In 2024, operators of critical infrastructure and organisations that service critical infrastructure faced a surge in cyberattacks amidst escalating geopolitical tensions. According to the Australian Signals Directorate’s (ASD) 2024 Annual Cyber Threat Report, state-sponsored actors persistently targeted essential sectors like energy, healthcare, and telecommunications, employing sophisticated tactics such as zero-day exploits and custom malware. Notably, this year, the Australian government repeatedly warned Australian companies about Chinese-sponsored threat actors specifically targeting western (and Australian) critical infrastructure.
Given that we at Mipela service the critical infrastructure sector, staying ahead in our cybersecurity efforts is of paramount importance. The threat is real, and we must do what we can to protect both ourselves and our customers.
We are staying on top of cyber threats through automated patching; enforced device compliance for access to company resources; and security training for our team on the latest phishing techniques. Central to our approach is our robust Security Information and Event Management (SIEM) system and Security Operations Centre (SOC), operated in collaboration with Fortian, our trusted Australian cybersecurity partner.
Our SIEM collects and analyses logs from across our business systems in real-time, enabling us to detect and respond swiftly to emerging threats. Unlike conventional SOCs that rely heavily on generic vendor-provided detections, our SOC employs a tailored, threat-informed methodology. This approach ensures that our detection capabilities align closely with our unique threat profile. For example, in 2024, the ASD reported a campaign by Iranian threat actors targeting Australian critical infrastructure through brute force and MFA fatigue attacks originating from specific VPN IP addresses. Within hours of this disclosure, our SOC conducted a comprehensive threat hunt to identify potential indicators of compromise within our environment. New analytic rules were deployed promptly, ensuring continuous monitoring for these activities on an hourly basis.
By combining strict access controls, a partnership with a leading cyber security provider, and a tailored threat-informed approach, we aim to ensure that Mipela remains secure in a hostile digital landscape where critical infrastructure and their suppliers remain at constant risk.