VIEWPOINT: Australia preparing for tomorrow’s defence challenges with yesterday’s cyber posture
By Jason Duerden
•Jun 4, 2026
Jason Duerden The nature of national security has irrevocably changed. Cyber security is no longer a niche technical concern sitting adjacent to national defence; it has become the foundational, non-negotiable condition upon which Australia’s entire future strategic posture and sovereign capability rests. Australia’s latest Budget rightly commits major investment to the next generation of Defence capability, from AUKUS and autonomous platforms to guided weapons, secure communications and sovereign industrial capacity. But the more Australia invests in advanced capability, the more urgent another question becomes – are the digital and operational systems behind that capability being secured with the same discipline? That question shouldn’t be treated as theoretical. ASD has warned that AI is accelerating vulnerability, discovery and exploitation, while ASIC has called for urgent cyber uplift as frontier AI intensifies the threat environment. The message from regulators is that organisations need to strengthen cyber fundamentals, reduce attack surfaces, patch promptly, assume breach, prepare incident response and use AI defensively where appropriate. The question for government, Defence and industry is whether they are holding themselves to the same standard now being expected of the private sector. Modern Defence capability depends on software, cloud environments, operational technology, identity systems, data platforms, communications networks, industrial suppliers and digital services. Every major capability program now carries a digital dependency, and every supply chain now has a cyber dimension. In that environment, delay is not a neutral position. The greatest risk to Australia’s Defence readiness is assuming cyber resilience can be addressed after the platforms, programs and industrial capacity are already in place. The new readiness test Australia’s readiness can no longer be judged only by what it buys, builds or deploys. It also depends on whether the digital infrastructure supporting those programs can detect, withstand and recover from attacks designed to disrupt operations or compromise sensitive national security data. AI makes that test more urgent. Threat actors can now discover vulnerabilities, generate attack paths and scale intrusion attempts at machine speed. Defence and critical infrastructure environments need the ability to detect abnormal behaviour, contain attacks and recover at the same pace. Defence readiness now sits across three connected layers: Defence capability, critical infrastructure, and the industrial and digital supply chains that support both. Australia’s military platforms depend on secure communications, energy, transport, logistics, cloud environments, OT systems, software providers and government services. If those systems are disrupted, national capability is weakened even if the platform itself remains intact. This is the layer adversaries are already testing. State-backed actors are targeting critical infrastructure, government agencies, universities, research institutions and Defence-linked organisations. They are probing the systems that sit around national capability; contractors, software suppliers, managed service providers, logistics networks and smaller businesses. A weak supplier, exposed credential, unpatched system or compromised software dependency can create a pathway into far more sensitive environments. Sovereign capability needs sovereign resilience As Australia invests more deeply in sovereign Defence capability, the cyber stakes become higher. Building more capability onshore expands the number of local organisations that need to operate with Defence-grade cyber resilience. A submarine program, autonomous platform, guided weapons enterprise or secure communications network is only as resilient as the systems, suppliers and software that support it. If those environments are fragmented, poorly monitored or slow to respond, adversaries can look for the weakest connected point. That makes supply chain visibility a core Defence readiness issue. If Australia wants sovereign Defence capability to be resilient, defence-in-depth needs to become a practical mandate across the supply chain. That means layered controls, tested response plans, restricted lateral movement and real visibility across the systems that support national capability. It cannot remain an academic tabletop exercise or a line item in a compliance framework. AI is changing the speed of the threat AI will make this challenge sharper. The Budget’s $70 million AI Accelerator is a smart start, but AI adoption also changes the threat model. AI can help defenders move faster, analyse more data and automate response. It can also help attackers compress the time between reconnaissance, exploitation and impact. Threat actors can use AI to identify exposed systems, generate convincing social engineering, accelerate vulnerability discovery and scale attacks across poorly defended environments. In a Defence context, that matters because the attack surface includes the broader industrial, research and technology ecosystem. The Australian Signals Directorate’s recent guidance on agentic AI makes clear that organisations need to treat AI systems as operational and security risks, particularly where they are given access to sensitive data, tools or critical systems. The risk is privilege, identity and visibility The issue is privilege. AI agents and automated systems can act across multiple environments, call tools, access data and make decisions at machine speed. If those systems are poorly governed, poorly monitored or over-permissioned, they can create new attack paths. Defence and critical infrastructure cannot afford blind spots in this layer. Security teams need to know what is running, who or what has access, which systems are exposed, and how quickly an intrusion can be contained. That requires operational visibility across cloud, endpoint, identity, software and AI environments. These are often treated as separate technical domains, but adversaries do not operate that way. They move through whichever pathway gives them the most leverage: a stolen credential, exposed cloud key, vulnerable software dependency, unmanaged endpoint or overly permissive identity. Bridging the gap between strategy and defence capability Australia has made progress on cyber policy through the 2023–2030 Cyber Security Strategy, critical infrastructure reforms and stronger expectations on regulated sectors. But policy architecture does not stop an attack in progress, and neither does procurement. Government, Defence and industry cannot wait for long acquisition cycles while adversaries move at machine speed. The capabilities needed to detect, contain and recover from AI-enabled threats are needed now, across the Defence supply chains, critical infrastructure and OT environments that support national capability. The next phase must focus on operational readiness. That means detection and response capability that can match the speed of modern threats, fewer attack paths across Defence supply chains, and identity controls for both human and non-human actors. We cannot protect machine-speed infrastructure with human-speed security. Australia’s strategic environment is becoming more contested, more digital and more automated. Ships, submarines, guided weapons and autonomous systems will remain essential, but they are only one part of the readiness equation. The architecture being made today will determine whether Australia can defend against AI-enabled threats and the new attack models that emerge over the next decade. The next test is whether Australia can secure the digital systems, OT environments, critical infrastructure and supply chains that keep national capability operating under pressure. Note: Jason Duerden is Area Vice President Australia & New Zealand, SentinelOne. For Editorial Inquiries Contact: Editor Kym Bergmann at [email protected] For Advertising Inquiries Contact: Group Sales Director Simon Hadfield at [email protected]
