The Australian Cyber Security Centre (ACSC) has repeatedly identified the software supply chain as a critical vulnerability for Australian organisations, with one insidious threat gaining prominence: ‘secrets sprawl’ [3.1, 3.2]. Secrets—passwords, API keys, and most critically, cryptographic keys—are scattered across code repositories, logs, and integrated systems, turning a minor breach in a third-party vendor into an enterprise-wide catastrophe. The SolarWinds hack and others demonstrated the chilling scale of this problem [3.5].
When a cryptographic key or token is leaked, attackers gain an unmonitored avenue for lateral movement and privilege escalation [3.1]. In a complex supply chain, this vulnerability is multiplied by every contractor, every CI/CD pipeline, and every outsourced software package [3.4]. The ACSC’s guidance is direct: Australian firms must prioritise immediate audits to identify and eliminate secrets from code and enforce the use of short-lived, narrowly scoped credentials [3.1].
Traditional, centralised key management systems often struggle to meet this level of rigour across distributed, third-party environments. They are single points of failure, both technologically and operationally.
Orbitra’s infrastructure directly tackles ‘secrets sprawl’ by leveraging the core security principles of distributed ledger technology (DLT) and dedicated key management systems.
To protect their economic and national interests, Australian organisations must evolve their cyber resilience strategies. Adopting decentralised security architecture is no longer optional; it is the most robust way to ensure that the integrity of data and the control of sensitive keys remain absolute, regardless of the vulnerabilities that might emerge elsewhere in the supply chain.
References:
[3.1] SecurityBrief Australia. (2025, September 23). Australian firms urged to secure code after rising repo attacks.
[3.2] Cyble. (2025, August 26). Australia’s Cyber Crisis & Supply Chain Vulnerabilities.
[3.4] Australian Cyber Security Centre (ACSC). (2023, May). Cyber Supply Chain Risk Management.
[3.5] Cyber Security Cooperative Research Centre. (2025, March). CSCRC Omni: Hardening Cybersecurity Supply Chains Report.