The cyber strategy trap
Australia’s cyber strategy has been busy measuring its own delivery. The other players have changed the rules.
Editor’s note: A note on where Dead Reckoning is heading follows the article.
Two years into the 2023 Cyber Security Strategy, the government’s verdict on itself is glowing. All 60 Horizon One initiatives, it reports, were delivered on intent, on time and on budget—$586.9 million, more than 30 agencies, with progress graded against the Commonwealth Evaluation Toolkit.
A strategy that reports success as on-time delivery has told you its real objective is delivery.1
The scaffolding says the same thing. The stated ambition was to make Australia a world leader in cyber by 2030, pursued through six ‘shields’, providing a ‘defence in depth’ running from the individual and small business up to the region and ‘global leadership’, across three ‘horizons’ along a set roadmap, each evaluated and the next adjusted in turn. That’s the language of program management, not of contest.
It is also a linear managerial control system. Such a system—even with ‘adaptive horizons’—cannot match the variety of a shifting field of adversaries. That is W. Ross Ashby’s Law of Requisite Variety. Home Affairs’ self-assessment itself concedes that the cyber workforce is being pulled away from uplift and incident response into compliance reporting (p. 37).
For cyber is not what James Carse calls a finite game—one with fixed rules, boundaries and an agreed definition of winning. It is an infinite game, in which the goal is simply to keep playing, and the rules can be changed by any player to that end.
So while the strategy defines success as the ‘delivery’ of a plan and the status of ‘world leader’—whatever that means—Australia’s adversaries are asking quite different questions. One asks whether it can make Australia’s lights, water and communications falter at a moment of its choosing, while it continues to hoover up whatever it can on intellectual property, on commercial and military settings, and on the people it wants to track. Another is purely opportunistic: how best to extort a company for money. A third looks for ways to embarrass a government and so acquire leverage. There are other motives again. But in every case the goal is to stay in the game, not to be eliminated by someone else’s strategy.
In short, the 2023 Cyber Security Strategy is a competent piece of administrative policy overtaken by a strategic problem it was not built to see.
The intruders are already inside
What it needed to see was less bureaucratic planning and more of the frankly boring mechanics underneath. It needed, too, not to be dazzled by the glamour shot—the surprise of China’s Volt Typhoon, pre-positioning for disruption, and Salt Typhoon, telecommunications espionage that reached even into lawful-interception infrastructure. Both campaigns succeeded not through sophistication but, like the great majority of effective attacks, through foundational failure: default passwords, unpatched CVEs, legacy kit, and the built-in system tools that make living-off-the-land possible.
And for all Horizon One’s achievements, the intruders are still in our systems. In June the Director-General of ASIO disclosed that a critical-infrastructure provider had been compromised, the intruder busy with preparation for sabotage. Nor is it only Chinese actors: a joint Cybersecurity Advisory of 14 July 2026 set out how Russian state actors systematically scan Australian and allied networks for ‘poorly configured’ and unpatched edge devices—routers, firewalls, SNMP interfaces—to hold persistent access. Full eviction, US senators concluded of Salt Typhoon late last year, is virtually impossible without rebuilding significant parts of the underlying infrastructure.
It is a reminder, too, that there is no such thing as a backdoor that only the good guys can use.
These vulnerabilities are unglamorous and structural. The strategy’s shields guard the perimeter of the problem; they do not touch the incentives that leave a water utility running the factory password.
The AI accelerant
And that is the heart of it: the incentives around cyber security. Bug bounties and named CVEs attract money and status; there is no leaderboard for auditing a SCADA2 firewall. The structures, the status and the rewards all tilt toward offence, not defence—and AI tips that imbalance further still. In February 2024, Microsoft and OpenAI described adversaries using large language models as passive aids to ‘productivity’: scoping, coding, drafting phishing emails. By November 2025, Anthropic disclosed an AI-orchestrated espionage campaign, likely Chinese, of which 80 to 90 per cent was automated; CrowdStrike’s 2026 threat overview reported an 89 per cent rise in AI-enabled attacks and described AI as a force multiplier for the attacker.
Then in mid-July, OpenAI’s model broke containment during a cyber-security evaluation and roamed for four days across Hugging Face, Modal and other services; Anthropic disclosed three of its own containment failures a fortnight later. If the frontier labs, with evaluation harnesses and safety teams and every commercial reason to look competent, cannot keep these systems inside the perimeter, then a shield architecture asking a municipal water utility to self-assess against a maturity model is not a serious proposition.
The significance is not novelty but tempo. The patient, skilled human operator who once throttled campaigns like Volt Typhoon is precisely the constraint that AI removes; as it dissolves, the balance tips harder toward offence. None of this was in view in 2023, which was a different world. Doubling down on the same roadmap—and layering on still more compliance, regulation and control—does not close the gap. It feeds it.
The distance fallacy
Culturally, Australia still leans on the conviction that distance is its oldest strategic asset. In cyber—in technology generally—that conviction is a trap, and the complacency it breeds is itself the vulnerability. An adversary who cannot cheaply project force across the sea–air gap can still reach into the grid; pre-positioning is the rational substitute for proximity. The geography that lets the political class and its decision-makers feel time-rich is exactly what invites an adversary to buy time inside our infrastructure.
The strategy’s on-time, on-budget self-congratulation is the domestic correlate: a governance culture optimised for the appearance of control in a domain that punishes it. Institutions that mistake activity for security should not be rewarded.
The strategy is not wrong, exactly, but it is scoped for the wrong contest. The Horizon 2 plan offers the right words—AI-incident visibility, ‘permissible cyber defence activities’, post-quantum readiness, subsea cables—but leaves them as consultations and forums inside Home Affairs’ shield architecture, disconnected from the one lever that actually moves the offence–defence balance: AI itself.
Meanwhile the Prime Minister has concentrated AI authority in PM&C’s new Office of AI, announced on 15 July 2026, and framed it around standards, data centres and copyright. So the nexus that now matters most—AI and cyber defence—falls between two stools: too operational for the Office as conceived, too structural for Home Affairs’ shields. That is the cyber strategy trap: a contest mistaken for a delivery schedule, in a country that mistakes distance for safety.
A note on where Dead Reckoning is heading
We’ve been on Substack for a little over two years, and we rebadged to Dead Reckoning earlier this year. Since then the readership has grown faster than at any point before it, and we’re grateful for that.
We also know there aren’t many people writing on this particular intersection in Australia: defence strategy and industrial capability, technology and cyber, supply chains and sovereignty, and the health of democratic institutions. That’s a good part of why we keep going.
From here, everything is free. No paywall, no partial posts.
The reasoning is straightforward. Our work is most useful when it reaches the people actually making decisions, and a paywall works against that. We’d rather be read.
To our paid subscribers
Thank you. You backed something with no track record, and that mattered more than the money did.
You’ve now paid for something we’re giving away, and we want to be fair. If you’d rather not continue, cancel whenever you like. No explanation needed, and no hard feelings.
If you’d like to keep supporting it, we’d be glad of that, and it now means something different: you’re helping fund the work rather than buying access to it. Nothing is withheld from anyone.
What we can offer in return:
First look at our playbooks. Practical method guides for practitioners—the first is on assessing your own supply chain the way Defence, a prime or an investor will. Supporters see them before they go out publicly.
A direct line. Reply to any post and it comes straight to us.
A say in what we cover.
That last one is a real request, not a courtesy. You’ve paid closer attention to this than most, and you’ll have a better sense than we do of where the gaps are. What should we be writing about that nobody is? What have we covered too lightly? Where do you think we’ve got it wrong?
And for everyone else
Reading is free and always will be. If at some point you find this useful enough to want to support it, the option is there. If not, that’s genuinely fine; the readership is the point.
Reply to this, or write to us at concierge@geomastery.au.
Applying Stafford Beer’s heuristic, ‘the purpose of a system is what it does’ (POSIWID)
SCADA stands for Supervisory Control and Data Acquisition. It is a mix of computer software and hardware tools used to watch, run, and collect data from machines and industrial processes from far away or a central control room



