Add Think Technology as a trusted source Foreign Technology and Data Security for Australian Business

Where does your technology actually come from?

A Hikvision security camera, illustrating foreign technology data security concerns

A Brisbane professional services firm we work with recently replaced their IP cameras. Their old units were a Chinese-made brand that Australian Defence had already removed from federal sites. The business hadn’t realised there was an issue. The cameras had worked fine for years. That’s exactly the problem: hardware and software can carry risks that have nothing to do with how well they perform day to day.

The origin of your technology matters. Governments across the Five Eyes are making decisions that directly affect what businesses can use, how their data is treated, and what supply chains are considered acceptable. For Queensland SMEs, this is no longer a background issue.

What has changed in Australia and globally

Australia banned Hikvision and Dahua cameras from federal government buildings in early 2023, after an audit found over 900 such devices across 250-plus government sites, including the Department of Defence and the Attorney-General’s office. Defence moved to remove the equipment. State-level reviews followed, with South Australia removing the cameras from its health department buildings on security grounds.

Canada went further. In June 2025, Canada’s Industry Minister ordered Hikvision to cease all operations in the country following a national security review. New federal purchases were banned and existing installations flagged for removal. That is a materially stronger position than Australia’s current rules, which still allow the cameras in private business use.

Australia has also applied restrictions to other foreign technology. TikTok was partially restricted on government devices in 2024and DeepSeek’s AI was banned from government use in 2025. The pattern is consistent: where a foreign technology product has ties to a government that could compel data access, Australia and its allies are acting to limit exposure.

In the United States, the FCC banned new Hikvision authorisations in 2022. In 2025, Hikvision lost a court challenge to lift that restriction. By mid-2026, the FCC was considering whether to extend restrictions to already-approved equipment.

New rules that now apply to smart devices sold in Australia

From 4 March 2026, Australia’s Cyber Security (Security Standards for Smart Devices) Rules 2025 took effect. These rules apply to manufacturers and suppliers of internet-connected or network-connected devices sold in Australia. They set mandatory security standards, covering areas like default passwords, software update obligations, and data handling requirements.

This matters for business buyers too. Devices that do not meet the new standards should not be available for sale in Australia from that date. But older devices already installed are not automatically covered. If your business has networked cameras, smart office equipment, or connected building systems installed before March 2026, those are operating under the previous, lower bar.

The Australian Signals Directorate (ASD) has consistently flagged supply chain risk as a core part of any organisation’s security strategy. Its 2025 Commonwealth Cyber Security Posture report found that 70% of government entities performed supply chain risk assessments, down from 74% in 2024. The direction is the wrong way, and that’s in government. Private business adoption is lower still.

What this actually looks like for a 30-seat Brisbane business

Most SMEs don’t buy technology because of where it comes from. They buy on price, features, and what the installer recommends. That’s reasonable. But the supply chain conversation has moved from a government-only issue into something that affects business continuity, cyber insurance, and client contracts.

A few things we see regularly in Brisbane businesses:

  • Networked cameras on the same flat network as the business systems, with no segmentation and factory-default passwords still active.
  • Cloud storage services where the provider’s data residency is unclear or offshore by default.
  • Phone systems and video conferencing equipment from vendors whose update and support lifecycle has ended or is unclear.
  • Software tools where the underlying components come from countries with data-sharing obligations that conflict with Australian privacy law.

None of these are hypothetical. They come up in our IT audits and security assessments regularly. The risk isn’t always that a foreign government is actively extracting your data. It’s that the conditions for that are present, and you may not be aware of it.

Practical steps to review your technology supply chain

You don’t need a geopolitical analyst to do this. A few practical checks go a long way:

  • Map your networked devices. List every device that connects to your network, not just computers. Cameras, printers, access systems, smart TVs in meeting rooms, building sensors.
  • Check data residency for cloud services. Where is your data stored? Who is the upstream provider? Does your software vendor have obligations to share data with a foreign government?
  • Segment sensitive systems. Keep cameras and IoT devices on a separate network from your business data. This limits what any compromised device can reach.
  • Review firmware and update status. Unpatched networked devices are a known entry point. If a vendor is no longer issuing updates, the device is a liability.
  • Include supply chain questions in procurement. Before buying new hardware or signing up for a cloud service, ask where it’s manufactured, who owns the vendor, and where data is processed.

Home Affairs has published Critical Technology Supply Chain Principles to help Australian organisations of all sizes think through these questions. It’s a useful starting point if you want a framework for internal decisions.

Where TTA fits in this conversation

We don’t tell clients to rip out every device that doesn’t come from an approved country list. That’s not practical, and the risk picture is more nuanced than that. What we do is help businesses understand their actual exposure.

A well-segmented network with good patch management and visibility into what devices are doing reduces the risk from any device, regardless of origin. Strong network security controls matter more than swapping hardware if you don’t address the underlying configuration gaps first.

That said, if you’re in a sector with government contracts, defence supply chain work, or sensitive client data, the origin of your technology now affects your eligibility and obligations. That’s a conversation worth having before a contract review or an incident forces it.

Frequently asked questions

Are Hikvision cameras illegal to use in my Australian business?

No. As of July 2026, Hikvision cameras are legal for private and business use in Australia. The Australian Government has removed them from federal buildings and Defence sites on security grounds, but there is no law preventing commercial or domestic use. The risk for businesses is operational and reputational rather than legal, though that may change as policy evolves.

What are Australia’s new smart device security rules?

The Cyber Security (Security Standards for Smart Devices) Rules 2025 took effect on 4 March 2026. They require manufacturers and suppliers of internet-connected or network-connected devices sold in Australia to meet mandatory security standards, including restrictions on default passwords, software update obligations, and data handling. The rules apply to new devices sold from that date, not to existing installations.

Does supply chain risk apply to cloud software, not just hardware?

Yes. Software-as-a-service tools, collaboration platforms, and cloud storage services all raise supply chain questions. The relevant issues are where data is stored, who the upstream infrastructure provider is, and whether the vendor has legal obligations to a foreign government that could result in your data being accessed. Australian Privacy Principles apply regardless of where the vendor is based.

How does a small business start a technology supply chain review?

Start with a device audit: list every networked device in your environment, including cameras, printers, and building systems. Then check data residency for your cloud services and confirm firmware is current on all devices. From there, segment IoT devices from business systems and build supply chain questions into your standard procurement process. TTA can help structure and run this review.

When should we ask for outside help with this?

If you have government contracts, handle sensitive client data, or are unsure what devices are on your network and what they are connecting to, outside help is worth it. An IT audit gives you a clear picture of your current exposure without requiring you to understand all the technical detail yourself. It’s a practical starting point before a contract review or an insurer asks the same questions.

Where to from here?

If you’d like a straightforward review of your technology setup, including where your devices and data sit, our team is ready to help. A conversation costs nothing and usually surfaces a few things worth knowing.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.