Critical Infrastructure: Control, Continuity and FOCI

Critical Infrastructure

Gadget Cyber News Weekly
Critical Infrastructure: Control, Continuity and FOCI

Week ending 12 July 2026  |  Five minute CISO briefing

Figure 1. This week’s signal: control, continuity and trust are now geopolitical assets.

The one line read:  In geopolitics, control is a cyber objective. Data still matters, but the ability to interrupt, route, observe, influence or quietly sit inside critical infrastructure may matter more.

This edition focuses on geopolitical cyber risk affecting telcos, banks, utilities, cloud, suppliers and critical digital infrastructure across Australia, Europe, the United States and Asia. The cheerful news is that the themes are becoming clearer. The less cheerful news is that the themes are control, continuity and strategic leverage.

The signal this week

The story is not a single dramatic cyber strike. It is the accumulation of signals pointing in the same direction. Geopolitical tension is turning critical infrastructure into strategic terrain. Telcos carry the nervous system. Banks move trust. Utilities keep the lights, water and heat behaving like civilisation. Cloud and managed services quietly hold the keys.

For CISOs, the uncomfortable lesson is that the target is not always data. The target can be authority. It can be routing. It can be timing. It can be the ability to degrade a service when politics makes disruption useful. Nobody needs a movie villain when a forgotten edge device and a sleepy service account will do.

Figure 2. Actor intent map: who is targeting whom, and why control matters.

Who is targeting whom, and why?

The simplest useful question is not “what malware did they use?” It is “what would this actor want to control?” PRC linked actors have been associated by western agencies with router compromise, telco visibility, managed services exposure and long duration access. Russia linked actors and aligned hacktivists keep pressure on NATO support, logistics, utilities and symbolic public services. Iran linked activity remains tightly connected to regional conflict and exposed operational technology. North Korea linked activity keeps blending espionage with revenue generation.

That does not mean every incident is a nation state incident. It means the same pathways are attractive to both strategic actors and criminals. A router is still a router. A supplier admin account is still delicious. A misconfigured OT gateway is still a bad idea with blinking lights.

Actor lensWhere control is usefulCISO translation
PRC linked actorsTelcos, routers, cloud, managed services, government and transport.Ask where long term access could become leverage during a strategic crisis.
Russia linked actorsLogistics, NATO support, utilities, technology suppliers and public services.Do not confuse crude techniques with low consequence. A simple SCADA mistake can still become the headline.
Iran linked actorsWater, energy, banks, healthcare, manufacturing and symbolic targets.Expect retaliation shaped activity when regional tension rises. Internet exposed OT is not a strategy.
North Korea linked actorsBanks, crypto, software supply chains and identity rich services.Follow the revenue trail and the access trail. They often travel together.
FOCI exposureCloud providers, data centres, MSPs, telco suppliers and outsourced support.Procurement is now part of the control plane. Visibility, contractual rights and offboarding matter.
CISO translation:  Ask what the actor could control before asking what data the actor could steal.

Critical infrastructure is now a dependency graph

Critical infrastructure used to sound like a list of sectors. Now it behaves more like a dependency graph. A bank depends on telco routing, cloud identity, payment rails, DNS, data centres, software suppliers, managed detection, legal communications and customer trust. A utility depends on OT, engineering workstations, remote access, vendor maintenance and the operational confidence of people who may not have chosen a career in cyber security but are suddenly chairing the incident bridge.

This is why FOCI matters. Foreign ownership, control or influence is not simply a procurement acronym. It is a practical question about who can influence the systems that keep services running, who sees the logs, who can push an update, who can delay disclosure, and who can prevent clean recovery. The supplier that looks peripheral on a spend report may sit right in the middle of the blast radius.

Figure 3. A control plane intrusion path for critical infrastructure, telcos, banks and utilities.

What happened in the last week

SecurityWeek reported that Japanese telecommunications provider KDDI confirmed more than 12 million people were affected by a June breach tied to a zero day vulnerability in a third party system supporting email infrastructure for several ISPs. The board level lesson is not simply “patch the third party system”. It is that telecommunications exposure can move through a vendor system and still land as a trust event for millions of users.

CISA’s advisory stream continues to show why edge devices, public facing software and legacy control paths need attention. The defensive work is not glamorous. It is exposure management, logging, segmentation, privileged access discipline and the brave act of asking whether that ancient appliance in the rack is actually still doing anything useful. Sometimes it is doing one useful thing and three terrifying things.

The Five Eyes cyber security agencies also used their June 2026 statement on AI to warn leaders that AI is transforming cyber risk. For critical infrastructure, the most immediate AI risk may be faster exploit discovery, better lures, accelerated reconnaissance and more convincing operational impersonation. In other words, the adversary gets a better intern. Unfortunately, the intern never sleeps.

Australia FY2024-25 in review

ASD’s ACSC described Australia as an attractive target for criminal and state sponsored actors because of its dependency on digital and internet connected technology. In FY2024-25, ASD’s ACSC received more than 42,500 hotline calls, responded to more than 1,200 cyber security incidents and notified entities more than 1,700 times about potentially malicious cyber activity.

Critical infrastructure stood out. ASD’s ACSC notified critical infrastructure entities of potential malicious cyber activity more than 190 times, up 111 percent, and CI made up 13 percent of all incidents. The report’s strategic message is plain: critical infrastructure is attractive because it supports national resilience, sovereignty and prosperity.

Figure 4. Australia FY2024-25 cyber resilience review, focused on operational resilience and critical infrastructure.

The new resilience frame is visible in CI Fortify, which asks operators to think about isolating vital OT and enabling systems for three months and completely rebuilding vital OT and enabling systems. That is a very different conversation from “we have a backup”. It is also a better one. Backups are comforting. Rebuild capability is evidence.

What to watch next financial year

The next Australian financial year will be shaped by the convergence of geopolitics, cybercrime and infrastructure resilience. The World Economic Forum’s Global Cybersecurity Outlook 2026 found that geopolitics remains a defining feature of cyber risk, with many organisations accounting for geopolitically motivated cyberattacks such as disruption of critical infrastructure and espionage. This is not IT risk wearing a nicer suit. It is operating risk with a router and a passport.

Expect six themes to keep coming back. AI will accelerate exposure discovery and more convincing operational lures. Proxy and operational relay box networks will let actors hide behind ordinary routers and traffic. FOCI scrutiny will become a real cyber control rather than a procurement afterthought. Critical infrastructure continuity tests will become more concrete. Bank systemic risk will face more pressure from AI enabled identity and payment attacks. Finally, blended disruption will become normal as DDoS, extortion, wipers, leaks and influence campaigns arrive together like the world’s least helpful group project.

Figure 5. FY2026-27 threat outlook: the next financial year of geopolitical and infrastructure cyber risk.

The CISO move

Start with the workflows an adversary would want to control. For a telco, that means routing, identity, lawful access systems, service management and supplier access. For a bank, it means payments, identity, settlement, fraud operations and customer trust. For a utility, it means OT visibility, engineering changes, remote access, manual operation and public safety. For cloud and managed services, it means tenant administration, log visibility, customer support and update authority.

Then test the boring bits. Can you remove a supplier’s privileged access quickly? Can you rebuild critical identity services from clean authority? Can you run a vital service if your telco, cloud or MSP is compromised? Can your board explain the difference between data loss and loss of operational control without needing a whiteboard, three coffees and a small act of mercy?

Board translation:  Build resilience around the workflows adversaries would want to control, not just the systems they might breach.
Board questionBetter answerEvidence to show
Could an actor interrupt a critical service?Answer by workflow, not by server. Name the five services that must continue.Continuity map, manual fallback, telco/cloud dependencies and tested crisis roles.
Could a supplier become the bridge?Assume yes. Show how blast radius is constrained and access can be revoked quickly.Supplier access register, privileged logs, FOCI review and incident notification clauses.
Could we rebuild if trust is lost?Backups are not the same as clean recovery. Prove clean authority can be restored.Gold images, isolated recovery, identity rebuild runbooks and rehearsal results.
Could we spot pre-positioning?Look for control plane change: router configs, dormant accounts, new admin paths and unexplained traffic.Centralised logs, edge telemetry, baselines, DNS monitoring and threat hunts.

References

Arghire, I. (2026, July 9). 12 million impacted by data breach at Japanese telco KDDI. SecurityWeek. https://www.securityweek.com/12-million-impacted-by-data-breach-at-japanese-telco-kddi/

Australian Signals Directorate Australian Cyber Security Centre. (2025). Annual cyber threat report 2024-2025. https://www.cyber.gov.au/about-us/view-all-content/reports-and-statistics/annual-cyber-threat-report-2024-2025

Australian Signals Directorate Australian Cyber Security Centre. (2026, June 22). Five Eyes cyber security agencies statement: The AI shift in cyber risk, why leaders must act now. https://www.cyber.gov.au/about-us/view-all-content/news/five-eyes-cyber-security-agencies-statement

Cybersecurity and Infrastructure Security Agency. (2024, December 4). Enhanced visibility and hardening guidance for communications infrastructure. https://www.cisa.gov/resources-tools/resources/enhanced-visibility-and-hardening-guidance-communications-infrastructure

Cybersecurity and Infrastructure Security Agency. (2025, December 18). Pro-Russia hacktivists conduct opportunistic attacks against US and global critical infrastructure. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-343a

Cybersecurity and Infrastructure Security Agency. (2026, April 7). Iranian-affiliated cyber actors exploit programmable logic controllers. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a

Cybersecurity and Infrastructure Security Agency. (2026, April 23). Defending against China-nexus covert networks of compromised devices. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-113a

Cybersecurity and Infrastructure Security Agency. (2025, September 3). Countering Chinese state-sponsored actors compromise of networks worldwide. https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-239a

The Hacker News. (2026, June 18). ThreatsDay bulletin: Claude chat abuse, NastyC2 npm, SD-WAN flaws, scams, and supply chain threats. https://thehackernews.com/2026/06/threatsday-bulletin-claude-chat-abuse.html

World Economic Forum. (2026). Global cybersecurity outlook 2026. https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2026.pdf

Visual assets: original light-background premium graphics generated for Gadget Cyber News Weekly and embedded for editorial use.