For many organisations, cyber crisis exercises still begin with a familiar scenario: a ransomware gang encrypts systems, demands payment, threatens data release, and operations are disrupted. These scenarios remain important. Ransomware continues to be one of the most visible and costly cyber threats facing Australian and New Zealand organisations.

However, for operators of critical infrastructure, the threat landscape has evolved.

As geopolitical competition intensifies across the Indo-Pacific, governments, intelligence agencies and cybersecurity leaders are increasingly warning that state-sponsored cyber actors are targeting critical infrastructure not simply for financial gain, but for strategic advantage, intelligence collection, coercion, and preparation for potential future conflict.

This raises an important question for boards, executives and crisis management teams:

Are your cyber crisis exercises preparing your organisation for the right adversary?

Why Critical Infrastructure Matters in Australia and New Zealand

Critical infrastructure operators in Australia and New Zealand are increasingly operating in an environment shaped by strategic competition in the Indo-Pacific. Government leaders continue to emphasise the challenges posed by increasing geopolitical competition, strategic contest and coercive behaviour in the region. Australia’s Foreign Minister, Penny Wong has recently described the Indo-Pacific as facing “accelerating contest” and a deteriorating strategic environment.

Cyber operations are now routinely used by nation states to:

Public reporting continues to demonstrate that sophisticated state-sponsored actors are actively targeting critical infrastructure globally, including energy, water, telecommunications, transportation and industrial organisations.

Cyber operations are rarely isolated events. Recent conflicts have further demonstrated that they are increasingly integrated with broader military, intelligence, economic and information operations. The distinction between peacetime competition and conflict is becoming increasingly blurred.

Cyber resilience can no longer be viewed solely through the lens of ransomware. For boards and executive teams, organisations responsible for essential services must also consider how they would respond to a sophisticated state-sponsored intrusion designed to achieve strategic rather than financial objectives.

The Problem with Ransomware-Only Exercises

Traditional ransomware tabletop exercises typically focus on questions such as:

These are important decisions. However, they generally assume that the threat actor’s primary objective is financial gain.

State-sponsored adversaries operate differently. Their objectives may include:

In many cases, the compromise may have existed for months or years before being detected.

The key challenge is no longer simply recovering from an attack. It is understanding what the adversary is trying to achieve and how your response may have broader national security implications.

When the Adversary Is a Nation State

Recent public reporting has highlighted how state-linked groups have targeted critical infrastructure operators globally, including energy, water, telecommunications, transportation and industrial organisations.

Unlike ransomware operators, state-sponsored actors often prioritise three things:

Persistence over Speed

Rather than announcing their presence through encryption, they seek to remain undetected.

Their goal may be to establish long-term access to operational technology (OT), industrial control systems (ICS), telecommunications infrastructure, or key corporate networks.

Intelligence over Extortion

The objective may be to understand:

This intelligence can provide significant strategic value during periods of heightened geopolitical tension.

Strategic Effects over Immediate Financial Gain

A nation-state actor may not seek to destroy systems today. Instead, they may seek to maintain access that could be leveraged during a future crisis.

This fundamentally changes the nature of executive decision-making.

How State-Nexus APT Exercises Differ

A mature critical infrastructure exercise should force executives to grapple with issues that are rarely considered in ransomware simulations.

1. Attribution Uncertainty

The first challenge is determining who is behind the attack.

The evidence may be incomplete. Government agencies may provide classified or limited intelligence. Technical indicators may point towards a nation-state but stop short of definitive attribution. Executives must make decisions without certainty.

Questions include:

2. Operational Safety Decisions

For critical infrastructure operators, the primary concern may not be data loss. It may be safety.

An exercise should test decisions such as:

These decisions are significantly more complex than restoring encrypted servers.

3. Government Coordination

State-sponsored attacks often trigger extensive engagement with government agencies.

Crisis teams may need to coordinate with:

This introduces additional complexity around information sharing, communications, and operational decision-making.

4. Escalating Geopolitical Context

A sophisticated exercise should include external developments. Examples include:

The cyber incident becomes part of a broader strategic picture rather than an isolated technical event.

5. Public Confidence and National Resilience

For critical infrastructure operators, maintaining public confidence can be as important as restoring systems. The consequences of a prolonged outage can extend far beyond the organisation itself.

What We Have Seen in Cyber Crisis Practice

Recently, CyBiz, working alongside Sygnia, facilitated a cyber crisis exercise for a critical infrastructure organisation based on a sophisticated state-sponsored APT scenario.

The exercise was intentionally designed to move beyond the traditional ransomware playbook. Rather than confronting participants with encrypted systems and ransom demands, the scenario centred on a long-term compromise of critical operational systems by a highly capable adversary seeking strategic advantage.

How Executive Discussions Shifted Away from Ransomware

What was striking was how quickly the discussion moved away from the topics that typically dominate ransomware exercises. There was no discussion about backups, ransom negotiations, or cyber insurance.

Instead, executives found themselves grappling with a very different set of questions:

Why Recovery Was Not the Hardest Challenge

The “ah-ha” moments were equally revealing. Participants recognised that many of their existing cyber crisis plans had been built around criminal actors seeking financial gain. While those plans remained valuable, they did not fully address the strategic, operational and geopolitical dimensions of a state-sponsored intrusion.

The exercise highlighted that recovery may not be the most difficult challenge. Significantly more complex were:

For many participants, the exercise reframed cyber resilience as more than a technology issue. It became a discussion about operational continuity, public confidence, national resilience, and leadership under uncertainty.

That shift in perspective is precisely why critical infrastructure organisations should be exercising against state-sponsored threat scenarios alongside more traditional ransomware events.

Preparing for the Cyber Threats That Matter Most

Ransomware remains a critical threat and should continue to be exercised. But for critical infrastructure operators, ransomware should no longer be the only scenario being tested.

The organisations that will be most resilient during the next decade will be those that prepare not only for criminal actors seeking profit, but also for sophisticated adversaries pursuing strategic objectives.

As geopolitical competition intensifies across the Indo-Pacific, the question is no longer whether critical infrastructure will be caught in the middle of cyber-enabled strategic competition. The question is whether executive teams have practised making the decisions that such an event would require.

Ready to Test Your Organisation Against a Different Adversary?

Many organisations have exercised ransomware scenarios multiple times. Far fewer have tested how their executives, crisis management teams, operational leaders and boards would respond to a sophisticated state-sponsored intrusion affecting critical services. The decisions are different. The stakeholders are different. The consequences can be different.

CyBiz, in partnership with Sygnia, designs and facilitates advanced cyber crisis exercises that incorporate real-world nation-state tradecraft, geopolitical escalation, operational technology impacts, intelligence-driven decision making, and critical infrastructure considerations.

Whether the scenario involves a compromised control room, manipulation of safety systems, strategic espionage, influence operations, or preparation for future disruption, the objective is the same: helping leaders make better decisions under pressure.

If your organisation operates critical infrastructure or delivers essential services, now is the time to ask whether your next tabletop exercise should test more than ransomware.

Contact CyBiz to discuss how a tailored state-sponsored APT cyber crisis exercise can help strengthen organisational resilience and prepare your leadership team for the evolving threat landscape.

When did your Board or Executive Team last exercise a nation-state cyber scenario? CyBiz, working with Sygnia, develops and facilitates executive cyber crisis tabletops based on realistic state-nexus APT scenarios for critical infrastructure organisations.
Talk to us about running an APT-focused executive tabletop.