TelSoc Newsletter – CommsDay Story of the Week

From CommsDay of 12 June 2026

Our Story of the Week is from today’s CommsDay. Earlier this week we have heard from a number of Government ministers on various matters going to Australia’s national security, national sovereignty, our digital future and defence.  Minister Marles spoke about changes to AUKUS, and referred to the inclusion within that program of the development of subsea drones and their potential use for monitoring the ever-growing number of cable systems connecting Australia with the global digital economy.  He emphasised digital dependency on our cable connections which carry over 95% of our internet traffic.  Ministers Ayres and Charlton have made important speeches and announcements about investment in critical digital infrastructure, including data centres.  There are many interconnected themes playing out in this area.  We have reprinted the article on the annmouncement by Minister Tony Burke, in his role as Minister for Cyber Security, of the new Horizon 2 plan for enhanced security of critical digital infrastructure.  The article spells out very clearly what Horizon 2 will do, and the consequences of not doing it.

The article follows on from last week’s Story of the Week in which a CommsDay Conference panel discussed digital infrastructure and the meaning of national sovereignty in today’s global digital environment.

Burke targets supply chain, subsea cables in next cyber strategy phase

Cyber security minister Tony Burke has put critical infrastructure supply chains, subsea cables and operational technology at the centre of the next phase of Australia’s national cyber strategy, warning that government and essential services remain the country’s greatest area of cyber risk.

The federal government has released the Horizon 2 action plan under the 2023–2030 Australian Cyber Security Strategy, with an additional $89.3 million over four years to drive new measures across critical infrastructure, technology security and cyber awareness.

Burke said Horizon 1 had focused on lifting cyber protections for government systems and critical infrastructure, including through the Cyber Security Act, mandatory ransomware reporting, the National Cyber Security Coordinator and the Executive Cyber Council.

“Our greatest area of risk is always government systems and critical infrastructure. Horizon 1 was about putting the strongest possible locks on the front door,” Burke said.

“In Horizon 2, we look at the supply chain that engages with government and critical infrastructure. We are now locking the windows.”

The plan will expand national cyber exercise programs to test real-world coordination and incident response, with a stronger focus on supply chains connected to critical infrastructure operators. Burke said the existing exercise program had largely focused on principal businesses, but would now extend further into the contractors and smaller suppliers that support essential services.

He said the government would prioritise small and medium businesses that were connected to government systems of signiϐicance or critical infrastructure, arguing they represented a disproportionate cyber risk because they often formed part of larger operational chains.

“Beyond that, anything in the supply chain on which you are dependent as critical infrastructure, even if they’re not plugging into your cyber system, if they go down, you might not be facing a cyber attack, but effectively your business is under attack because of someone else’s cyber attack,” Burke said.

Subsea cables are also singled out in Horizon 2. Burke said internet traffic might be discussed in abstract terms, but the infrastructure was physical and needed clearer regulatory treatment.

“We call it traffic on the internet, but 99 percent of it travels through subsea cables,” he said. “On subsea cables, we need to classify and secure.”

He said responsibility for subsea cable protection was spread across infrastructure, communications, Home Affairs and Defence interests, and that the government needed to streamline how the assets were regulated and protected.

The plan will also focus on “data sets of national significance” through a risk-based framework, as well as stronger logging and monitoring standards. Burke compared logging and monitoring to “CCTV” over data sets, saying organisations with effective logging could more quickly determine how far an intruder had penetrated a system and avoid having to assume all systems had been compromised.

The government also intends to strengthen security standards for connected technology used across homes, businesses and industrial environments, including routers, operational technology, consumer energy resources, smart devices and connected vehicles.

Burke said legacy IT and connected devices remained a common route into larger systems, with old or poorly secured equipment providing “the easy pathway through.”

He also highlighted the Cyber Security Act’s power to regulate connected devices, saying the first measures would target default passwords on imported devices. “It will no longer be possible to import material where the default password is password on devices,” he said.

Horizon 2 also flags work with telecommunications and cloud providers on upstream blocking of cyber threats. Burke compared the proposal to the way spam is increasingly filtered before reaching an email inbox, saying the government wanted to work with telcos and cloud providers to intervene earlier in the threat chain.

The strategy also includes a whole-of-government framework for the misuse of drone technology.

AI THREATS: Burke said artificial intelligence had increased the urgency of the cyber task by improving attackers’ ability to impersonate trusted people. He cited “vishing”, or voice phishing, where attackers could use AI-generated voices to trick employees into installing malicious software or disclosing sensitive operational information.

“Investing in a technical firewall is not enough. We need to improve the human firewall for real cyber security,” he said.

The government will develop a CyberSmart program, modelled in part on the UK’s Cyber Essentials scheme, to give small and medium businesses a simpler standardsbased cyber uplift path. Burke said the Australian Signals Directorate’s Essential Eight remained useful for government, large business and critical infrastructure, but was not designed for smaller firms.

The government said Horizon 1 had completed 60 action items by the end of last year. Burke said Horizon 2 would build on that work by focusing on infrastructure, devices and people.

“Nothing will stop those who want to attack us,” he said. “But we can make them as frustrated as possible, and Horizon 2 will do exactly that.”

TELCO THOUGHTS: The plan also follows public Horizon 2 submissions from Telstra and Vocus, the only two telcos to respond to last year’s Home Affairs consultation.

Telstra pushed back against generic cyber awareness messaging, arguing government should focus on why users and businesses still fail to adopt basic protections such as multifactor authentication despite years of campaigns. It also warned that requiring industry to block threats at scale would be impractical unless obligations reflected different levels of resources and capability. Instead, it called for higher-quality threat intelligence feeds, with validated indicators separated from lower-confidence material.

Telstra also said national cyber crisis arrangements remained unclear. While state emergency processes were well understood, it said industry did not always know which federal agency would issue directions in a major cyber incident, or how those directions would be delivered if communications were degraded.

Vocus used its submission to emphasise the physical infrastructure behind cyber resilience, arguing that trusted regional telecommunications networks were essential to Australia’s cyber security ambitions in the Pacific and Asia.

It was particularly direct on subsea cables, urging the government to treat them as critical infrastructure in the national interest. Vocus said current cable protection zones offered only passive protection and called for stronger monitoring, enforcement and additional zones in Darwin, Port Hedland, Maroochydore and Christmas Island, with government or ACMA to meet the cost of applications.

On satellites, Vocus urged early industry consultation before any extension of the Security of Critical Infrastructure regime to space technologies, calling for flexible, principles-based rules rather than prescriptive obligations.

Grahame Lynch

IN TODAY’S COMMSDAY (Friday 12June 2026)

Cyber security minister Tony Burke has put critical infrastructure supply chains, subsea cables and operational technology at the centre of the next phase of Australia’s national cyber strategy, warning that government and essential services remain the country’s greatest area of cyber risk.

Optus faces the prospect of compensation orders in a long-running privacy case that began more than five years ago, after the Australian Privacy Commissioner found the carrier had interfered with the privacy of customers whose details were published in the White Pages despite requests for unlisted numbers.

While the public debate over data centre construction in Australia is often framed around the risks involved, these risks are outweighed by the risks of not embracing data centres and AI, according to industry minister Tim Ayres. In a speech at a conference in Sydney yesterday, Ayres said the most dangerous response to the risk would be to retreat.

The Space Industry Association of Australia has warned proposed capital gains tax changes could undermine investment in space, AI, quantum and other high-growth technology sectors at a critical point in Australia’s innovation cycle.

Telecommunications Industry Ombudsman Cynthia Gebert has told a Senate inquiry that “sheer frustration” with telcos’ cancellation policies have driven a significant number of consumers to complain to the dispute-resolution body.

The federal government has authorised the Australian Financial Complaints Authority as the single external dispute resolution body for scam complaints across the telecom, digital platform and banking sectors.

The National Communication Museum has appointed arts executive Patrick McIntyre and technology lawyer Cheng Lim to its board as the Hawthorn-based museum moves into what it describes as its next strategic phase.

Hawaiki operator BW Digital has partnered with the National University of Singapore’s College of Design and Engineering to develop engineering frameworks for quantum-ready digital infrastructure in Southeast Asia’s tropical data centre markets.

AT&T chief financial officer Pascal Desroches has defended the company’s elevated network investment program, arguing that AI, autonomous vehicles, drones and smart devices will drive a new wave of bandwidth demand, particularly on the uplink.

_______________________________

CommsDay is published by Decisive Publishing, S704 6A Glen St Milsons Point NSW
ACN: 065 084960 Mailing Address: PO Box 490 Milsons Point NSW 1565 Australia

TO SUBMIT EDITORIAL FEEDBACK OR INQUIRIES: gr**********@**********il.com
TO ENQUIRE ABOUT A SUBSCRIPTION: vi***@**********il.com

 

With the compliment of TelSoc

Telecommunications Association Inc. ABN 34 732 327 053
Scroll to Top