Mobile operators and critical infrastructure providers are facing rapidly increasing cybersecurity threats and associated costs, with industry groups warning that fragmented and overlapping regulatory frameworks are driving up compliance expenses. The GSMA reports that global core cybersecurity spending by mobile operators is expected to more than double by 2030, reaching up to $42 billion, as the number and sophistication of attacks continue to rise. The organization highlights that inconsistent national regulations and duplicate reporting requirements are diverting resources from effective risk mitigation to compliance activities, and calls for greater international coordination and harmonization of standards to reduce unnecessary burdens on operators.
In Australia, critical infrastructure sectors such as energy, water, and transport are subject to a growing set of cybersecurity obligations under the Security of Critical Infrastructure Act and sector-specific frameworks like the Australian Energy Sector Cyber Security Framework (AESCSF). These regulations require board-level engagement and comprehensive governance, risk, and compliance programs that address both IT and operational technology systems. The focus is shifting from basic reporting to proactive risk mitigation, with the government empowered to intervene in emergencies. While these frameworks are specific to Australia, they offer guidance that can inform cybersecurity strategies for critical infrastructure operators globally.

See the reporting duties and controls this puts on the clock.
2 events from the most recent confirmed update back to the earliest known activity.
The GSMA said a patchwork of cybersecurity regulations is driving up costs for the mobile industry, highlighting industry concern over inconsistent global compliance requirements.
Tenable published a blog post outlining Australian cybersecurity regulations relevant to critical infrastructure operators, providing compliance-focused guidance for affected organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.