




The Australian Government’s cyber strategy: It’s all about you (and what you do)
Sovereign SOC and AI access controls are no longer optional under Horizon 2, they're expected, evidenced, and enforced. Here's what's changing and what your organisation needs to do now.

In the first two blogs of this three-part series, we discussed the first two phases of the Australian Government’s new cyber security strategy and what you needed to know about your new obligations, as well as the all-new Essentials, which will replace the Essential Eight within the next few years.
In this blog, we cover two of the main areas of impact of Horizon 2 as the government aims to strengthen cyber maturity across our economy, our society, and our digital infrastructure:
Sovereign SOC (security operations centre) and monitoring requirements
Securing AI access controls
So, what will these changes mean to your organisation? What can you expect, and what will you need to do?
No more wiggle room for sovereign SOC and monitoring requirements
Under Horizon 2, government and critical infrastructure will face strengthened logging and monitoring standards. These will aim to improve visibility, boost early detection capabilities, and enhance these sectors' ability to coordinate responses to cyber threats.
This move is a direct signal to Australian organisations – in particular, critical infrastructure entities – that sovereign monitoring capability is no longer ‘nice to have’. It is being embedded into our national standards. Note: This does not impact the broader private sector except for organisations that support or supply critical infrastructure. These supply chain partners should expect increased scrutiny of their own monitoring and security practices.
But what's actually changing?
The government is moving from hoping applicable organisations monitor their systems well to mandating how and what is monitored. And they expect proof.
The days of ‘we have a SOC’ being enough are over. If you are a critical infrastructure entity or government agency, under Horizon 2, you’ll need to demonstrate what you can see, how fast you can detect, and how quickly you can respond.
What will you actively need to do?
Logging and monitoring
Implement standardised logging across systems – not just some systems, all of them
Ensure logs are centralised, protected, and actively analysed – not just collected and stored
Be able to demonstrate early detection capability, not just post-incident reporting
Incident readiness
Develop and test incident response playbooks specific to your sector
Run tabletop simulations to test whether your team actually knows what to do in a crisis
Know your Systems of National Significance obligations if you operate in critical infrastructure
Supply chain
Extend your security monitoring into your supply chain, not just your own environment
Understand which of your suppliers could create a cascading failure if compromised
Participate in national cyber exercises to test readiness across the chain
For critical infrastructure specifically
If your asset has been declared a System of National Significance (aka SoNS), comply with Enhanced Cyber Security Obligations under the Security of Critical Infrastructure Act – including incident response planning, cyber exercises, vulnerability assessments and system information reporting
Engage with the Trusted Information Sharing Network – sharing threat intelligence is strongly expected and increasingly a baseline requirement
Prepare for potential new Ministerial Directions powers that could compel action during a cyber incident
SOC capability
Move towards sovereign or locally-operated SOC models, particularly for sensitive sectors
Offshore or fully outsourced SOC arrangements are likely to face increasing scrutiny as government preference shifts towards Australian-controlled monitoring capability
The bottom line on SOC?
Government organisations and critical infrastructure entities can no longer tick a compliance box and move on. If this is you, you’ll need a live, evidenced, tested monitoring capability and the ability to prove it works.
Securing AI appropriately – no more blanket controls
This applies to everyone. The Australian Government sees AI as a ‘whole-of-economy' concern – not a sector issue.
The government’s Horizon 2 Action Plan is direct about the scale of the problem. Drawing on vendor research, it identifies AI as an expanding cyber threat vector – and points to a striking finding: 97% of organisations that reported an AI-related security incident lacked proper AI access controls.
Read that again. Not a minority or fringe case. 97%.
So the government’s message is clear: AI adoption is rapidly outpacing AI security. And that gap is precisely what Horizon 2 is designed to close.
Horizon 2 takes a risk-based, proportionate approach to AI security. It rejects blanket prohibitions in favour of targeted governance and intelligence-driven controls. So while the government wants your business to use AI safely and responsibly, the rules are going to be tailored to what you’re actually doing with it. It’s not a one-size-fits-all mandate.
What's actually changing?
The government isn't banning AI. In fact, it wants you to embrace it – but safely.
Horizon 2 is about closing the gap between the AI security incidents so many organisations experience and their lack of AI access controls. Not shutting AI down.
What will you actively need to do?
Implement AI access controls – right now
Identify every AI tool in use across your organisation – including shadow AI and tools staff have adopted informally
Implement access controls specific to AI systems – who can use them, what data they can access, what actions they can take
Govern AI risk – not just IT risk
Treat AI as a distinct risk category, not just another software tool
Develop an AI risk register that captures what AI tools are used, what data they touch, and what could go wrong
Align this to the government's Technology Vendor Review Framework – AI vendors will face the same scrutiny as other technology suppliers
Prepare for AI incident response
The government is assessing crisis management frameworks for major AI incidents – organisations should do the same internally
Ask: what would we do if our AI system was compromised, manipulated, or used against us?
Build this into your existing incident response playbooks
For critical infrastructure and government
Participate in the government's information sharing on AI incidents via the Trusted Information Sharing Network
Build visibility of AI use across your supply chain – not just your own environment
Data centres and AI infrastructure
Organisations running or procuring AI infrastructure should prepare for new government expectations around data centre security and AI infrastructure alignment with national interests
Post-quantum readiness
Start quantum readiness planning now – government guidance is moving towards mandating it
Review your encryption standards and identify what would be vulnerable to a quantum-capable adversary
The bottom line on AI?
You don’t need to stop using AI. You need to know what AI you’re using, control who can access it, protect the data it touches, and have a plan if something goes wrong.
The government is watching – and strongly encourages you to share any AI incidents.
What to do next?
Priority actions:
Audit all AI tools in use – including unofficial and shadow AI
Implement AI-specific access controls
Review and uplift your logging and monitoring to meet coming standards
Test your incident response with a tabletop exercise
Map your supply chain security dependencies
Begin quantum readiness planning
You and your new horizons
How do we feel about these changes to the horizon? We believe these changes are necessary and long overdue – and they reflect precisely what we've believed since the start. It's why we built a bi-coastal sovereign SOC and committed to operating as a sovereign business from day one.
If you have questions or need help with the topics we’ve covered in this blog series, we’re happy to have a yarn about the practical steps you need to take and the plans you need to put in place for the future.
Get in touch – no obligation, just a straightforward conversation.


