Heading image for Cyber Wardens: What the $23 million program delivered and measured

What the image represents

The government team sees a successful cyber-security program in the mirror, while businesses and networks burn outside it. The image represents the gap between reassuring metrics and evidence that businesses became more secure.

The Australian Government committed up to $22.995 million over three years, from 2023–24 to 2025–26, to an ad hoc grant for the Council of Small Business Organisations Australia (COSBOA) to run Cyber Wardens. 89 Degrees East delivered the program. (1)

The grant objective was to build small businesses’ ability to protect themselves from cyber security threats. Its intended outcomes included greater awareness, action by small businesses and trained in-house cyber wardens. (1)

News24 reported on the grant in May 2023: (2)

The program aimed to reach 60,000 enrolments and 50,000 graduates by 31 July 2026. On 11 May 2026, COSBOA said it had 48,000 enrolments and 34,000 graduates, with 12 weeks remaining in the funded period. (3)

A Treasury spokesperson later confirmed that government involvement would end on 31 July 2026, in line with the grant agreement. The 2026–27 federal budget did not provide further funding. (4)

What did Cyber Wardens provide?

Cyber Wardens is an online learning platform that presents cyber security material through text, videos and multiple-choice questions.

Cyber Wardens Video Example

The platform displayed 17 courses, with estimated completion times of 10–60 minutes each.

Cyber Wardens Video Courses

In testing the platform, I was able to open a course, move directly to its final step and receive a certificate without viewing all of the course content or demonstrating that its recommendations had been applied.

Cyber Wardens Video Graduation

What commercial products appeared?

The platform displayed an offer for a Telstra device with 20% off McAfee.

Cyber Wardens Telstra Promotion

It also recommended the paid SMB1001 certification program.

Cyber Wardens SMB1001 Promotion

How was Cyber Wardens evaluated?

First Person Consulting was engaged as the program’s independent evaluator. The evaluation framework included marketing and engagement data, enrolments, graduations, retention, Net Promoter Score and qualitative participant feedback. (1)

Cyber Wardens Evaluation Methods

Participants were surveyed about how likely they were to take specified actions after completing the training. Most respondents selected “likely” or “highly likely.” (1)

Cyber Wardens participant survey results

The midpoint evaluation concluded: (1)

Overall, the data suggests that the Cyber Wardens program has built on the positive outcomes demonstrated in the first evaluation report and made progress towards intermediate outcomes.

What the disclosed evaluation did not measure

The documents released under FOI include participation data and self-reported survey responses. They do not include measurements of participating businesses’ technical security controls before and after the training. (1)

In my test, the platform did not require evidence that a business had implemented the practices taught in the course.

Opinion: Measure resilience, not participation

The Australian government is trying to improve the cyber resilience of small businesses at scale. The main obstacle, however, is not simply insufficient awareness or course participation.

The deeper problem is that Cyber Wardens separated training from implementation and verification. Enrolments, course completions and surveys about intended actions can measure reach and engagement. They do not establish that businesses implemented stronger cyber-security controls.

A stronger program would connect each recommendation to implementation instructions, acceptable evidence, proportionate validation, remediation and retesting. Automated tools could test externally observable controls. Screenshots, redacted logs and other evidence could be reviewed manually, while businesses with more complex environments could receive one-on-one assistance from qualified experts.

This would establish whether specific controls had been implemented. It would not, by itself, prove that those controls reduced cyber incidents or financial losses.

That distinction is important when the government recommends frameworks such as the Essential Eight or SMB1001. The Essential Eight is based on ASD’s threat intelligence, incident response, penetration testing and implementation experience. That provides a technical basis for its controls, but it is different from actuarial evidence showing how much those controls reduce the frequency or severity of losses among Australian micro and small businesses.

I could not identify publicly available actuarial validation specific to Australian micro and small businesses for either the Essential Eight or SMB1001. This does not establish that the frameworks are ineffective. It means their technical rationale should not be treated as proof of financial-loss reduction for every type of small business.

The government could strengthen its evidence by combining technical advice with de-identified incident and claims data from specialist cyber insurers, actuaries, brokers and incident-response providers. Insurance data also has limitations: it represents an insured population, may exclude unreported incidents and can be affected by policy terms and selection bias. It should therefore supplement—not replace—evidence from security agencies, independent research and participating businesses.

Course completion demonstrates that training was completed. Control validation demonstrates that protections were implemented. Incident and claims data can help determine whether those protections reduced losses.

A government program intended to improve cyber resilience should measure and report each of these outcomes separately.

References

  1. FOI 4282: Cyber Wardens Grant, Department of the Treasury, June 2026

  2. Labor to be grilled on $23 million grant for ‘Cyber Wardens’ program, News24, May 2023

  3. Budget uncertainty hangs over Cyber Wardens, SmartCompany, 11 May 2026

  4. Government involvement in Cyber Wardens coming to an end, SmartCompany, 20 May 2026