News

Supply chain cybersecurity challenges highlighted

Written by Emma Chu | Sep 22, 2026, 4:00:00 AM

INDUSTRY needs to be proactive in ensuring interconnected supply chains do not fall prey to cybersecurity threats.

This was a key message from the Defending Digital: Cybersecurity in the Supply Chain panel at MegaTrans 2026 in Melbourne, a conference dedicated to the logistics and supply chain sector.

With the rapid acceleration of digital technology, the sector's operational resilience is increasingly linked with digital security.

The panel on Defending Digital: Cybersecurity in the Supply Chain, brought together key voices from government, academia and the law, including Anthony M from the Australian Signals Directorate (ASD); professor of logistics and supply chain at RMIT Vinh Thai, and partner at law firm HFW Owen Webb.

Scale is no shield

The session began with a panel opened with a stark reminder that cyber threats do not discriminate by company size. While high-profile incidents, such as the late 2023 cyber-attack on DP World, captured national headlines, recent months have seen a surge in targeted attacks against small and medium-size operators.

Notable examples include Alliance Distribution Services (a subsidiary of publishing giant Hachette) and an incident at CEVA Logistics in Europe. The CEVA breach was seen as critical as it involved the theft of employees' personal data, triggering a class action lawsuit by employees.

Furthermore, highlighting the catastrophic compounding effects of a single point of failure, the panel pointed to the 2022 Medibank breach, where a single compromised password led to the leakage and extortion of data belonging to 10 million people, leading to legal scrutiny and class actions.

The AI arms race

AI has fundamentally reshaped the threat landscape. Pointing to the commercial reality, Owen Webb cited global IBM reports indicating that AI-driven attacks have already surged by 56%. Building on this from a national intelligence perspective, Anthony M (ASD) said state-sponsored actors were increasingly engaging in "pre-positioning", stealthily infiltrating corporate systems and lying dormant. They wait for strategic moments, such as geopolitical conflicts, to trigger disruptions across critical national infrastructure like shipping, container terminals, and automated warehouses as defined in the Security of Critical Infrastructure Act 2018 (SOCI Act).

While cybercriminals leverage AI to lower barriers and rapidly craft sophisticated phishing scams or deepfake identities, commercial and government defence systems are also racing to adopt AI countermeasures. Commercial defence systems often lag behind aggressive AI-driven attack vectors, heightening the vulnerability.

Legal liabilities and board-level governance

Cybersecurity is no longer merely an IT hurdle; it has escalated into a core governance and legal risk. Cybersecurity is now a board-level responsibility, and from a legal perspective, company directors face potential personal liability if they fail to take reasonable steps to mitigate foreseeable cyber risks.

Panellists noted that data exfiltration often succeeds not just because intruders breach the perimeter, but due to internal failures to encrypt sensitive employee and customer data, leaving no secondary layer of protection. Additionally, commercial contracts must explicitly allocate cyber risk responsibilities, especially regarding rising invoice fraud - where hackers intercept emails to redirect payments to fraudulent accounts. To counter this, major corporations are reverting to old-school safety measures, refusing to alter banking details unless verified through in-person, face-to-face meetings backed by authorised personal identification.

Key strategies: Getting back to basics

The panel offered concrete, actionable steps for businesses in supply chains. Professor Vinh Thai (RMIT) outlined three core pillars for businesses to fortify their operations.

First, cybersecurity must not be treated merely as an IT problem, but rather as a critical component of overall business continuity and operational resilience. Second, companies must "get the basics right the first time, every time," emphasising fundamental basics like robust credentials, system patching, and adherence to frameworks like Australia's Essential Eight (cybersecurity maturity model). Third, due to digital interconnectedness, businesses must treat their supply chain partners' cybersecurity as their own - because a digital failure in one minor node can halt the entire physical supply chain.

Building on these foundational strategies, Anthony M said the ASD urges industry leaders to utilise free guidance available via cyber.gov.au.

Addressing fears of regulatory punishment, he clarified that under the Cyber Security Act, the ASD is bound by limited use obligations, meaning businesses could, and should, reach out for help via the national cyber security hotline (1300 CYBER ONE), without fear of public exposure.