12
Scale threat blocking capabilities
to stop cyber attacks
The problem we face
Threat intelligence sharing is essential to building a stronger threat picture, but it is only the first
step. In order to effectively block threats at scale before they reach end users, threat intelligence
must be put into action.
Australia’s current approach to threat blocking is multifaceted, incorporating a mixture of
technical capabilities, regulatory functions, and baseline mitigation strategies implemented by
both government bodies and industry. Telecommunications and internet service providers (ISPs)
have adopted a wide range of approaches to threat blocking. These entities need better access
to high-confidence threat information to help them adopt comprehensive measures to block
malicious cyber activity.
As threat actors become more sophisticated, it is essential for industry and government to
share actionable, timely and contextualised threat intelligence to facilitate effective threat
blocking capabilities.
How the Government will take action
The Australian Government is already building our national capability to block scams and harmful
content through the launch of the National Anti-Scam Centre, as well as defining industry codes
that specify responsibilities of the private sector in relation to scam activity. We have also made
regulatory amendments to help telecommunications providers take proactive action to block
threats. To further enhance our national threat blocking capabilities, the Australian Government
will support and promote threat blocking across industry.
Under this initiative, the Government will:
1. Develop next-generation threat blocking capabilities
Building on existing work led by the National Anti-Scam Centre, the Government will support
telecommunications and ISPs to block threats at scale. We have established a National Cyber
Intel Partnership to develop cutting-edge threat blocking capabilities. Comprised of industry
leaders and cyber experts from academia and civil society, the Steering Group is piloting the
development of an automated, near-real-time threat blocking capability. These capabilities will
build on, and integrate with, existing government and industry platforms. The Steering Group will
inform the deployment of further threat blocking capabilities that can prevent identified threats
from reaching end users.
As we build our threat intelligence sharing capabilities, we will develop more effective threat
blocking technologies that work at machine speed and leverage machine learning algorithms to
actively respond to the changing threat environment.
2. Expand the reach of threat blocking capabilities
Drawing on the work of the Steering Group, the Government will also seek to encourage
and incentivise threat blocking across the economy by those most capable of doing so –
including telecommunication providers and ISPs.
2023–2030 Australian Cyber Security Strategy
37