The Insider Threat: Critical Infrastructure's Overlooked Vulnerability
Containing cyber threats in critical infrastructure assets has tended to focus on having the right tools, but Australia’s authorities increasingly want more attention paid to the people who have access to vital functions and data.
The emergence of advanced AI cyber tools has raised concerns among governments, regulators and security specialists about the resilience of critical sectors. In particular, there is growing unease that the pace of threats is evolving faster than organisations can adapt. In some cases, models have not been publicly released because of concerns that those capabilities could be abused by bad actors (see our recent article on Anthropic Mythos).
Regulators in Australia, the US, the UK and Canada are already engaging with financial institutions and other critical sectors about how they intend to maintain operational resilience as AI-driven threats accelerate.
But while the debate around AI-enabled cyber risk often focuses on technical controls and network defence, there is another vulnerability that many organisations continue to underestimate: their people.
The challenge for the C-suite is not necessarily to eliminate all risk, but to build governance, preparedness and operational resilience frameworks capable of responding when incidents occur. For critical infrastructure organisations, that starts with recognising that personnel risk is no longer a narrow HR issue - it is a question of organisational resilience.
One of the most significant shifts under Australia’s Security of Critical Infrastructure Act 2018 (SOCI Act) and associated Critical Infrastructure Risk Management Program (CIRMP) obligations is the focus on “critical workers” - individuals whose actions or access could significantly affect the resilience of essential infrastructure. Importantly, this term extends beyond traditional employees to include contingent workers and contractors in critical roles. Organisations are therefore required to apply the same screening rigour across their entire workforce, whether permanent or temporary.
Despite this, many organisations still approach recruitment screening through the lens of conventional criminal background checks. Under the enhanced CIRMP rules, however, this will no longer satisfy regulatory expectations. Entities responsible for certain categories of critical infrastructure assets will be required to use the Australian Government's AusCheck framework for screening critical workers – or, alternatively, to permit access where a critical worker holds a relevant security clearance (at Negative Vetting 1 level or higher) issued by an authorised Australian Government entity. It is worth noting that these enhanced obligations do not yet apply universally across all critical infrastructure asset types. At present, these enhanced obligations are directed at a defined subset of higher-risk assets, which are water, energy, broadcasting, domain name systems and freight infrastructure and services assets.
The AusCheck framework uses a more comprehensive model for screening individuals seeking sensitive roles. This includes identity verification, criminal history and national security assessments and right-to-work verifications. However, many organisations continue to avoid AusCheck due to the cost implications. That reluctance now faces a double challenge as AusCheck fees are continuing to rise and the enhanced CIRMP rules are set to make either an AusCheck background check or the holding of a relevant security clearance (NV1 minimum) mandatory for critical workers requiring access to critical components.
Offshore critical workers also present a unique challenge, as they may not be eligible for screening through AusCheck or for holding a relevant security clearance. Organisations with offshore personnel in critical roles will need to address this gap within their CIRMP, including by identifying and implementing alternative screening and risk mitigation measures appropriate to those individuals.
For organisations already in growth phases or actively onboarding new personnel, this combination of rising costs and a regulatory mandate requires particular consideration of screening budgets, recruitment timelines and workforce processes. Importantly, for critical workers requiring ongoing access to critical components, the AusCheck background check will need to be conducted at least every five years and for NV1, at least every ten years. This means organisations will need to build ongoing review cycles into their employment and contracting arrangements. Organisations should also consider imposing positive obligations on critical workers to notify relevant personnel if their circumstances change in a way that may affect their suitability for the role, providing an additional layer of assurance between formal re-screening intervals.
Under the baseline CIRMP framework, organisations are not legally required to use AusCheck directly, with many opting for private background check agencies instead. The problem is that standard commercial screening often misses the very risks that regulators and security agencies increasingly warn about. These include whether an individual has failed a security clearance review, been subject to national security attention, been investigated for organised crime links, or faced disciplinary action within defence or intelligence establishments – matters that may not appear under civilian criminal law.
This issue is particularly important as critical infrastructure operators often seek to hire former defence and intelligence agency personnel for their extensive experience of cyber threats and to carry out operational and security functions.
One of the issues is that military disciplinary systems operate differently from civilian equivalents. Serious misconduct, imprisonment or discharge under defence legislation may not automatically appear in ordinary corporate background checks.
Unless organisations ask the right questions, and use providers capable of obtaining the relevant information, important information could be missed.
It is important not to overlook these additional checks. When a major incident occurs, regulators will inevitably ask whether the organisation took reasonable steps to assess insider risk, particularly where employees or contractors had access to sensitive systems and data. Governance failures in this area could result in regulatory action, reputational damage and, in serious cases, personal liability for directors.
Critical infrastructure organisations therefore need to integrate legal, risk and operational considerations into their screening processes. Conducting only one of these elements in isolation leaves critical governance gaps.
To manage these changes effectively, organisations should integrate AusCheck screening into existing onboarding processes. In practice, this means building screening lead times into recruitment timelines, evaluating roles by criticality to determine where AusCheck is mandatory versus where enhanced commercial screening may suffice in the interim, and engaging legal advisors early to draft contract terms that clearly allocate screening obligations. Taking these steps early will help minimise both cost and disruption as the new requirements take effect.
Another growing challenge is that many organisations still define insider risk too narrowly. Critical worker regimes often focus on employees with direct physical access to operational infrastructure. But in practice, the risk landscape extends well beyond those roles.
Senior executives, legal teams, governance functions, payroll personnel, cyber security leaders and risk officers may all hold privileged access to highly sensitive information, systems or operational decision-making processes. In some cases, their authority and visibility across the organisation may create risks equivalent to those posed by operational personnel. This is even more pertinent as organisations digitise more operational functions and centralise access to sensitive systems.
The lesson from mature defence and intelligence environments is that resilience depends on applying disciplined access management principles across the organisation. “Need to know”, “need to hold” and privileged-access controls are also governance issues rather than purely technical controls.
The challenge for Boards is that governance failures are often far less visible than technical vulnerabilities - until an incident occurs late on a Friday night.
As AI-driven threats accelerate, organisations must recognise that they cannot realistically recover every vulnerability immediately. Decisions around addressing vulnerabilities need to become increasingly risk-based and supported by vigorous governance frameworks.
That governance also needs to extend into procurement and supply chain management. Third and fourth-party vendors often hold access to systems, operational environments and sensitive data that may be critical to resilience. Contractual protections alone will not satisfy regulators if a major compromise occurs.
A question that arises is how an organisation can require an employee identified as a critical worker to undergo these checks.
The simplest solution is to ensure a critical worker's employment contract requires satisfaction of screening requirements as part of the pre-employment checks as well as an obligation to undergo periodic re-screening as required by the organisation. This will resolve the issue for new employees and any current employees who are re-issued employment contracts.
If existing employees do not have screening obligations in their employment contracts, then organisations may need to issue a lawful and reasonable direction for them to undergo screening. If an employee refuses to comply, that becomes a separate issue, to be managed on its own facts.
Organisations should also ensure position descriptions are updated to identify whether a role is critical for the purposes of the SOCI Act. This will be useful in establishing whether compliance with the screening requirements under the SOCI Act forms part of the inherent requirements of their role.
If an adverse screening result is received, organisations should be mindful of their obligations under employment and anti-discrimination legislation when managing an employee's employment.
For many organisations, enhanced SOCI and CIRMP requirements are still treated as compliance milestones. In reality, they are better understood as indicators of where regulatory expectations are heading.
The Protected Security Policy Framework (PSPF), used across Australian government agencies, offers one example of the level of rigour increasingly expected around personnel security, physical security and governance.
The framework extends into areas such as facility security planning, access governance and operational resilience. Many private-sector organisations remain unfamiliar with that depth of discipline because historically they have not operated in heavily regulated national security environments. That is changing.
The broader lesson from defence and intelligence sectors is not that private companies are resilient, it is that resilience requires continual reassessment, long-term planning and a recognition that security is not a “set and forget” exercise.
Technology will continue to evolve rapidly. AI-enabled offensive capabilities will continue to lower the cost, speed and sophistication of cyber-attacks. The organisations best positioned to manage that environment will be those capable of building disciplined governance, stronger personnel screening, integrated legal-risk oversight and mature preparedness frameworks before a major incident occurs.
Authors: Clare Doneley, Partner; Rachael Falk, Partner; Tamara Lutvey, Partner; Amanda Wu, Senior Associate; Sanjam Bajwa, Lawyer and Molly Fitzgerald, Lawyer.
This publication is a joint publication from Ashurst Perkins Coie Australia and Ashurst Perkins Coie Risk Advisory Pty Ltd, which are part of the Ashurst Perkins Coie Group.
Ashurst Perkins Coie Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.
Ashurst Perkins Coie Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.
The Ashurst Perkins Coie Group comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.
The services provided by Ashurst Perkins Coie Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by qualified legal practitioners acting in that capacity. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services.
This material is current as at 6 August 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.