Espionage in Australia: What ASIO’s ‘Extreme’ Threat Assessment Means for Business

Why cybersecurity alone is not enough when state-sponsored espionage can exploit people, communications, physical environments, supply chains and digital systems.

By Claude Khoury, Chief Operating Officer, NSI Global  

PUBLISHED: 21 June 2018    SUBSTANTIVELY UPDATED: 1 October 2026

When NSI Global first published this article in June 2018, Australia was debating major reforms to its espionage and foreign-interference laws. Those reforms subsequently became law. Eight years later, the strategic problem has not disappeared. Australia’s security agencies now assess the threat of state and state-sponsored espionage at extreme levels, and the economic cost is measurable in billions of dollars.

The Australian Institute of Criminology’s 2025 report prepared for the Australian Security Intelligence Organisation estimated that espionage cost Australia at least $12.5 billion in 2023-24. The estimate includes direct losses from known or suspected espionage, together with mitigation, response and remediation costs across government, business and universities. The report also cautions that the true cost is likely higher because espionage is covert by nature and many consequences cannot be reliably priced.

For business leaders, the significance is not simply the headline number. Modern espionage is a convergence threat. Sensitive information can be targeted through cyber intrusion, insiders, human intelligence, compromised communications, third parties, physical access and covert technical surveillance. Protecting the organisation therefore requires more than a cyber-security program operating in isolation.

Australia’s Espionage Threat Is Now at Extreme Levels

ASIO and the Australian Institute of Criminology describe espionage as one of Australia’s principal security concerns. Their public analysis states that the threat from state and state-sponsored theft of Australian information or capabilities is at extreme levels and is expected to worsen.

The $12.5 billion estimate relates specifically to the 2023-24 financial year and remains the latest publicly available national cost estimate as of October 2026. It is not a forecast for 2026. It is a measured estimate of direct, mitigation and response costs for a defined period, informed by public and classified material, stakeholder input and case-based analysis.

The same report illustrates how individual incidents can create losses well beyond the immediate cost of investigation and remediation. It modelled share-market losses of up to $887.2 million from theft of trade secrets affecting a large publicly listed Australian company, and up to $439.6 million from a cyber-espionage attack affecting a large listed company. These are scenario estimates, not average incident costs, and should be understood in that context.

Why Australian Businesses Are Intelligence Targets

Espionage is not limited to classified government information. ASIO’s NITRO guidance states that Australian businesses and research institutions, including organisations supporting sovereign capability, are being targeted by foreign intelligence services seeking privileged information and strategic advantage.

The information of interest will vary by organisation and adversary objective. It can include:

  • Research and development, patents, engineering data and proprietary technology.
  • Defence-adjacent and AUKUS-related supply-chain information.
  • Energy, resources, infrastructure and telecommunications information.
  • Tender strategy, pricing, mergers and acquisitions, investment and negotiation positions.
  • Executive communications, board material and sensitive meeting content.
  • Supplier, customer and government relationships.
  • Network architecture, security controls, credentials and access pathways.
  • Commercial data, intellectual property and trade secrets.
  • Sensitive personal information that can assist targeting, coercion or recruitment.

The critical point is that information does not have to be classified to be valuable. ASIO warns that seemingly innocuous information can be aggregated with other material to fill intelligence gaps or identify people, systems and organisations for future targeting.

The Crown Jewels Are Not Always Classified

Many organisations underestimate espionage risk because they do not hold national-security classified material. That is the wrong threshold. A foreign intelligence service may gain value from information that is commercially sensitive, operationally revealing or useful when combined with other sources.

An executive travel schedule, a supplier list, an engineering drawing, a conference-room discussion, a network diagram or a document describing a government customer’s requirements may appear routine internally. In the hands of an intelligence service, competitor, proxy or recruited insider, it may expose relationships, dependencies, technical capability or future intent.

This is why counterintelligence begins with identifying the organisation’s real crown jewels: the people, information, capabilities, relationships and decisions that would cause material harm if stolen, altered, exposed or manipulated.

State-Sponsored Espionage Is Not Only a Cyber Problem

Cyber espionage is one of the most visible parts of the threat, but it is not the whole threat. ASD’s Australian Cyber Security Centre says state-sponsored cyber actors remain an active and evolving threat to Australian networks, targeting government, critical infrastructure and businesses for state objectives. During FY2024-25, ASD’s ACSC made more than 1,700 notifications to entities about potentially malicious cyber activity, an 83% increase from the previous year.

A mature counter-espionage program therefore has to consider several pathways at once:

Cyber Espionage

Compromise of networks, cloud environments, credentials, remote-access services or endpoints can give an adversary long-term access to sensitive information and operational insight.

Insider Threat

A person with legitimate access can sometimes bypass controls that would stop an external attacker. Insider risk may involve deliberate cooperation, coercion, divided interests, negligence or exploitation of a trusted position.

Human Intelligence

Sensitive information can be elicited through relationships, professional approaches, social contact, recruitment efforts or apparently routine conversations.

Technical Surveillance

Meeting rooms, offices, vehicles, residences and communications environments can be targeted through covert audio, video, tracking or interception methods.

Supply-Chain and Third-Party Access

Contractors, vendors, consultants and technology providers can hold privileged access or sensitive information that creates an indirect pathway to the organisation.

Mobile and Telecommunications Targeting

Mobile devices and communications infrastructure can expose location, communications, identifiers, metadata and other information if systems or networks are compromised or manipulated.

Why Cyber Security Does Not Protect a Sensitive Meeting Room

A well-defended network does not automatically protect conversations occurring in a boardroom, executive office, hotel suite, vehicle or residence. Cyber controls are designed primarily to protect digital systems and information. Technical surveillance countermeasures address a different part of the attack surface: the physical and electromagnetic environment in which sensitive information is discussed or transmitted.

Depending on the threat, a sensitive environment can be exposed by concealed recording devices, hidden cameras, unauthorised transmitters, compromised conference-room equipment, tracking devices or collection methods that do not behave like conventional malware on a corporate network. Some threats may not be transmitting at the moment a room is inspected, which is one reason TSCM should not be reduced to a simple radio-frequency scan.

NSI Global’s Technical Surveillance Counter Measures (TSCM) service covers offices, boardrooms, executive areas, residences, vehicles and other sensitive environments where covert surveillance is a credible risk.

Insider Indicators Need Assessment, Not Assumptions

ASIO’s public NITRO guidance identifies behaviours that can be relevant to hostile intelligence activity, including unauthorised removal of information, electronic devices entering sensitive areas, unusual attempts to elicit information, excessive copying, unexplained access patterns and other departures from normal security behaviour.

None of those indicators, by itself, proves espionage. Many can have legitimate explanations. The correct response is proportionate assessment: establish context, preserve relevant evidence, test alternative explanations and escalate only where facts justify it.

This matters for both security and procedural fairness. An insider-risk program that treats anomalies as proof can damage trust and expose an organisation to legal and employment consequences. A program that ignores anomalies can allow genuine compromise to persist.

Espionage, Foreign Interference and Corporate Espionage Are Not the Same Thing

The terms are often used interchangeably, but they describe different problems.

  • Espionage involves obtaining Australian information for, or with the intention of providing it to, a foreign power seeking advantage.
  • Foreign interference involves covert, deceptive, corrupting or threatening activity by or on behalf of a foreign actor intended to influence decision-making contrary to Australia’s sovereignty or interests.
  • Corporate espionage is a broader commercial expression often used for covert acquisition of proprietary or commercially valuable information. It is not automatically state-sponsored espionage.

For organisations, that distinction affects who should be notified, which laws may apply, which evidence should be preserved and whether the matter is primarily a cyber incident, criminal investigation, employment matter, national-security concern or a combination of these.

The Cost of Espionage Extends Beyond the Stolen File

The direct loss of intellectual property or sensitive information is only one part of the damage. Espionage can also create investigation costs, legal costs, remediation, system rebuilds, lost productivity, delayed projects, loss of commercial advantage, weakened negotiating positions, reduced investor confidence and long-term harm to partnerships or sovereign capability.

The AIC/ASIO analysis estimated that cyber-enabled theft of intellectual property and trade secrets from businesses cost up to $1.901 billion in 2023-24, while insider threats involving state or state-sponsored actors affecting Australian businesses were estimated at up to $324.8 million. Those figures sit within the broader $12.5 billion national estimate and reinforce why prevention, detection and response all matter.

Building a Corporate Counter-Espionage Program

A counter-espionage program should be risk-based, proportionate and integrated with existing security and governance. The objective is not to make every organisation behave like an intelligence service. It is to identify what matters most, understand credible collection pathways and reduce the opportunities available to an adversary.

  1. Identify the crown jewels. Define the information, people, systems, capabilities and relationships whose compromise would cause material harm.
  2. Map access and exposure. Understand who can reach sensitive information, where it is discussed or stored, and which third parties have privileged access.
  3. Harden digital pathways. Implement strong identity controls, logging, network visibility, privileged-access management, patching and third-party cyber controls.
  4. Protect sensitive environments. Apply physical security and risk-based TSCM to locations where high-value discussions or work occur.
  5. Secure communications. Assess the confidentiality and integrity of communications channels used for sensitive operational, legal, board or government-related activity.
  6. Manage insider risk proportionately. Use reporting, access governance, behavioural context and lawful investigative processes rather than assumption-driven monitoring.
  7. Strengthen due diligence. Examine counterparties, key suppliers, acquisitions, strategic hires and relationships where hidden interests or undisclosed connections could create risk.
  8. Prepare to investigate. Establish escalation pathways so digital evidence, devices, accounts and logs can be preserved quickly if compromise is suspected.
  9. Reassess after trigger events. Mergers, restructures, major tenders, executive changes, geopolitical escalation, sensitive travel and unexplained information leakage can all change the threat profile.

How NSI Global Approaches Counterintelligence Risk

Serious counterintelligence problems rarely fit neatly within one discipline. A suspected information leak may begin as a corporate investigation and develop into a digital-forensic matter. A compromised device may raise telecommunications-security questions. A pattern of unexplained disclosures may justify a TSCM assessment. A strategic partnership may require enhanced due diligence before sensitive access is granted.

NSI Global’s current service structure reflects that convergence. Counterintelligence, TSCM, digital forensics and incident response, communications security, investigations, enhanced due diligence, global intelligence and risk advisory can be brought together according to the evidence and the authorised scope of the engagement.

What Should an Organisation Do if Espionage Is Suspected?

Do not begin by confronting a suspected individual or resetting devices simply to ‘clean’ the environment. Early actions can alter evidence, alert an adversary or close off investigative options.

The appropriate response depends on the facts, but organisations should consider preserving relevant logs, devices, accounts and access records; restricting unnecessary access where authorised; documenting what has been observed; seeking legal and security advice; and determining whether the matter should be escalated to ASIO, law enforcement, ASD’s ACSC or another competent authority.

ASIO’s NITRO portal advises organisations with concerns about suspicious or unusual activity related to espionage, sabotage or foreign interference to raise them through the organisation’s security manager or adviser, and to report unresolved national-security concerns to ASIO.

Frequently Asked Questions

How Much Does Espionage Cost Australia?

The Australian Institute of Criminology estimated that espionage cost Australia at least $12.5 billion in 2023-24. The estimate includes direct losses and mitigation, response and remediation costs. It is the latest publicly available national estimate as of October 2026 and is not a 2026 annual-loss figure.

Is Espionage in Australia Increasing?

ASIO and the AIC describe the threat of state and state-sponsored espionage as being at extreme levels and expected to worsen. ASD also describes state-sponsored cyber actors as a serious, persistent and evolving threat to Australian government, critical infrastructure and businesses.

Why Would a Foreign Intelligence Service Target a Private Company?

Private companies can hold technology, trade secrets, supply-chain data, research, government-related information, executive communications and other material that provides strategic, economic, military or diplomatic advantage.

Does Information Have to Be Classified to Be Valuable to a Foreign Intelligence Service?

No. ASIO warns that sensitive but unclassified and apparently innocuous information can be valuable, particularly when aggregated with other sources to reveal capabilities, relationships, vulnerabilities or intent.

Can Cyber Security Alone Prevent Espionage?

No. Cyber security is essential, but espionage can also exploit insiders, relationships, physical access, technical surveillance, supply chains and communications environments. Counter-espionage therefore requires controls across people, technology, information and physical environments.

What Is TSCM?

Technical Surveillance Counter Measures is the specialist process of detecting, identifying and mitigating covert surveillance risks in physical, electronic and communications environments. It can form part of a broader counterintelligence program when the threat assessment justifies it.

Should an Organisation Investigate an Employee Who Shows an Espionage Indicator?

An indicator should trigger proportionate assessment, not an assumption of guilt. Context, lawful authority, evidence preservation, procedural fairness and alternative explanations should be considered before any investigative conclusion is reached.

Who Should Be Contacted About Suspected State-Sponsored Espionage?

Depending on the circumstances, an organisation may need to involve its security team, legal counsel, ASIO, ASD’s ACSC, law enforcement or another relevant authority. National-security concerns involving espionage, sabotage or foreign interference can be reported to ASIO through NITRO.

Counter-Espionage Is a Business Resilience Issue

Australia’s espionage threat is no longer something that can be treated as a niche government-security problem. ASIO’s assessment and the AIC’s economic modelling show that state and state-sponsored espionage can impose significant costs on business, research, government and the wider economy.

The practical lesson for organisations is not to assume that every anomaly is espionage. It is to recognise that valuable information can be targeted through multiple pathways, and that protecting it requires cyber security, personnel security, physical security, communications security, TSCM, due diligence, digital forensics and governance to work as a coordinated system.

Organisations with a credible concern about information leakage, covert surveillance, insider compromise or state-sponsored targeting can contact NSI Global for a confidential discussion using a secure channel outside the suspected environment.

Sources and Further Reading

  1. Australian Institute of Criminology / ASIO – The Cost of Espionage (2025)
  2. ASIO NITRO – Recognising Hostile Intelligence Activity
  3. ASIO NITRO – Protecting Australian Business and Research
  4. Australian Signals Directorate – Annual Cyber Threat Report 2024-25
  5. NSI Global – Technical Surveillance Counter Measures
  6. NSI Global – Digital Forensics and Digital Evidence Services
  7. NSI Global – Communications Security (COMSEC)

Speak with NSI Global