Eight ML2 from November 2025, and Tier 1 miners' own supplier-assurance programmes increasingly ask for demonstration of control effectiveness, not attestation that controls exist.

On the record

What regulators and experts are saying

In 2024, the number of reported attacks rose to 30, up from ten in 2023, highlighting the sector's growing vulnerability. And those are just the ones we know about — there is massive under-reporting in cyber incidents.
Rob Labbé
CEO and CISO in residence, MM-ISAC
March 2025·Mine Australia
We face daily attempts, as all companies do. Common attacks range from password spraying and brute forcing to social engineering and phishing/vishing campaigns.
Jeff Pick
Director of Cybersecurity Architecture and Operations, Freeport-McMoRan
March 2025·Mine Australia
Businesses and organisations must operate with a mind-set of "assume compromise" and consider which assets or systems they cannot afford to lose.
ASD ACSC
Annual Cyber Threat Report 2024–25 fact sheet
October 2025·cyber.gov.au
What is now required

Mining is under escalating cyber pressure

MM-ISAC logged three times as many attacks on mining in 2024 as in 2023, and attackers are increasingly reaching operators through contractors and METS suppliers. Oil and gas majors are designated SOCI Act critical infrastructure.

Mining and resources entities operating designated critical infrastructure assets are subject to the SOCI Act CIRMP obligations — typically large-scale energy generation, liquid fuels, or assets designated by the Minister. The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt one of five approved frameworks. Energy sector entities may choose the AESCSF, which is specifically designed for the Australian energy sector. Mining entities also face obligations under the Privacy Act 1988 and state-based mining and resources regulations that increasingly include cyber security requirements.

Legislation
SOCI Act — Critical Infrastructure Risk Management Program

Federal legislation covering energy, resources, and mining as critical infrastructure sectors. Oil and gas majors and designated mining entities must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector and tests IT/OT boundary segmentation under the supply chain vector. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.

Your chosen CIRMP cyber frameworkSelect one
Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

SOCI Act — responsible entities for energy and resources assets

In effect

Responsible entities for critical energy and resources assets carry mandatory obligations — a board-approved risk management program, critical systems protection, and 12/72-hour cyber incident notification.

Cyber Security Act 2024

30 May 2025

Mining companies over $3M turnover must report ransomware payments within 72 hours, and SOCI-regulated assets carry additional 12/72-hour incident notification obligations.

Critical Minerals Strategy 2023-2030

In effect

Australia's Critical Minerals List identifies the minerals essential to defence and energy security — 31 resource commodities as at February 2024. A policy strategy rather than a regulatory instrument — but it sharpens government expectations on supply-chain security, alongside existing export-approval and FIRB foreign-investment screening regimes.

State mining regulations — Cyber/OT overlap

2024-2025

Cyber failures in automated equipment and OT are increasingly treated as work health and safety issues, not just IT incidents — a lens that puts attack-path evidence in front of safety regulators too.

Platform credentials

The only autonomous pentesting platform that is:

SOCI
Control-by-control
Energy & resources
Essential Eight
Mapped ML1–3
ASD baseline
Gartner Peer Insights
4.7 / 5
Customers' Choice (Oct 2025)
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Validate your IT/OT boundary before the next incident

See how NodeZero tests IT network resilience and segmentation in your mining environment