Next Phase of Australia’s Cyber Strategy

The Australian government is shifting gears on cybersecurity. As it enters the next phase of its 2023–2030 Cyber Security Strategy, the focus is turning to practical changes—browser-level scam blocking, deeper vulnerability research, and improving access to cyber insurance for small businesses and nonprofits.

Horizon Two Begins (2026–2028)

Home Affairs officially launched the second phase (Horizon Two) of the national cyber strategy. Along with it came a full status report on Horizon One, a priority roadmap for the next three years, and a new model for evaluating progress.

The strategy is built around six interconnected “shields,” which together are meant to form a multi-layered defense system for Australia’s digital infrastructure. Here’s what’s taking shape under this new phase:

Rethinking Cyber Insurance Access

One of the biggest concerns is the cyber insurance gap. Small and not-for-profit organizations often struggle to meet the technical standards required by insurers. Many can’t afford coverage, or they don’t qualify.

The government sees potential to step in—not to control pricing, but to improve access. It may look at ways to support smaller entities without distorting the market. The idea is to create a fairer path to insurance, especially for those most vulnerable to attacks.

Regulations Under Review for cybersecurity strategy

Another major point: regulations. Home Affairs is asking whether current laws are actually helping organizations become more cyber mature—or holding them back.

The goal is to spark a discussion on whether existing compliance requirements are too scattered or burdensome, and whether there’s room to simplify or align them.

Data in Motion and AI Risks

As AI systems grow in capability, so does the risk around “data in motion.” That’s the data moving through systems and across networks.

The strategy now includes a focus on understanding how sensitive data flows—especially into and out of AI models. With these models able to process data at massive scale, the government is planning stronger protections in this area.

Vulnerability Research Gets Backing

Security researchers—often working independently—have long called for better protections and recognition in Australia. The new strategy phase finally acknowledges this.

The government is looking at:

  • Legal clarity and protections for researchers
  • Incentives for businesses to adopt vulnerability disclosure policies
  • A national framework for safely reporting vulnerabilities

The message is clear: researchers are a valuable resource, and they shouldn’t be operating in legal limbo.

Browser-Level Scam Blocking

Another change coming in Horizon Two: a shift from large-scale threat blockers (like ISPs and banks) to browser-level protection.

This means more tools built directly into browsers to stop scams, phishing, and deceptive sites—before they reach users. The government wants to boost awareness and adoption of features like safe browsing and deceptive warning pages.

Focus on Not-for-Profits

Non-profits are also getting attention in this phase. Many rely on volunteers and don’t have large budgets for training or cybersecurity.

The strategy acknowledges this, stating that NFPs must still maintain strong security—especially since they often handle sensitive donor data. The plan includes support to help them build resilience without diverting funds from their core missions.

Bibi Zuhra
Bibi Zuhra
Bibi Zuhra has a Master's degree in public administration and a Certificate in Entrepreneurship from Santa Rosa Junior college (California). Bibi has worked in research & marketing, and in policymaking, and also has more than four years of experience as an SEO Content Writer, and news articles for e-commerce, tourism, business, education, and lifestyle. she believe words have the power to change the world, and she try to do that through her work.

Similar Articles

Comments

Most Popular