For many organisations, cyber crisis exercises still begin with a familiar scenario: a ransomware gang encrypts systems, demands payment, threatens data release, and operations are disrupted. These scenarios remain important. Ransomware continues to be one of the most visible and costly cyber threats facing Australian and New Zealand organisations.
However, for operators of critical infrastructure, the threat landscape has evolved.
As geopolitical competition intensifies across the Indo-Pacific, governments, intelligence agencies and cybersecurity leaders are increasingly warning that state-sponsored cyber actors are targeting critical infrastructure not simply for financial gain, but for strategic advantage, intelligence collection, coercion, and preparation for potential future conflict.
This raises an important question for boards, executives and crisis management teams:
Are your cyber crisis exercises preparing your organisation for the right adversary?
Why Critical Infrastructure Matters in Australia and New Zealand
Critical infrastructure operators in Australia and New Zealand are increasingly operating in an environment shaped by strategic competition in the Indo-Pacific. Government leaders continue to emphasise the challenges posed by increasing geopolitical competition, strategic contest and coercive behaviour in the region. Australia’s Foreign Minister, Penny Wong has recently described the Indo-Pacific as facing “accelerating contest” and a deteriorating strategic environment.
Cyber operations are now routinely used by nation states to:
- Collect intelligence
- Establish strategic access
- Influence decision-making
- Prepare the battlefield for potential future crises
Public reporting continues to demonstrate that sophisticated state-sponsored actors are actively targeting critical infrastructure globally, including energy, water, telecommunications, transportation and industrial organisations.
Cyber operations are rarely isolated events. Recent conflicts have further demonstrated that they are increasingly integrated with broader military, intelligence, economic and information operations. The distinction between peacetime competition and conflict is becoming increasingly blurred.
Cyber resilience can no longer be viewed solely through the lens of ransomware. For boards and executive teams, organisations responsible for essential services must also consider how they would respond to a sophisticated state-sponsored intrusion designed to achieve strategic rather than financial objectives.
The Problem with Ransomware-Only Exercises
Traditional ransomware tabletop exercises typically focus on questions such as:
- Do we pay the ransom?
- How do we communicate with customers?
- What systems need to be restored first?
- How long can we operate manually?
- What are our regulatory notification obligations?
These are important decisions. However, they generally assume that the threat actor’s primary objective is financial gain.
State-sponsored adversaries operate differently. Their objectives may include:
- Intelligence gathering
- Strategic positioning
- Disruption of critical services
- Undermining public confidence
- Supporting broader geopolitical objectives
- Preparing access for future conflict or coercion
In many cases, the compromise may have existed for months or years before being detected.
The key challenge is no longer simply recovering from an attack. It is understanding what the adversary is trying to achieve and how your response may have broader national security implications.
When the Adversary Is a Nation State
Recent public reporting has highlighted how state-linked groups have targeted critical infrastructure operators globally, including energy, water, telecommunications, transportation and industrial organisations.
Unlike ransomware operators, state-sponsored actors often prioritise three things:
- Persistence over speed
- Intelligence over extortion
- Strategic effects over immediate financial gain
Persistence over Speed
Rather than announcing their presence through encryption, they seek to remain undetected.
Their goal may be to establish long-term access to operational technology (OT), industrial control systems (ICS), telecommunications infrastructure, or key corporate networks.
Intelligence over Extortion
The objective may be to understand:
- Operational dependencies
- Safety systems
- Emergency procedures
- Network architecture
- Supply chain relationships
- Crisis management capabilities
This intelligence can provide significant strategic value during periods of heightened geopolitical tension.
Strategic Effects over Immediate Financial Gain
A nation-state actor may not seek to destroy systems today. Instead, they may seek to maintain access that could be leveraged during a future crisis.
This fundamentally changes the nature of executive decision-making.
How State-Nexus APT Exercises Differ
A mature critical infrastructure exercise should force executives to grapple with issues that are rarely considered in ransomware simulations.
1. Attribution Uncertainty
The first challenge is determining who is behind the attack.
The evidence may be incomplete. Government agencies may provide classified or limited intelligence. Technical indicators may point towards a nation-state but stop short of definitive attribution. Executives must make decisions without certainty.
Questions include:
- What can we say publicly?
- When should government agencies be engaged?
- How much information should be shared with industry partners?
- What are the consequences of incorrectly attributing an attack?
2. Operational Safety Decisions
For critical infrastructure operators, the primary concern may not be data loss. It may be safety.
An exercise should test decisions such as:
- Do we continue operations?
- Do we isolate industrial control systems?
- Do we shut down facilities as a precaution?
- How do we balance safety, service continuity and economic impact?
These decisions are significantly more complex than restoring encrypted servers.
3. Government Coordination
State-sponsored attacks often trigger extensive engagement with government agencies.
Crisis teams may need to coordinate with:
- National cyber authorities
- Intelligence agencies
- Regulators
- Law enforcement
- Defence-related stakeholders
This introduces additional complexity around information sharing, communications, and operational decision-making.
4. Escalating Geopolitical Context
A sophisticated exercise should include external developments. Examples include:
- Rising regional tensions
- Military activity
- Diplomatic disputes
- Trade restrictions
- Coordinated influence campaigns
- Disinformation targeting the organisation
The cyber incident becomes part of a broader strategic picture rather than an isolated technical event.
5. Public Confidence and National Resilience
For critical infrastructure operators, maintaining public confidence can be as important as restoring systems. The consequences of a prolonged outage can extend far beyond the organisation itself.
What We Have Seen in Cyber Crisis Practice
Recently, CyBiz, working alongside Sygnia, facilitated a cyber crisis exercise for a critical infrastructure organisation based on a sophisticated state-sponsored APT scenario.
The exercise was intentionally designed to move beyond the traditional ransomware playbook. Rather than confronting participants with encrypted systems and ransom demands, the scenario centred on a long-term compromise of critical operational systems by a highly capable adversary seeking strategic advantage.
How Executive Discussions Shifted Away from Ransomware
What was striking was how quickly the discussion moved away from the topics that typically dominate ransomware exercises. There was no discussion about backups, ransom negotiations, or cyber insurance.
Instead, executives found themselves grappling with a very different set of questions:
- How confident are we that the threat actor has been fully removed?
- What operational risks are acceptable while investigations continue?
- At what point do we involve government agencies and intelligence partners?
- How do we communicate with customers and stakeholders when attribution remains uncertain?
- What if the adversary’s objective is not immediate disruption, but positioning for future action?
- How should we respond if broader geopolitical tensions continue to escalate?
- What are our obligations if this incident is assessed as having national security implications?
Why Recovery Was Not the Hardest Challenge
The “ah-ha” moments were equally revealing. Participants recognised that many of their existing cyber crisis plans had been built around criminal actors seeking financial gain. While those plans remained valuable, they did not fully address the strategic, operational and geopolitical dimensions of a state-sponsored intrusion.
The exercise highlighted that recovery may not be the most difficult challenge. Significantly more complex were:
- Understanding the adversary’s intent
- Assessing ongoing risk
- Maintaining confidence in critical operations
- Coordinating with government stakeholders
For many participants, the exercise reframed cyber resilience as more than a technology issue. It became a discussion about operational continuity, public confidence, national resilience, and leadership under uncertainty.
That shift in perspective is precisely why critical infrastructure organisations should be exercising against state-sponsored threat scenarios alongside more traditional ransomware events.
Preparing for the Cyber Threats That Matter Most
Ransomware remains a critical threat and should continue to be exercised. But for critical infrastructure operators, ransomware should no longer be the only scenario being tested.
The organisations that will be most resilient during the next decade will be those that prepare not only for criminal actors seeking profit, but also for sophisticated adversaries pursuing strategic objectives.
As geopolitical competition intensifies across the Indo-Pacific, the question is no longer whether critical infrastructure will be caught in the middle of cyber-enabled strategic competition. The question is whether executive teams have practised making the decisions that such an event would require.
Ready to Test Your Organisation Against a Different Adversary?
Many organisations have exercised ransomware scenarios multiple times. Far fewer have tested how their executives, crisis management teams, operational leaders and boards would respond to a sophisticated state-sponsored intrusion affecting critical services. The decisions are different. The stakeholders are different. The consequences can be different.
CyBiz, in partnership with Sygnia, designs and facilitates advanced cyber crisis exercises that incorporate real-world nation-state tradecraft, geopolitical escalation, operational technology impacts, intelligence-driven decision making, and critical infrastructure considerations.
Whether the scenario involves a compromised control room, manipulation of safety systems, strategic espionage, influence operations, or preparation for future disruption, the objective is the same: helping leaders make better decisions under pressure.
If your organisation operates critical infrastructure or delivers essential services, now is the time to ask whether your next tabletop exercise should test more than ransomware.
Contact CyBiz to discuss how a tailored state-sponsored APT cyber crisis exercise can help strengthen organisational resilience and prepare your leadership team for the evolving threat landscape.
When did your Board or Executive Team last exercise a nation-state cyber scenario? CyBiz, working with Sygnia, develops and facilitates executive cyber crisis tabletops based on realistic state-nexus APT scenarios for critical infrastructure organisations.
Talk to us about running an APT-focused executive tabletop.

Posted in Blog, Risk Assessment and Penetration Testing
