Threats

A tale of two threats: balancing nation state and insider risks

August 19, 2026
14 min read

Key Insights:

  • Recent events in Australia and New Zealand demonstrate how critical infrastructure organisations face attacks from a broad spectrum of threat actors
  • New Zealand Security Intelligence Service have published their fourth threat environment report in 2026
  • "NZ's national security challenges have intensified over the past year"
  • On espionage, "The People’s Republic of China (PRC) is the only country we have detected doing it at scale"
  • In Australia, the security breach at Origin Energy is linked to an offshore employee
  • Outsourcer "intended to extort the company for money" for the return of 900,000 customer records

CNI operators under attack

"A 'coordinated cyberattack' targeted more than 30 ‌community water systems in the U.S. state of Minnesota on July 26 and July 27,"

Recent news reports have highlighted targeted attacks against US critical infrastructure operators in the water sector as the US government has raced to ramp up guidance for the sector.

Overcyte has previously covered the challenges the sector faces to protect internet facing systems, with attacks in Canada rising by 20% year on year.

Iran is being blamed for the recent spate of attacks as the conflict in the Middle East continues to escalate with media attention acting as a reminder that all OT operators should ensure their systems are adequately protected from cyber threats.

CISA has urged Water and Wastewater operators to protect OT against activity targeting PLCs with new guidance created to reduce cyber threats to the most critical systems.

And Jen Easterly, former director of CISA has estimated that the US must now "commit at least $3 billion in new multiyear funding... dedicated to replacing aging controls in water facilities and strengthening their ability to operate safely when digital systems fail."

Can you trust your trading partners?

There are several states that conduct espionage against New Zealand, but the People’s Republic of China (PRC) is the only country we have detected doing it at scale.
New Zealand Security Intelligence Service

Closer to Overcyte's home in NZ, the Security Intelligence Service have published their fourth threat environment assessment and picked China - not Iran - as the primary concern for the region.

It's the first time the country has identified China as a growing threat to critical assets with scenarios documented including a Communist Party-affiliated research institution called the Purple Mountain Observatory attempting to install Ground Based Space Infrastructure in New Zealand.

The US has previously warned about Volt Typhoon cyber operations as part of a larger effort to infiltrate western critical infrastructure, including naval ports, internet service providers, communications services and utilities.

You can read the full New Zealand's Security Threat Environment 2026 online the SIS website.

Can you trust your (outsourced) employees?

Meanwhile in Australia, The Australian Financial Review reports that an investigation into a recent security breach at Origin Energy that saw the disclosure of data connected to approximately 900,000 customers was likely not a hack, but a rogue insider.

Attention is said to be focusing on a former employee working for a third party provider in Manila, where the Aussie electricity and gas company had outsourced billing and customer support functions.

The individual was said to have downloaded customer data before seeking payment for its safe return.

The AFR says the Australian Cyber Security Centre is not involved with the incident investigation because it's been deemed an employee - not cyber - issue.

Remove the humans, remove the risk?

Coverage of this latest security incident is a reminder that attacks can come from many varied adversaries, both external and internal.

And to reflect the ever growing popularity of AI as a possible corporate silver bullet, we leave you with this fine quote:

“This is one of the key sales points for automation and AI in this kind of work because it removes the human element of greed. You can’t offer a bribe to a bot, so there is less chance of corruption.”
Mohit Sharma

If you can't trust your largest trading partner, and you can't trust your employees, maybe automation and AI is the solution to cyber security threats after all?

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo