Telstra outage caused by failure to address known network vulnerabilities, independent report finds

Telco warned by government agencies months before July 8 meltdown that affected 45% of calls and data sessions

edit
By LineZotpaper
Published
Read Time3 min
Sources2 outlets
An independent report has found that Telstra's major nationwide outage on July 8 was caused by the company's failure to prioritise fixing known vulnerabilities in its network, despite being warned about them months earlier by federal government agencies and academics.

The review by Technology Audit Partners (TAP), released by Telstra yesterday, found that a lack of oversight and ownership of key network elements contributed to the outage, which affected about 45 per cent of all calls and data sessions on Telstra's mobile network and saw hundreds of Triple Zero (000) calls unable to connect.

The report revealed that the outage began at 2:50am — nearly an hour earlier than Telstra had previously disclosed — and was triggered after a faulty power supply was replaced, which reset a GPS card date to 2006, causing the error to flow through the rest of the mobile network.

The review noted that alarms that would usually alert staff were only monitored during business hours by a "limited number" of people, and a lack of "knowledgeable staff" contributed to the telco taking several hours to determine the root cause.

"There were several reasons for this, primarily due to insufficient clarity of responsibility regarding NTP (Network Time Protocol) ownership and support, lack of visibility to the planned event to replace the Melbourne chassis that night, as well as a lack of understanding of the alarms that were the earliest indicators of a problem in the network," the report said.

The report also found that two of the telco's key engineers were on mandatory leave at the time of the outage.

Telstra chief executive Vicki Brady said the company accepts the findings of the report and is working through its recommendations.

"The cause … was consistent with what we said at the time, so it was not due to infrastructure failing, it was due to an undocumented design change in October, and it was due to a software update having not been done on a GPS card," she told a media briefing.

"The overarching finding is that we did not prioritise our timing system inside our networks at the highest level as a critical capability, which is exactly what it should have been. That is a miss on our side. We should have had it prioritised at the highest level."

The report's findings come after the ABC revealed in the days after the July outage that Telstra had been warned for months by federal government agencies and academics that it was vulnerable to the type of error it experienced. In 2024, Australia's government-run Cyber and Infrastructure Security Centre put out a public alert about how "Australia's critical infrastructure increasingly relies on the delivery of positioning, navigation and timing."

Ms Brady said the company has already reallocated resourcing to the team to improve its capability.

§

Analysis

Why This Matters

  • The outage affected nearly half of Telstra's mobile network, including emergency Triple Zero calls, highlighting critical infrastructure fragility.
  • The report shows that known vulnerabilities went unaddressed despite government warnings, raising questions about regulatory oversight of essential services.
  • Telstra's admissions of oversight failures could lead to increased scrutiny and potential reform of how telecommunications companies manage network risk.

Background

Telstra is Australia's largest telecommunications company, operating a mobile network that serves millions of customers and is considered critical national infrastructure. The July 8 outage was one of the most significant in recent years, disrupting calls, data, and emergency services across the country. The independent report commissioned by Telstra from Technology Audit Partners (TAP) aimed to identify the root cause and systemic issues. Prior to the outage, the Cyber and Infrastructure Security Centre had issued public alerts about the vulnerability of timing systems in critical infrastructure.

Key Perspectives

Telstra: The company has accepted the report's findings and acknowledged that the timing system should have been prioritised as a critical capability. CEO Vicki Brady said the company is reallocating resources and working through the recommendations.

Government and regulators: Federal agencies had warned about vulnerabilities in timing systems months before the outage, indicating that the risks were known at a policy level. The incident may prompt stronger regulatory requirements for network resilience.

Critics/Skeptics: The report reveals that key engineers were on mandatory leave and alarms were only monitored during business hours, suggesting systemic under-resourcing. Critics may argue that Telstra's internal culture and cost-cutting priorities contributed to the failure, and that the company's response should have been faster and more transparent.

What to Watch

  • Implementation of the report's recommendations: whether Telstra's promised resource reallocation and process changes actually occur.
  • Regulatory response: possible government inquiry or new rules mandating 24/7 monitoring of critical network components.
  • Senate inquiry developments: the outage has already prompted a Senate inquiry, and this report may influence its findings and any resulting recommendations.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.