12 Scale threat blocking capabilities to stop cyber attacks The problem we face Threat intelligence sharing is essential to building a stronger threat picture, but it is only the first step. In order to effectively block threats at scale before they reach end users, threat intelligence must be put into action. Australia’s current approach to threat blocking is multifaceted, incorporating a mixture of technical capabilities, regulatory functions, and baseline mitigation strategies implemented by both government bodies and industry. Telecommunications and internet service providers (ISPs) have adopted a wide range of approaches to threat blocking. These entities need better access to high-confidence threat information to help them adopt comprehensive measures to block malicious cyber activity. As threat actors become more sophisticated, it is essential for industry and government to share actionable, timely and contextualised threat intelligence to facilitate effective threat blocking capabilities. How the Government will take action The Australian Government is already building our national capability to block scams and harmful content through the launch of the National Anti-Scam Centre, as well as defining industry codes that specify responsibilities of the private sector in relation to scam activity. We have also made regulatory amendments to help telecommunications providers take proactive action to block threats. To further enhance our national threat blocking capabilities, the Australian Government will support and promote threat blocking across industry. Under this initiative, the Government will: 1. Develop next-generation threat blocking capabilities Building on existing work led by the National Anti-Scam Centre, the Government will support telecommunications and ISPs to block threats at scale. We have established a National Cyber Intel Partnership to develop cutting-edge threat blocking capabilities. Comprised of industry leaders and cyber experts from academia and civil society, the Steering Group is piloting the development of an automated, near-real-time threat blocking capability. These capabilities will build on, and integrate with, existing government and industry platforms. The Steering Group will inform the deployment of further threat blocking capabilities that can prevent identified threats from reaching end users. As we build our threat intelligence sharing capabilities, we will develop more effective threat blocking technologies that work at machine speed and leverage machine learning algorithms to actively respond to the changing threat environment. 2. Expand the reach of threat blocking capabilities Drawing on the work of the Steering Group, the Government will also seek to encourage and incentivise threat blocking across the economy by those most capable of doing so – including telecommunication providers and ISPs. 2023–2030 Australian Cyber Security Strategy 37

Select target paragraph3