top of page

The Australian Government cyber strategy: Are you ready for the new Horizon?

Australia's seven-year national cyber security strategy is well underway - and the goalposts have shifted. Horizon 1 set the rules. Horizon 2 enforces them. Here's what that means for your organisation right now.

Three years ago, the Australian Government declared a clear ambition to position Australia among the world's leading cyber security nations by 2030.


To achieve this, it launched a seven-year national cyber security strategy with a structured, time-bound roadmap built across three escalating phases known as Horizons.


The first phase, Horizon 1, ran from 2023 to 2025. Horizon 2 runs from 2026 to 2028, and Horizon 3 will span 2029 to 2030. We review what Horizon 1 delivered and what it means for your organisation today - and what Horizon 2 now requires of you.


Horizon 1 – laying the groundwork


Horizon 1 was designed to close the critical gaps in Australia's cyber defences. This included introducing new laws and reporting obligations, and giving businesses the foundational tools and frameworks to start taking cyber security seriously. In effect, Horizon 1 built the rules we all need to follow to achieve the government’s overall goal.


Twenty actions and sixty initiatives have been delivered under Horizon 1 – and all were completed on time. But as we are now in the Horizon 2 phase, we won’t do a full retrospective of all of the Horizon 1 actions and initiatives. Instead, we’ll review the actions you need to have taken by now.


Let’s just say that if you haven’t done these things yet, you’re already running behind. By now, you should have:


  • Reviewed your obligations under the Cyber Security Act 2024

  • Put in place a mandatory ransom payment reporting process

  • Completed an Essential Eight assessment

  • Deployed MFA across all of your internet-facing systems

  • Enforced critical patching within 48hrs / 2 weeks

  • Established centralised logging and active monitoring

  • Identified your legacy IT and put a remediation plan in place

  • Tested your incident response plan

  • Completed a supply chain risk assessment

  • Delivered cyber awareness training to all staff

  • Defined Board/C-suite cyber governance responsibilities

  • Understood and met your SOCI obligations (if applicable)


Just quietly - what if you haven’t met your Horizon 1 obligations?


To be honest – you’re not alone. However, the window to catch up quietly is closing fast.


Horizon 2 is already underway, and it is being built on the assumption that Horizon 1 is done. The longer you wait, the more expensive and disruptive the catch-up becomes.


Horizon 1 is made up of both legally enforceable requirements and strongly recommended practices - and the distinction matters. If you haven’t addressed the mandatory requirements, you are potentially in breach of the law right now. In particular:

  • Mandatory ransomware payment reporting - if you suffer a ransomware attack and make a payment, you have 72 hours to report it.

  • Critical Infrastructure Risk Management Programs (SOCI Act) - if you are a regulated critical infrastructure entity.

  • Enhanced Cyber Security Obligations - if classified as a System of National      Significance.

  • Voluntary information sharing regime - understanding what you can and cannot      share with government.

The requirements below aren’t yet mandatory – but aren’t that far off, so it’s strongly recommended that you:

  • Uplift your Essential Eight maturity – progressively reach higher maturity levels that demonstrate controls are consistently applied and working, not just nominally in place. This will be mandated under Horizon 2.

  • Formalise supply chain risk assessments     – so you can identify every third-party supplier, vendor or partner with      access to your environment, then evaluate whether their cyber security      practices could create a vulnerability or entry point.

  • Enforce cyber awareness training standards     – ensure all staff (not just IT teams) receive regular, structured      training. Minimum training standards are expected under the incoming ASD      Essential Series for Enterprise IT.


Fallen behind? How and why it’s important to catch up


The good news is that being behind Horizon 1 is fixable.


But staying behind is a choice - and under Horizon 2, it’s an increasingly costly one. Be mindful that Horizon 2 isn’t waiting around for you to finish Horizon 1.


The Horizon 2 Action Plan sets out 19 actions across 64 initiatives, running from 2026 to 2028. It builds directly on the legal and policy foundations Horizon 1 put in place.


The commercial consequences are already being felt. Procurement requirements are already referencing Horizon 2 standards - so if you haven’t established compliance with Horizon 1 foundations, you will start losing contracts. And insurance underwriters are tightening up - cyber insurance premiums and eligibility are increasingly tied to demonstrated maturity.


The problem won’t just go away, so to catch up with what’s legally required:

  • Understand what’s what – what’s legally enforceable as opposed to recommended.

  • Triage the gaps - focus your resources on addressing the highest risks first.

  • Conduct a gap assessment - before committing resources, get a clear picture of where you actually stand.

  • Build a remediation plan – make a time-bound plan that’s pragmatic about what’s achievable. (A credible plan, even one that shows you're not there yet, is far better than no plan when a regulator or procurement team comes asking.)


Horizon 2 – putting plans into action


Right now (even if you have fallen behind), Horizon 2 is the one that matters - and it has real teeth.


If Horizon 1 was about building the rules, Horizon 2 is about enforcing them. If you’ve treated the last two years as a grace period, that window is now closed.


The focus in Horizon 2 shifts from establishing capability to embedding it - scaling cyber maturity across the entire economy, not just within government or large enterprise. For the first time, that expectation extends to small and medium businesses, not-for-profits, and organisations that may have previously considered themselves below the radar.


As far as your organisation is concerned, Horizon 2 is past the planning stage - it's about doing, proving and sustaining. If up until now you’ve been observing quietly from the sidelines, it just got real.


By the end of Horizon 2, you need to:

  • Deliver cyber awareness training to all staff – given that the human element is a factor in 60% of data breaches, your people are your first line of defence. Horizon 2 mandates a minimum training standard for everyone who touches your systems.

  • Work toward CyberSmart certification (SMBs) - the new CyberSmart standard is being built into government procurement and supply chain requirements. Without it, you’ll find that winning contracts and demonstrating trustworthiness to larger customers will become harder.

  • Uplift Essential Eight - the baseline is rising. ML2 (maturity level 2) is now the expected minimum for all industries, and ML3 for high-risk sectors. The framework itself is being replaced by a broader ASD Essentials Series.

  • Prove sovereign SOC and monitoring requirements - logging and monitoring standards are being mandated across government and critical infrastructure. You will need to move from passive collection to active, evidenced detection capability.

  • Enforce AI access controls and governance - 97% of organisations that have had an AI-related security incident had no proper AI access controls in place. Horizon 2 expects your organisation to know what AI you are running, who can access it, and what data it touches.

  • Map and assess supply chain security - your security is only as strong as your weakest supplier. Government exercises and procurement requirements will increasingly scrutinise the cyber maturity of your entire supply chain, not just your own environment.

  • Review and streamline incident reporting processes - a Single Cyber Incident Reporting Interface is coming. You are expected to have clean, tested processes for what to report, to whom, and by when, across all your regulatory obligations.

  • Meet Enhanced Cyber Security Obligations (if applicable) - Systems of National Significance face specific, enforceable obligations under the SOCI Act. Non-compliance is no longer a grey area, and new Ministerial Directions powers could compel action during an incident.

  • Begin quantum readiness planning - post-quantum cryptography transition planning is becoming mandatory for government agencies and will flow into critical infrastructure. Take advantage of the opportunity to prepare now, not later.


What are the key changes that will impact your organisation?


While that’s a significant ‘to-do’ list, we believe that three of these requirements will have a major impact on your organisation. The most significant changes are:

  1. Essential Eight - in one of the most significant cyber security framework shifts in Australian history, the Essential Eight is being retired – not just updated, but evolved into an entirely new series with new expectations. Simultaneously, maturity level expectations are being raised across the economy.

  2. Mandated sovereign SOC and logging/monitoring standards – the government is mandating how and what they monitor - and expecting proof. The days of "we have a SOC" being enough are over. Under Horizon 2, you’ll need to demonstrate what you can see, and how fast you can detect and respond.

  3. AI access controls – blanket controls will no longer make the grade and will need to be replaced with targeted governance and intelligence-driven controls.


What next?


Over the next two blogs in this series, we'll go deeper on each of these three changes - and what they mean practically for your organisation.


If any of this has raised questions about where your organisation sits, we're happy to help you work it out. Get in touch - no obligation, just a straight conversation.

bottom of page