Cybersecurity Policy Report, Recommendations on Geo-Blocking for Cyber Defense Offered in Australia, (May 19, 2025)
By Tony Foley
The Australian Signals Directorate (ASD), the country’s primary cybersecurity regulator, published guidance today on the use of “geo-blocking” as a cybersecurity strategy.
The ASD’s guidance explains that geo-blocking is a technique used by organizations to block network traffic based on the geographical assignment of an Internet protocol (IP) address. The agency said that, while such data could help with initial threat detection and analysis, it did not reliably indicate the intent, identity, or origin of malicious activity. Rather, ASD said, technical indicators like IP addresses must be considered in context; they may point to infrastructure used in an attack but not necessarily identify who is responsible for the attack.
The guidance specifies that cybersecurity practitioners should rely on a layered approach, drawing on a combination of indicators, behavioral patterns, and cross-validated information, when assessing cyber attacks. It also clarifies that an IP address is not equivalent to a GPS coordinate, outlining the reasons why an IP address may appear to originate from one country while the individual or system behind it is elsewhere. Some organizations might consider using commercial IP reputation services (which assign risk scores to IP addresses based on specified suspicious activities), but ASD argues that they should not be solely relied upon because of the potential for false positives, blocking legitimate users, or missing actual threats.
The ASD’s guidance lays out the benefits and risks of geo-blocking. Potential benefits include a reduction in malicious and nonoperational traffic and enhanced defensive posture, but risks identified include the potential for unintended consequences and inefficiencies when implemented as a stand-alone control, such as blocking legitimate users.
With respect to distributed denial of service (DDoS) attacks, the guidance acknowledges that geo-blocking traffic originating outside Australia might reduce such attacks but adds that DDoS traffic may not originate from overseas and that geo-blocking may impact legitimate users temporarily outside the country.
The guidance lays out several recommendations, including the following:
Evaluating the impacts of geo-blocking on a service’s user base and business model;
Using IP reputation data and public IP geolocation tools to inform, but not dictate, access decisions;
Using rate-limiting, anomaly detection, and behavioral monitoring to identify suspicious activity;
Implementing cloud-based DDoS protection where relevant;
Segmenting network traffic and isolating high-risk edge, or externally facing, devices;
Keeping firmware and software up to date across exposed systems;
Replacing end-of-life equipment and monitoring for unusual access patterns; and
Using phishing-resistant multifactor authentication, replacing default passwords with strong passwords or passphrases, and disabling password hints.
“IP addresses and geolocation data are useful signals in cybersecurity investigations, but they are only one piece of the puzzle,” ASD concludes. “Whether considering attribution or access control through geo-blocking, organisations should avoid relying on IP address geolocation alone.”
News: InternationalLegislation DataSecurity