Protecting Australia’s unseen critical infrastructure in the digital age 


Russell Cohen
Contributor

November marks Critical Infrastructure Security Month, a national initiative led by the Cyber and Infrastructure Security Centre (CISC) focused on uplifting the security and resilience of Australia’s most essential systems. 

At PEXA, we operate the world’s first digital property settlement and lodgement platform, which is designated as critical infrastructure under the Security of Critical Infrastructure Act, so this focus has deep resonance. 

The new definition of critical infrastructure

Traditionally, “critical infrastructure” meant the physical: pipelines, ports, power stations and telephone poles. But in the digital era, some of Australia’s most important infrastructure is increasingly digital. 

Every time Australians tap their phone, digitally sign a document, or settle on a new property, they rely on a chain of unseen systems operating together securely and seamlessly. 

This is Australia’s unseen critical infrastructure: the digital backbone that connects our institutions, our economy and our people. It includes banks, payment systems, stock exchanges and the PEXA Exchange, which securely enables the electronic settlement and lodgement of property transactions. 

Protecting these assets demands more than codes and compliance, it requires constant vigilance, responsive regulation and strong public-private collaboration. 

Modernising the rules that govern trust

The latest Australian Cybersecurity Strategy policy discussion paper rightly identifies that Australia’s current regulatory frameworks, though well-intentioned, can be complex, overlapping and difficult to navigate.  

Across energy, telecommunications, payments and property, fragmented and inconsistent rules can unintentionally create new risks, slowing innovation, duplicating effort and increasing cost. 

Current regulations don’t reconcile the competing challenges when two critical infrastructure operators must exchange information. Financial institutions are required to obtain compliance data from suppliers, but when those suppliers are also classified as critical infrastructure, legal constraints can restrict what may be shared. This misalignment creates practical barriers to meeting regulatory obligations efficiently. 

Horizon 2 of the strategy presents an opportunity for regulatory clarity, and the Government’s commitment to a co-design process with industry must be applauded as a critical step towards delivering this. Co-design will be central to ensuring that principles such as aligned standards, innovation and technology flexibility remain alongside the priority of protecting consumers.

PEXA welcomes the opportunity to participate with industry and government with the aim to achieve greater clarity for all. 

Navigating a complex regulatory landscape

For national digital infrastructure providers, the intersection of federal, state and financial regulation presents a unique complexity. Horizon 2 recognises that regulatory coherence is essential to improving cyber readiness, particularly protecting while empowering small business.  

At PEXA, we navigate multiple regulatory domains: our industry regulator ARNECC (a council of State and Territory representatives), the Reserve Bank, ASIC, and CISC. This requires transparent engagement and investment in adaptive compliance systems.  

Through the PEXA Exchange, we orchestrate complex transactions involving financial institutions, as well as small businesses including lawyers and conveyancers. This puts us in a unique position to help support our smaller partners and customers to meet the challenges of cybersecurity compliance.  

Specifically, we work with industry bodies to drive the adoption of compliance frameworks such as the SMB1001 Cybersecurity Standard, helping to ease the path toward stronger, standardised security practices across the legal sector.  

While we currently support law firms through general security reviews, we see significant value in aligning these efforts to recognised frameworks including SMB1001, which encourage “reasonable steps” to protect client confidentiality and enhance system resilience against threats and fraud. By partnering with industry associations, we aim to reduce the compliance burden through education, collaboration and practical guidance. 

Why policy and regulation must evolve

Strong policy and regulation are the invisible scaffolding that hold up national trust. Yet, as cyber risks evolve fast and become more complex, our frameworks must keep pace while giving business the time to adapt. Even the most up-to-date protocol will do nothing to reduce risk if it is very complex to implement.  

To stay ahead, cyber policy must shift from reactive compliance to proactive resilience, built on collaboration, real-time intelligence sharing, and standards that adapt with risk. 

Consultation paired with technology is the only way to deliver the regulation that genuinely protects our critical infrastructure ecosystem.  

For example, streamlined cyber standards for small businesses could help more Australian enterprises adopt baseline protections without heavy cost, and adopting standardised identity frameworks can ensure citizens and companies transact safely online without friction.  

Clear, forward-looking regulation doesn’t just prevent harm; it creates confidence. With the confidence of a co-designed framework, businesses can invest and innovate, Governments can plan, and Australians will live securely in a digital nation. 

Governments and business share a responsibility to build a cohesive cybersecurity framework that extends beyond compliance into collaboration, and at PEXA we look forward to continuing to play our part. 

Russell Cohen is chief executive and group managing director at PEXA, Australia’s digital property exchange platform and a key part of the nation’s critical digital infrastructure. He is an advocate for trust, resilience and innovation in Australia’s digital economy. 

This article was produced in partnership with PEXA as part of its sponsorship of the InnovationAus Awards for Excellence 2025. 

Do you know more? Contact James Riley via Email.

Leave a Comment

Related stories