Skip to main content
Geopolitics & DefenseNational Security

Australia Urged to Fuse Threat Data to Counter Cross-Domain Attacks

Undersea cables exposed at a coastal facility, highlighting physical vulnerability.

Around 95 percent of international data traffic travels through undersea cables, a vulnerability the source material says "can’t be left to navies, border commands or telecommunications companies alone."

Digital Defence Symposium, 21–22 July: a cross-domain alarm bell

The fourth Digital Defence Symposium in Singapore, held on 21 and 22 July and hosted by the Association of Southeast Asian Nations Defence Ministers’ Meeting Cybersecurity and Information Centre of Excellence, gathered more than 300 military officers, government officers, researchers and industry representatives from 35 countries. Participants brought different perspectives, but the shared message was stark: contemporary digital threats frequently span cyber, physical and information domains and require coordinated responses across institutions.

Undersea cables and the limits of single-agency responses

At the Shangri‑La Dialogue in May, Minister for Defence Richard Marles said Australia is among the nations most exposed to undersea-cable risk. The report stresses why: those cables carry roughly 95 percent of international data traffic and depend on a chain of landing stations, network-management systems, maintenance vessels and commercial providers. The piece warns that protection "can’t be left to navies, border commands or telecommunications companies alone," instead demanding coordination across defence, intelligence, cyber authorities, regulators, police, border force, industry and international partners.

Australian Signals Directorate: technical fixes versus anticipatory questions

The Australian Signals Directorate’s latest threat assessment, as cited in the source, outlined that state-sponsored actors continued to target Australian governments and infrastructure. Its recommended remedies included better logging, legacy-system replacement and third-party risk management. The writing argues these are necessary but incomplete: they address the tail end of campaigns without answering the anticipatory questions — who is preparing to target Australia, which suppliers are being probed, and whether activity is coordinated with coercion or information operations.

AI, influence operations and the human target

Speakers at the symposium highlighted the human dimension. Singapore’s Permanent Secretary for Defence, Joseph Leong, warned that "technology was shifting from a tool into an actor." The source describes a late July espionage operation in which malicious actors used autonomous AI to spy on the Thai Ministry of Finance. The piece draws two linked conclusions: adversaries can use AI to automate reconnaissance and amplify information campaigns, and defences must preserve human judgement for high‑impact decisions because "algorithms can’t be held accountable." It also emphasises cognitive resilience — training people to recognise manipulated information, deepfakes, coordinated influence attempts and conspiracy theories — because the ultimate targets of cyber operations are people behind the technology.

Intelligence-led national resilience and fused information

The source calls for moving from reactive cybersecurity responses to "intelligence-led national resilience, supported by greater information-sharing." It notes that many organisations concentrate monitoring and incident response within their own networks, often detecting only the end of much longer campaigns. The recommended remedy is fusion: combining cyber intelligence with geopolitical analysis, law‑enforcement data, open-source research and industry reporting to build a shared operational picture before crises arise. Joint exercises that bring national security specialists, military officers, intelligence, police and infrastructure operators together are proposed to create a common operating language and anticipatory posture.

What this means for defence, regulators, and the public

  • Defence and intelligence: Expect calls to expand coordination efforts and to fuse technical threat indicators with geopolitical analysis and law‑enforcement reporting so operations are detected earlier, not just after compromise is discovered.
  • Regulators and infrastructure operators: The Security of Critical Infrastructure Act 2018 already covers 11 sectors, but the piece argues sector-based regulation alone risks missing cascading failures; regulators will be pushed toward cross-sector planning and supplier-focused scrutiny.
  • The public and civic institutions: The report advocates building cognitive resilience — public education on deepfakes, manipulated information and influence operations — because preserving trust and preventing panic is part of national resilience.

The core prescription is operational: fuse information across domains, exercise those fused capabilities before a crisis, and retain human oversight where decisions have strategic consequence. As the source concludes, "A prepared Australia with a crisis-response playbook — one that streamlines coordination between government bodies and private sectors to sustain essential services, restore systems quickly and communicate credibly — makes that calculation less attractive" for adversaries.

Original story