Summary

  • Australia's communications regulator found that emergency-call rule breaches followed the 8 November 2023 nationwide outage, that 2,145 people could not reach the emergency call service, that welfare checks were not carried out for 369 of them, and that the outage "should have been preventable".
  • A government review produced 18 recommendations, all accepted, including mandatory post-outage reporting and remote, redundant access to network management tools.
  • On 18 September 2025, Optus says, a routine planned firewall upgrade at the Regency Park exchange went ahead without traffic being diverted first, and an independent report counted at least ten mistakes by Optus employees and its contractor Nokia.
  • The two events are the same class of failure. The remediation is only proven if it constrained the second change — and the public record does not yet show that it did.

What the regulator concluded

The Australian Communications and Media Authority announced that subsidiaries of Singtel Optus Pty Limited paid penalties totalling more than $12 million for breaches of emergency call rules following its investigation (ACMA); news reporting on the penalty recorded the same $12 million figure (iTnews). The regulator tied those breaches directly to the 8 November 2023 nationwide outage. In the same release it stated that 2,145 people were unable to access the emergency call service during the outage, that 369 welfare checks on people who had tried to call were not conducted, and that its findings indicated Optus "failed in the management of its network in a number of areas and that the outage should have been preventable".

The formal investigation, published in redacted form, is more specific (ACMA investigation report). It records findings that Optus Mobile contravened subsection 148(1) of the Telecommunications (Consumer Protection and Service Standards) Act on 4,560 occasions, with smaller counts for Optus Networks, Optus Internet and Optus Fixed Infrastructure. It records that the three infrastructure entities each contravened subsection 11(1) of the Determination once on 8 November 2023 by failing to maintain the proper and effective functioning of their controlled networks — including failing to ensure the network was sufficiently resilient to protect core network routers, and failing to ensure appropriate access to monitor and manage the network. The regulator also assessed that Optus had failed to take practicable steps to implement out-of-band connections, and had insufficient out-of-band access to manage its own network during an outage.

That detail matters because out-of-band access is the mechanism by which operators reach their equipment when the ordinary management path is gone. A finding that it was inadequate speaks to detection and recovery, not only prevention.

What the review required

On 9 November 2023 the Australian Government announced a post-incident review and appointed Richard Bean, a former Deputy Chair of the ACMA, to lead it. The department records that Mr Bean submitted his final report on 21 March 2024 with 18 recommendations, and that the government accepted all 18 (Department of Infrastructure). The department also records that the Senate Environment and Communications References Committee tabled its own report on 27 September 2024, with the government's response tabled on 28 January 2025.

Several of the recommendations speak directly to the control that failed. The final report recommends that carriers conduct six-monthly end-to-end testing of the Triple Zero ecosystem, including network behaviour during outages of various types; that providers report to the ACMA and the department within a mandated timeframe after a major outage, setting out causes, resolution steps, the impact on Triple Zero and a dated plan to prevent recurrence; that carriers communicate specific information to customers during and about outages; and that network operators be required to establish the ability to remotely access and activate network management tools, with sufficient network redundancy to deploy them in the event of a core network outage (Bean Review final report). The government's response accepted the recommendations (Australian Government response).

Read together, those recommendations are an instruction to build a control that governs future changes: test the emergency path, keep a way in when the network is down, and write down what happened.

What happened next

The Senate committee chapter is the most useful single record of the 2023 mechanism, because it places the parties' accounts side by side. It records Optus stating that at around 4.05am the network received changes to routing information from an international peering network following a routine software upgrade, that those changes propagated through multiple layers and exceeded preset safety levels on key routers that could not handle them, and that the routers disconnected from the Optus IP Core network to protect themselves (Parliament of Australia). It records Singtel stating that a significant increase in addresses being propagated through the network triggered preset failsafes but that "the upgrade was not the root cause" (Reuters), and Cisco stating that it could confirm Cisco routers "performed as configured". Optus's managing director of networks told the committee that almost 90 routers were affected when a preset safety limit was reached or exceeded, and that the outage resulted from Optus's defences for the change in routing information not working as they should have.

Optus's own submission to the committee goes further on scale: the 2023 outage occurred because more than 100 devices automatically self-isolated to protect themselves from an overload of IP routing information; the self-protection limits were default settings provided by the equipment vendor; and restoration required work across more than 100 devices in 14 sites (Optus submission). Optus also states there that the software upgrade at a Singtel internet exchange in North America resulted in the routing change but was not the cause of the outage.

That is the 2023 dispute in one page: a planned change, an automatic protective behaviour that no one had modelled, and a disagreement about which of the two should carry the label "root cause".

The same submission then describes what happened on 18 September 2025. Optus states that it suffered an outage lasting over fourteen hours, from 00:17 to 14:34 AEST, and that 605 unique service numbers attempting to make Triple Zero calls were unsuccessful in South Australia, Western Australia, the Northern Territory and parts of far west New South Wales.

It states that a "soft lock/hard lock" change to a session border gateway was performed without redirecting traffic off the platform first, and that the outage occurred because an incorrect procedure was followed during a routine and planned upgrade to a firewall at the Regency Park exchange — compounded by failures to escalate the alarms that were triggered and to respond to customer calls reporting the outage.

The independent report on that event is blunt. It states that Triple Zero customer calls failed to connect during a typical firewall upgrade implemented just after midnight, that voice calls including emergency calls were not diverted before a gateway was closed to isolate the firewall at Regency Park in South Australia, and that closing the gateway without a diversion blocked Triple Zero calls. It attributes the failure to a series of at least ten mistakes by Optus employees and their contractor Nokia, says those mistakes could only be explained by a lack of care about a critical service and a lack of disciplined adherence to procedure, and states that the change instructions Optus gave Nokia were incorrect and that adequate reviews of the likely outcomes were not made by either party (independent report).

What would count as proof now

Nothing in the public record establishes that the 2024 remediation package was inadequate, and nothing establishes that it was sufficient. The point is narrower and harder: the two failures share a shape. In 2023 a planned change produced an unmodelled propagation that removed the carrier's ability to reach its own equipment. In 2025 a planned change was applied without a diversion that would have kept the emergency path clear, and the alarms that should have shortened the outage did not produce the escalation they were meant to.

The review's own recommendations describe what would count. Six-monthly end-to-end testing of the Triple Zero path either happens and its results are published, or it does not. Post-outage reporting either arrives inside the mandated timeframe with causes and a dated plan, or it does not. Remote, redundant management access either exists and is exercised, or it exists on paper.

A reader should treat a completed change with a documented diversion step, an escalation that demonstrably reached a decision-maker within minutes, and a tested emergency path that carried calls during the same window as evidence the control holds — and sustained silence on those three points as evidence that accountability has been relocated rather than resolved.

For anyone tracking a carrier through its own directory record, the standing question is the same one the regulator asked in 2024 and the operator's own submission answered in 2025: who approves a change that touches the emergency path, and what happens to the alarm when it fires at 00:17. See SingTel Optus Pty Ltd in the BTW directory.