Home Cyber Security

The Worst-Case Cyber Scenario: A Call to Action for Australian Organisations

David Shields, ANZ Government Consulting Lead for Mandiant (part of Google Cloud)
 

A recent headline about a cyber breach caught my eye. It suggested that the disclosure of personal information is the “worst case scenario” when a cyber breach occurs. While such incidents spark significant public concern, I don’t think this is in fact “The Worst-Case Cyber Scenario” as it was made out to be. This article isn’t about any specific breach, but rather takes a deeper look into what that “Worst-Case Cyber Scenario” could truly be for Australia.

For years, I’ve maintained that if, by the end of the decade, the worst cyber impacts are limited to ransomware and personal data leaks, it would be a win for the cyber industry and society. Perhaps I’m desensitised by supporting numerous organisations through their breaches, but hear me out.

The global geopolitical landscape heavily influences cyber threats. As U.S. Defence Secretary Pete Hegseth stated at the Shangri La Dialogue in May 2025, Beijing is “credibly preparing to potentially use military force to alter the balance of power in the Indo-Pacific. We know. It’s public that Xi has ordered his military to be capable of invading Taiwan by 2027. The PLA is building the military needed to do it. Training for it every day. And rehearsing for the real deal.” While opinions on the likelihood of conflict in the South China Sea vary, the risk of escalation is undeniably high. Offensive cyber operations will be a compelling tool for all involved. From Australia’s perspective and in the context of assumed support of the U.S., at least in principle, if not militarily, it’s highly probable that our interests would be targeted to distract, demotivate, and degrade our ability to respond, aiming for national paralysis.

Russia’s invasion of Ukraine offered crucial lessons in cyber doctrine supporting military objectives. Initially, the focus was on intelligence and pre-positioning, followed by propaganda and degrading emergency services, aligned with an assumed swift decapitation of Ukrainian leadership. When this failed, objectives shifted to intelligence gathering and supporting kinetic warfare, and surprisingly, kinetic warfare supporting cyber objectives, aiming to sap Ukraine’s will to fight through attacks on critical infrastructure.

However, we also learned that prior preparations make a difference. Russian cyber forces were pre-positioned for months, even years. This pre-positioning reveals targeting specifics and adversary priorities, which, when uncovered through advanced threat hunting, allows defenders to prioritise resources effectively, increasing the likelihood of successful defence.

Our potential adversaries have also learned from Russia’s limitations, particularly the need for tighter coherence between strategic and tactical cyber and military goals. We must defend where the enemy attacks this time, not where they attacked last time.

In a sustained cyber campaign by a sophisticated, well-resourced adversary with access to undisclosed vulnerabilities and the capacity for multiple global operations, logical Australian targets could include:

The key takeaway is that a “Worst-Case Cyber Scenario” will deliberately exploit our most sensitive vulnerabilities to keep us compliant, distracted, and fearful, while limiting our ability to respond directly to a crisis. These scenarios are not exhaustive, and indeed, we may find our adversary seeking to overwhelm us by broadly targeting multiple pressure points at the same time.

Tough decisions will be necessary regarding cyber-defence resource prioritisation. The potential impact of a worst-case scenario far exceeds the capacity of any single organisation. While the Government will play a vital coordinating role and provide bespoke technical capabilities, they cannot assist the potentially dozens or hundreds of large organisations that will need to respond quickly and effectively.

Similar to “Victory Gardens” during World War II, self-sufficiency will be critical. Many organisations will need to recover and self-sustain after such impacts. This scenario is a sobering reminder of what’s at stake and what a plausible “worst-case scenario” looks like in the current geopolitical climate.

My advice to all Australian organisations providing critical products and services is:

About the Author: David Shields has been supporting the Australian Government for his entire working life, including as a soldier in the Australian Army and within the Australian National Intelligence Community working on our nation’s biggest cyber security challenges. He is currently the ANZ Government Consulting Lead for Mandiant (part of Google Cloud) where he focuses on cyber resilience for the Australian and New Zealand Government, State

Owned Enterprises and Critical Infrastructure.