Why defeating disinformation is harder than it looks

Why defeating disinformation is harder than it looks
Image credit: Getty Images/ Alicja Nowakowska

Disinformation has become one of the defining security challenges of the digital age. Governments, political movements, commercial actors, and state intelligence services all use it to shape public opinion, influence behaviour, and weaken institutions.

Recent elections, pandemic debates, and geopolitical conflicts have shown how quickly false narratives can spread online and polarise societies. Yet despite the scale of the problem, most countries still lack a clear way to determine whether they are actually prepared to defend themselves against organised disinformation campaigns.

Unlike traditional cyber attacks, which target computers and networks, disinformation attacks target something far more complex: human belief.

The goal is simple but powerful. If an attacker can persuade enough people to believe something that is false, or to continue believing something that is false, they can influence elections, polarise societies, damage reputations, or shift public policy.  

This is the essence of what is now termed “cognitive warfare”.

Technology has made this easier than ever. Social media networks allow messages to spread rapidly across populations. Artificial intelligence can now generate convincing text, images, and videos at scale. Networks of fake accounts can amplify messages until they appear widely supported.

Yet, despite growing concern, there is still no widely accepted framework for determining whether a country is actually capable of defending itself against disinformation campaigns.

That gap is what researchers at Monash University set out to address.

Measuring national preparedness

Researchers at Monash University have recently published the first nation state Capacity Maturity Model, designed  specifically to assess a country’s ability to defeat disinformation campaigns.

In effect, the model asks a simple question: 

If a major disinformation operation targeted a nation tomorrow, how well could it respond?

The concept of a capacity maturity model is already familiar in cybersecurity. For many years, governments have used the model developed by the Global Cyber Security Capacity Centre at University of Oxford to assess their ability to deal with cyber threats. These assessments help identify weaknesses and guide improvements in national capability.

But disinformation presents a fundamentally different challenge.

Cyber attacks target systems. Disinformation targets belief

Most cyber-attacks aim to steal data, disrupt services, or exploit computer systems. In other words, cyber-attacks manipulate technology in order to benefit the attacker. Disinformation attempts to manipulate beliefs.

Their goal is to either push a population into a false belief state, or to reinforce one that already exists. Once beliefs shift, behaviour often follows. Political attitudes can change, trust in institutions can erode, and social divisions can deepen. 

Some of the best recent examples of large-scale disinformation attacks arose during the COVID-19 pandemic. The most bizarre might be the widely asserted false claim that the disease resulted from radio-frequency emissions produced by 5G cell-phone towers. Over 100 incidents of vandalism or arson against cell-phone infrastructure and abuse or attacks on personnel were reported.

Cyber operations and disinformation campaigns often reinforce each other. Hackers may steal confidential documents and release altered versions to create misleading narratives, or selectively leak information to influence public debate.

Because the problem is different, the solutions are also different.

Why “simple solutions” rarely work

A wide range of countermeasures has been proposed, but many have serious limitations in practice.

Blocking websites can often be bypassed with simple technology. De-platforming influential propagators may simply push them to other platforms or new identities. Fining technology companies can present legal and practical challenges and may not significantly change behaviour.

Public rebuttals can sometimes amplify the very claims they are trying to counter. Education campaigns may lose effectiveness over time as people forget what they have learned. In some jurisdictions, certain countermeasures may even be unlawful.

Human psychology adds another layer of difficulty. People tend to believe information that confirms their existing views, a cognitive bias known as confirmation bias. Disinformation campaigns deliberately exploit these vulnerabilities.

The uncomfortable reality though, is that no single measure can defeat disinformation on its own.

Effective defence almost certainly requires a combination of legal, technological, institutional, and social responses working together.

Building the model

Recognising this complexity, the researchers behind the Monash model began by examining where disinformation defence overlaps with traditional cybersecurity approaches and where it differs.

They produced an extensive rationale document outlining the challenges involved in countering disinformation and identifying the capabilities nations may need in order to respond effectively.

Developing this analysis required a broad survey of known problems in the field and a review of existing countermeasures and international policy approaches. The resulting document runs to over 100 pages and examines issues such as:

  • how disinformation is defined
  • how it differs from cyber-attacks
  • the impacts of disinformation campaigns
  • cognitive biases commonly exploited by attackers
  • how disinformation spreads across digital networks
  • technologies used to generate and distribute it
  • the growing role of artificial intelligence
  • mathematical approaches to modelling deception and resilience
  • strategies for countering disinformation
  • national and international policy responses.

The democratic dilemma

One important conclusion is that any model designed to assess national capability cannot be overly prescriptive. Different countries will inevitably adopt different strategies depending on their legal systems, political cultures, and strategic priorities.

Protecting freedom of speech is also a critical constraint. Ironically, many disinformation campaigns—particularly those conducted by hostile states—seek to weaken democratic systems. Yet democratic societies depend on open debate and freedom of expression.

Defending against disinformation therefore requires a careful balance between protecting public discourse and avoiding unnecessary restrictions on speech.

The problem of “proxies”

Another major challenge involves so-called “proxies”: often ordinary individuals who unknowingly spread disinformation on behalf of malicious actors. Many people who share misleading information genuinely believe it to be true.

This creates difficult ethical and legal questions when designing countermeasures.

Determining what is actually true can also be more complicated than it first appears. In many complex situations there may be multiple interpretations of incomplete evidence, and disinformation often thrives in precisely these environments of uncertainty.

The highly politicised debate over the origins of COVID-19 is a recent example of how competing narratives can flourish when definitive evidence is limited.

Fact-checking is often presented as a solution, but in practice fact-checkers can also make mistakes. Limited subject-matter expertise, ideological bias, political polarisation, or simple misunderstanding can all affect fact-checker conclusions.

Avoiding unintended consequences

Another important consideration is the risk of unintended consequences. Measures designed to counter disinformation may themselves cause harm—for example by restricting legitimate speech or disproportionately affecting particular groups.

Recent attempts by Australian legislators to regulate aspects of social media highlighted some of these difficulties. Criticism from the Law Council of Australia raised many serious concerns about the potential implications of poorly designed regulation.

For this reason, the Monash model emphasises careful assessment rather than simple or universal solutions.

What happens next

The next step is practical application: using the model to evaluate national capacity and identify gaps in policy, institutions, and technical capability.

Such assessments could help governments strengthen their resilience to disinformation campaigns and better understand where improvements are needed.

In an era where information itself has become a strategic weapon, the ability of societies to recognise and resist manipulation may prove just as important as defending their networks, borders, or economies.

Latest posts

Republish

You may republish this article online or in print under our Creative Commons licence. You may not edit or shorten the text, you must attribute the article to Monash Lens, and you must include the author's name in your republication.

If you have any questions, please email lens.editor@monash.edu

Republishing Guidelines

https://lens.monash.edu/republishing-guidelines

Title

Why defeating disinformation is harder than it looks

Content