top of page

The Australian Government’s cyber strategy: It’s all about you (and what you do)

Sovereign SOC and AI access controls are no longer optional under Horizon 2, they're expected, evidenced, and enforced. Here's what's changing and what your organisation needs to do now.

In the first two blogs of this three-part series, we discussed the first two phases of the Australian Government’s new cyber security strategy and what you needed to know about your new obligations, as well as the all-new Essentials, which will replace the Essential Eight within the next few years.


In this blog, we cover two of the main areas of impact of Horizon 2 as the government aims to strengthen cyber maturity across our economy, our society, and our digital infrastructure:


  • Sovereign SOC (security operations centre) and monitoring requirements

  • Securing AI access controls


So, what will these changes mean to your organisation? What can you expect, and what will you need to do?


No more wiggle room for sovereign SOC and monitoring requirements


Under Horizon 2, government and critical infrastructure will face strengthened logging and monitoring standards. These will aim to improve visibility, boost early detection capabilities, and enhance these sectors' ability to coordinate responses to cyber threats.


This move is a direct signal to Australian organisations – in particular, critical infrastructure entities – that sovereign monitoring capability is no longer ‘nice to have’. It is being embedded into our national standards. Note: This does not impact the broader private sector except for organisations that support or supply critical infrastructure. These supply chain partners should expect increased scrutiny of their own monitoring and security practices.


But what's actually changing?


The government is moving from hoping applicable organisations monitor their systems well to mandating how and what is monitored. And they expect proof.


The days of ‘we have a SOC’ being enough are over. If you are a critical infrastructure entity or government agency, under Horizon 2, you’ll need to demonstrate what you can see, how fast you can detect, and how quickly you can respond.


What will you actively need to do?


Logging and monitoring


  • Implement standardised logging across systems – not just some systems, all of them

  • Ensure logs are centralised, protected, and actively analysed – not just collected and stored

  • Be able to demonstrate early detection capability, not just post-incident reporting


Incident readiness


  • Develop and test incident response playbooks specific to your sector

  • Run tabletop simulations to test whether your team actually knows what to do in a crisis

  • Know your Systems of National Significance obligations if you operate in critical      infrastructure


Supply chain


  • Extend your security monitoring into your supply chain, not just your own environment

  • Understand which of your suppliers could create a cascading failure if compromised

  • Participate in national cyber exercises to test readiness across the chain


For critical infrastructure specifically


  • If your asset has been declared a System of National Significance (aka SoNS), comply with Enhanced Cyber Security Obligations under the Security of Critical      Infrastructure Act – including incident response planning, cyber exercises, vulnerability assessments and system information reporting

  • Engage with the Trusted Information Sharing Network – sharing threat intelligence is strongly expected and increasingly a baseline requirement

  • Prepare for potential new Ministerial Directions powers that could compel action during a cyber incident


SOC capability


  • Move towards sovereign or locally-operated SOC models, particularly for sensitive sectors

  • Offshore or fully outsourced SOC arrangements are likely to face increasing scrutiny as government preference shifts towards Australian-controlled monitoring capability


The bottom line on SOC?


Government organisations and critical infrastructure entities can no longer tick a compliance box and move on. If this is you, you’ll need a live, evidenced, tested monitoring capability and the ability to prove it works.


Securing AI appropriately – no more blanket controls


This applies to everyone. The Australian Government sees AI as a ‘whole-of-economy' concern – not a sector issue.


The government’s Horizon 2 Action Plan is direct about the scale of the problem. Drawing on vendor research, it identifies AI as an expanding cyber threat vector – and points to a striking finding: 97% of organisations that reported an AI-related security incident lacked proper AI access controls.


Read that again. Not a minority or fringe case. 97%.


So the government’s message is clear: AI adoption is rapidly outpacing AI security. And that gap is precisely what Horizon 2 is designed to close.


Horizon 2 takes a risk-based, proportionate approach to AI security. It rejects blanket prohibitions in favour of targeted governance and intelligence-driven controls. So while the government wants your business to use AI safely and responsibly, the rules are going to be tailored to what you’re actually doing with it. It’s not a one-size-fits-all mandate.


What's actually changing?


The government isn't banning AI. In fact, it wants you to embrace it – but safely.


Horizon 2 is about closing the gap between the AI security incidents so many organisations experience and their lack of AI access controls. Not shutting AI down.


What will you actively need to do?


Implement AI access controls – right now


  • Identify every AI tool in use across your organisation – including shadow AI and tools staff have adopted informally

  • Implement access controls specific to AI systems – who can use them, what data they can access, what actions they can take


Govern AI risk – not just IT risk


  • Treat AI as a distinct risk category, not just another software tool

  • Develop an AI risk register that captures what AI tools are used, what data they touch, and what could go wrong

  • Align this to the government's Technology Vendor Review Framework – AI vendors will face the same scrutiny as other technology suppliers


Prepare for AI incident response


  • The government is assessing crisis management frameworks for major AI incidents – organisations should do the same internally

  • Ask: what would we do if our AI system was compromised, manipulated, or used against us?

  • Build this into your existing incident response playbooks


For critical infrastructure and government



Data centres and AI infrastructure


  • Organisations running or procuring AI infrastructure should prepare for new government expectations around data centre security and AI infrastructure alignment with national interests


Post-quantum readiness


  • Start quantum readiness planning now – government guidance is moving towards mandating it

  • Review your encryption standards and identify what would be vulnerable to a quantum-capable adversary


The bottom line on AI?


You don’t need to stop using AI. You need to know what AI you’re using, control who can access it, protect the data it touches, and have a plan if something goes wrong.


The government is watching – and strongly encourages you to share any AI incidents.


What to do next?


Priority actions:


  1. Audit all AI tools in use – including unofficial and shadow AI

  2. Implement AI-specific access controls

  3. Review and uplift your logging and monitoring to meet coming standards

  4. Test your incident response with a tabletop exercise

  5. Map your supply chain security dependencies

  6. Begin quantum readiness planning


You and your new horizons


How do we feel about these changes to the horizon? We believe these changes are necessary and long overdue – and they reflect precisely what we've believed since the start. It's why we built a bi-coastal sovereign SOC and committed to operating as a sovereign business from day one.


If you have questions or need help with the topics we’ve covered in this blog series, we’re happy to have a yarn about the practical steps you need to take and the plans you need to put in place for the future.


Get in touch – no obligation, just a straightforward conversation.

bottom of page