Orbitra

The New Supply Chain Risk: Why Cryptographic Key Management is Now Crucial

The New Supply Chain Risk: Why Cryptographic Key Management is Now Crucial
Secrets Sprawl is the Supply Chain Killer: DLT’s Answer to the ACSC’s Critical Warning

The Australian Cyber Security Centre (ACSC) has repeatedly identified the software supply chain as a critical vulnerability for Australian organisations, with one insidious threat gaining prominence: ‘secrets sprawl’ [3.1, 3.2]. Secrets—passwords, API keys, and most critically, cryptographic keys—are scattered across code repositories, logs, and integrated systems, turning a minor breach in a third-party vendor into an enterprise-wide catastrophe. The SolarWinds hack and others demonstrated the chilling scale of this problem [3.5].

The Danger of Uncontrolled Keys

When a cryptographic key or token is leaked, attackers gain an unmonitored avenue for lateral movement and privilege escalation [3.1]. In a complex supply chain, this vulnerability is multiplied by every contractor, every CI/CD pipeline, and every outsourced software package [3.4]. The ACSC’s guidance is direct: Australian firms must prioritise immediate audits to identify and eliminate secrets from code and enforce the use of short-lived, narrowly scoped credentials [3.1].

Traditional, centralised key management systems often struggle to meet this level of rigour across distributed, third-party environments. They are single points of failure, both technologically and operationally.

How Distributed Ledger Technology Mitigates Sprawl

Orbitra’s infrastructure directly tackles ‘secrets sprawl’ by leveraging the core security principles of distributed ledger technology (DLT) and dedicated key management systems.

To protect their economic and national interests, Australian organisations must evolve their cyber resilience strategies. Adopting decentralised security architecture is no longer optional; it is the most robust way to ensure that the integrity of data and the control of sensitive keys remain absolute, regardless of the vulnerabilities that might emerge elsewhere in the supply chain.

References:

[3.1] SecurityBrief Australia. (2025, September 23). Australian firms urged to secure code after rising repo attacks.

[3.2] Cyble. (2025, August 26). Australia’s Cyber Crisis & Supply Chain Vulnerabilities.

[3.4] Australian Cyber Security Centre (ACSC). (2023, May). Cyber Supply Chain Risk Management.

[3.5] Cyber Security Cooperative Research Centre. (2025, March). CSCRC Omni: Hardening Cybersecurity Supply Chains Report.

Beyond the ID: How Zero-Knowledge Proofs are Securing Australia’s Digital Future

Beyond the ID: How Zero-Knowledge Proofs are Securing Australia's Digital Future
The Data Minimisation Revolution: How Zero-Knowledge Proofs are Driving Australia’s Trust Exchange (TEx)

In the wake of successive high-profile data breaches, the Australian government is making a dramatic shift in how personal information is handled. At the centre of this transformation is the development of the Trust Exchange (TEx) and the powerful cryptographic tools it leverages, particularly Zero-Knowledge Proofs (ZKPs) [2.2]. The core philosophy is clear: the most secure data is the data that is never shared.

What the Trust Exchange Promises

Launched in proof-of-concept phase, TEx is designed to be the nexus for secure, consent-driven identity verification. Working through a user’s digital wallet (such as myGov), TEx allows Australians to verify an identity attribute or credential based on official government data, without handing over the sensitive source document [2.1].

For example, when accessing a service that requires age verification (like a licensed venue), TEx doesn’t transmit the user’s date of birth or driver’s licence. Instead, it sends a cryptographic token—a digital ‘thumbs up’—that simply assures the business that the user is over 18. This is where ZKPs become essential.

Zero-Knowledge Proofs: Proving, Not Showing

A Zero-Knowledge Proof is a cryptographic method where one party (the prover) can prove to another party (the verifier) that a given statement is true, without revealing any information beyond the validity of the statement itself [2.5, 2.6].

This has profound implications for Australian privacy:

For platforms and enterprises, integrating with systems that use ZKPs, like the future TEx, is not merely a technical choice—it’s a strategic compliance and security decision. By leveraging ZKP technology, Orbitra helps enterprises adopt this privacy-first model, simplifying KYC/AML burdens while drastically enhancing customer data protection. This forward-thinking approach is critical to staying aligned with the Australian Government’s mission to build national identity resilience [2.1].

References:

[2.1] Ashurst. (2024, August 16). Australia’s Digital ID Act and a new Trusted Exchange (TEx).

[2.2] Minister Shorten. (2024, August 13). Trust exchange drives secure digital services.

[2.3] TechRepublic. (2024, August 22). Australian Digital ID: TEx System Poised to Boost Security By Sharing Less Data With Businesses.

[2.5] Electronic Frontier Foundation. (2025, July 25). Zero Knowledge Proofs Alone Are Not a Digital ID Solution to Protecting User Privacy.

[2.6] Internet Policy Review. (2025, July 30). The impact of zero-knowledge proofs on data minimisation compliance of digital identity wallets.

Crypto Custody: What ASIC’s Updated Guidance Means for Fund Managers

Crypto Custody: What ASIC’s Updated Guidance Means for Fund Managers
The New Standard of Trust: What ASIC’s RG 133 Update Mandates for Australian Crypto Custody

The era of ad hoc digital asset custody in Australia is officially over. The Australian Securities and Investments Commission (ASIC) has delivered a clear regulatory signal, significantly updating its Regulatory Guide 133 (RG 133): Funds management and custodial services: Holding assets. This decisive revision formally extends the regulator's minimum standards to the custody of crypto-assets where they constitute financial products, fundamentally reshaping operational requirements for responsible entities and custodians [1.1, 1.6]. For organisations like fund managers and high-growth fintechs, this guidance isn't just about ticking compliance boxes; it’s about establishing a new, verifiable benchmark of trust with institutional clients.

The Non-Negotiables of Institutional Custody

The core of the updated RG 133 focuses on risk mitigation that accounts for the unique technical challenges of digital assets.

The Orbitra Advantage: Building Trust from the Ground Up

For infrastructure providers, RG 133 underscores the need for specialist expertise and infrastructure [1.1]. Our Electronic Wallet Security System is designed specifically to meet these heightened expectations. By implementing institutional-grade hot/cold wallet separation and multi-signature access controls, Orbitra helps responsible entities not only comply with the letter of the law but exceed the operational integrity demanded by ASIC. Furthermore, the requirement to perform due diligence on third-party service providers (like exchanges) and ensure they meet equivalent AUSTRAC registration and AML/CTF standards [1.1, 1.6] reinforces the need for fully auditable, compliant service partners across the value chain.

The updated RG 133 is a necessary maturation of the Australian digital finance landscape. By clearly defining the ‘good practices’ for crypto custody, ASIC is actively paving the way for larger, regulated institutional capital to enter the market with confidence. For firms ready to meet this challenge, this guidance is an opportunity to solidify their position as trustworthy leaders in the region.

References:

[1.1] Bits of Blocks. (2025, January 21). ASIC extends custody guidance to crypto assets.

[1.2] Charltons Quantum. (2024, December 10). ASIC Reinforces Custodial Standards: Insights into the Updated Regulatory Guide 133.

[1.6] KWM. (2025, January 15). Crypto custody: ASIC expands its Regulatory Guidance under RG 133.