Skip to content
Government ACT, Information Technology

CSIRO and Google partner to help secure Australia’s Critical Infrastructure from risky software components

Google 2 mins read

Partnership to assist critical infrastructure operators in meeting growing legislative obligations to prove the integrity and security of their software supply chains

 

CSIRO, Australia’s national science agency, and Google today announced a research partnership to close crucial gaps in how Australia’s critical infrastructure (CI) operators find, understand, and fix vulnerabilities in their software supply chains. 

 

A part of Google’s Digital Future Initiative and CSIRO’s Critical Infrastructure Protection and Resilience developing mission, the partnership will see Google and CSIRO work together to develop tools and frameworks that help Australian CI operators meet critical obligations around software supply chain security, including those in the amended Security of Critical Infrastructure (SOCI) Act and Australia’s Cyber Security Strategy

 

The tools and frameworks will focus on accurately identifying and fixing vulnerabilities in open source software components that have become an increasingly important part of digital transformation for Australia’s critical infrastructure, which includes everything from public utilities and hospitals to freight networks and groceries.  To maximise the impact of this partnership, all project findings will be publicly available, allowing critical infrastructure sectors free and easy access. 

 

CSIRO’s Project Lead, Dr Ejaz Ahmed, said the creation of new and homegrown technologies will enhance the security of software used in Australian critical infrastructure. 

“Software developed, procured, commissioned, and maintained within Australia will also be better aligned with local regulations, promoting greater compliance and trustworthiness,” Dr Ahmed said.  “This partnership builds upon a successful track record of AI-powered innovation, demonstrating the transformative power of Google and CSIRO's expertise.” 

 

A roadmap to more secure software

The partnership will see CSIRO work with the Google Open Source Security Team (GOSST) and Google Cloud to develop novel AI-powered tools for automated vulnerability scanners and data protocols that can quickly and precisely identify and assess the impact of open source vulnerabilities on Australian CI operators’ software supply chains. 

 

The tools will tap on existing resources including Google’s OSV database for the most up-to-date intelligence on vulnerabilities. CSIRO’s applied research, including methods to test for responsible AI usage and tools for analysing software packages, will help to ensure reports and recommendations directly address the local regulatory and operating context of Australian operators.

 

Similarly, CSIRO and Google will collaborate on designing a secure framework that gives Australian CI operators clear guidance on how to meet current requirements and a baseline for future ones. The framework will adapt and extend the Supply-chain Levels for Software Artifacts (SLSA) framework created by Google, with insight from CSIRO’s Australian industry practices, to define multiple levels of software supply chain maturity as well as steps to achieve each one. 

 

Google Cloud will provide secure and scalable infrastructure and solutions, including machine learning and Big Data capabilities as well as domain specific large language models, to accelerate the partnership’s research and translate it into tools or as-a-service offerings for CI operators. 

 

“Software supply chain vulnerabilities are a global issue, and Australia has led the way in legislative measures to control and combat the risks," said Stefan Avgoustakis, Security Practice Lead, Google Cloud, Australia & New Zealand. 

 

“The tools and frameworks we’re developing will give Australia’s CI operators a clear and consistent roadmap towards software supply chain maturity, based on the in-depth industry knowledge that CSIRO has built up over years of research. Making these resources openly available to CI operators will help establish greater resilience throughout critical infrastructure nationwide, and reflects our longstanding interest in teaming up with industry and academia to enhance the effectiveness of our years of work in open source security.” 

More from this category

  • Information Technology
  • 12/12/2025
  • 08:11
Datavault AI Inc.

Datavault AI Inc. (NASDAQ: DVLT) Announces a Distribution Date of Dec. 24, 2025, for the Dream Bowl Meme Coin Tokens to All Eligible Record Equity Holders of Datavault AI and Holders of Common Stock of Scilex Holding Company

PHILADELPHIA, Dec. 11, 2025 (GLOBE NEWSWIRE) -- via IBN-- Datavault AI Inc. (NASDAQ: DVLT) (“Datavault AI” or the “Company”), a leader in data monetization, credentialing, and digital engagement technologies, today announced that its board of directors (the “Datavault Board”) has set Dec. 24, 2025, as the distribution date for the Dream Bowl 2026 Meme Coin token (the “Meme Coin”) to all eligible record equityholders of Datavault AI. Dec. 24, 2025, will also be the distribution date for Datavault AI’s voluntary distribution of Meme Coins to record holders of common stock of Scilex Holding Company (NASDAQ: SCLX), which is being made…

  • Information Technology
  • 12/12/2025
  • 05:26
Denodo Technologies Inc. ("Denodo")

Denodo Named a Leader in the 2025 Gartner® Magic Quadrant(TM) for Data Integration Tools for Six Consecutive Years

Denodo believes this recognition is due to the strength of its AI capabilities and the loyalty of its diverse customer basePALO ALTO, Calif., Dec. 11, 2025 (GLOBE NEWSWIRE) -- Denodo, a leader in data management, today announced that Gartner® has positioned the Company as a Leader for the sixth consecutive year in its 2025 Magic Quadrant for Data Integration Tools. “Data integration tools remain a fundamental architectural component as organizations increasingly seek improved capabilities to support their operational, analytical and AI use cases,” states Gartner. “This research helps data and analytics leaders make their decisions by analyzing 20 vendors in…

  • Information Technology
  • 11/12/2025
  • 21:11
Patton Electronics Co.

Patton Honored with Gold-Level Innovators Award

Cabling Installation & Maintenance has recognized Patton’s CopperLink® CL-SFP Ethernet Extender as among the structured cabling industry's most innovative cabling and communications technology products for 2025.CopperLink®... Going the Distance!“I would like to congratulate Patton on their gold-level honoree status.”Patrick McLaughlinChief EditorCabling Installation & MaintenanceGAITHERSBURG, Md., Dec. 11, 2025 (GLOBE NEWSWIRE) -- Patton—world-renowned US manufacturer of networking and communications technology—announced today that its CopperLink® CL-SFP “world’s smallest” Ethernet Extender has won the 2025 Innovators Award from Cabling Installation & Maintenance Magazine.The CL-SFP Ethernet Extender is celebrated among the most innovative products introduced in the year 2025.Judges. An esteemed and experienced panel of…

Media Outreach made fast, easy, simple.

Feature your press release on Medianet's News Hub every time you distribute with Medianet. Pay per release or save with a subscription.