Heading image for How Australia can better show its cyber progress

What the image represents

The image captures the moment when a strategy’s reassuring language meets the question it cannot avoid: did it actually make Australia safer?

I wanted to understand a simple question: when officials update Australia’s Minister for Cyber Security on the national cyber strategy, what do they report as progress and success?

I lodged a Freedom of Information request for ministerial reporting on the 2023-2030 Australian Cyber Security Strategy. The release included a February 2025 submission to the Minister, The Road to Horizon 2. (1, 2)

The brief was prepared as officials began planning the strategy’s next phase. Its update on Horizon 1 is clear. Of the Action Plan’s 60 initiatives, it says 29 had been “delivered in full” or had “transitioned into a sustained work program”. A further 31 had “progressed”. Department-led and co-led initiatives in that group were “all on track for planned delivery timelines”.

Excerpt from the FOI brief showing Horizon 1 initiative status

The brief records actions including the Cyber Security Act 2024, ransomware measures, grants, incident-response playbooks, cyber exercises and work on obligations for nationally significant systems.

The released brief reports the status of initiatives: whether they are delivered, transitioned into sustained work, progressed, or on track.

Excerpt from the FOI brief showing Horizon 1 initiative status

Within this document, there is no corresponding list of priority national cyber risks, no stated level of acceptable risk, and no assessment of whether individual initiatives have reduced those risks.

That is not evidence that government lacks other cyber-risk advice or that the initiatives are ineffective. It is what this released ministerial brief shows about the information presented to the Minister to report strategy progress.

Opinion

I then asked myself a practical question: if Tony Burke had to defend the Cyber Security Strategy - after a serious incident, in an inquiry, or when seeking further funding - what could he say on the basis of the reporting set out in this released brief?

He could point to real work: legislation passed, grants awarded, playbooks prepared, exercises run, and initiatives delivered or on track. That is important evidence of implementation.

But could he also say which national cyber risks the Strategy was intended to reduce, whether the available evidence showed those risks were declining, and how that evidence should inform the next funding decision? This released brief does not answer those questions. I therefore prepared a point of view for Tony Burke proposing a national cyber-risk reporting model. (3)

Excerpt from the Point of View

The point of view I prepared for Tony Burke is deliberately conceptual. It is not a finished national measurement system. It sets out the questions that stronger reporting should answer: which risk is an initiative intended to reduce, what evidence would show progress, and what value is government receiving for its investment?

Those questions can be built into the design and reporting of cyber initiatives. The task will not always be simple: evidence will vary in strength, and not every initiative will have a direct, readily measurable national effect. But government can be clearer about the risk an initiative is intended to influence, how it will assess its contribution to risk reduction, and whether the expected benefit justifies the cost.

Excerpt from the Point of View

My own proposal has an important limitation. It does not yet link every initiative across the Strategy’s six shields into a complete, whole-of-nation story about risk reduction. That work would require more detailed analysis, better data and the perspectives of people who work across policy, operations, economics and cyber security.

Even so, it is a step in the right direction. A practical starting point would be to test the approach on one priority risk and learn from it. I would welcome other practitioners, researchers and policy professionals adding to the work - challenging the ideas, improving upon them and helping turn the concept into a credible national risk measurement and reporting approach.

References

  1. FOI Request, Benjamin Mosse, 15 June 2026

  2. 2023-2030 Australian Cyber Security Strategy - The Road to Horizon 2, Home Affairs, 2025

  3. A Call for National Cyber Risk Reporting, Benjamin Mosse, 26 August 2026