Protect the person, not just the network

We spend enormous amounts of money protecting the networks around our most important people. Then, at the end of the day, we send those people home.

Protect the person, not just the network

Protect the person, not just the network

We spend enormous amounts of money protecting the networks around our most important people. Then, at the end of the day, we send those people home. There they find a car that logs where it goes and what is said inside it, a watch that records heart rate, among other biorhythms, an AI assistant that reads calendars and messages to be useful and a five-year-old router carrying all of it. Each was bought as a convenience. Together they create a high-fidelity record of a life, and very little of it stays within national borders. For most people that is a consumer-protection question. For some it is also a question of national resilience.

What is needed is a stronger focus on protected personal digital environments alongside the national digital ecosystem: trusted solutions that provide consumers with automatic security updates, network-level protections and clear separation between trusted devices and wider personal networks.

The criticality is becoming difficult to ignore. An ABC Four Corners investigation just this week showed a security researcher remotely manipulating a BYD Shark 6, including tracking its location and accessing its microphone. Regulation is catching up. The draft of Australia’s Privacy Amendment (Personal Data Protection) Bill 2026, on which consultation closed on 18 September, is the most substantial rework of Australian privacy law in a generation. It introduces a fair and reasonable test for the collection, use and disclosure of personal information, tightens consent and creates a right to have information erased by large digital platforms. And it is framed explicitly against emerging technologies, including AI and wearables.

But its focus remains on data collection, and it leaves the rules on overseas disclosure untouched. Consent given in Melbourne or Perth is worth only as much as the jurisdiction where the data comes to rest. A connected vehicle’s telemetry moves to a manufacturer’s cloud, where local laws could compel access to it. The rules need to therefore cover cross-border disclosure so that consent means the same thing overseas as in Australia.

Even then, privacy law governs just the handling of information. It does not cover, for example, whether a car’s brakes are isolated from its infotainment system or whether a smart TV still receives critical security updates. That requires enforceable technical standards, for which the government’s current consultation on adopting UN Regulations 155 and 156 as Australian Design Rules is the key instrument, together with origin-aware risk assessment for critical connected technology.

But these aren’t problems for governments alone.

China is now the largest single source of new vehicles sold in Australia, with a third of the market this year and rising. The same concentration runs across the supply chain, in the modules, chipsets and cloud services inside products carrying European and Korean badges. This means banning Chinese suppliers stopped being viable some time ago: no list of prohibited suppliers is long enough to keep such technology out of our driveways, wrists and homes. Governments have therefore moved, rightly, to managing foreign ownership, control and influence by assessing exposure, mandating standards and regulating access rather than presence – working with the manufacturers.

That approach accepts that the technology is arriving. But the approach should ensure that individual consumers are empowered to manage the risk. Choices that consumers make when they buy and set up devices are important, assuming policy makes those choices clear: data sharing off by default, plain statements of where data is processed and under whose law, and an end-of-support date on the box.

As the range of information with strategic or economic value expands, so too does the number of people whose personal digital security matters. This group carries sensitive information with them when they leave the workplace. Protecting their personal digital environments therefore becomes a question of national resilience.

The Protective Security Policy Framework tells Australian government agencies how to protect their people, information and premises at the workplace – but only in the workplace. Nothing equivalent covers what those same people are exposed to at home, and nothing covers the executives running Australia’s banks, telecommunications providers, energy networks and ASX 200-listed companies – those equally vital to national resilience.

A senior executive spends the day behind enterprise firewalls, managed devices and a security operations centre. At home, the same person sits behind that five-year-old router, surrounded by personal devices and family members with accounts of their own. Almost none of that is visible to the team protecting the executive at work. Britain’s National Cyber Security Centre treats such people as high-risk individuals, whose personal accounts are easier targets precisely because they lack corporate protections. In 2024, US authorities disrupted a Chinese state-sponsored network built from hundreds of compromised home and small-office routers, many of them old ones no longer receiving updates. In April 2026, the US disrupted a Russian operation that hijacked home routers to intercept the traffic of targets in government, military and critical infrastructure.

But extending corporate management into someone’s household is not the answer. Nor is a commercial VPN. A VPN encrypts traffic on an untrusted network, but it cannot tell you whether the home router has been compromised, patch the smart television, isolate an insecure camera or stop someone handing email credentials to the sender of a convincing phishing message. It also moves trust to a VPN provider, which deserves far more scrutiny when the user is a cabinet minister or ASX-listed CEO.

Britain has moved part of the way towards creating the protected personal digital environment. Its National Cyber Security Centre offers services that filter malicious websites for enrolled personal devices and alert users to account compromise.

The Australian government’s reforms are heading in the right direction. But there is now an opportunity for industry to complement them with trusted solutions that minimise data collection, manage data retention and mobilise a response to digital attacks. We expect police to provide a baseline for public safety, but we also add alarms, guards or panic buttons where a specific threat warrants it. Digital protection should follow the same logic.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.