Loading

Horizon 2: Expanding our reach (2026–2028)

​​​​​​​​​​​​Horizon 2 of the 2023–2030 Australian Cyber Security Strategy (the Strategy) commences in 2026 and continues to the end of 2028. 

Since the launch of the Strategy in November 2023, the cyber threat environment has changed. In preparing for Horizon 2, we have considered the changes in technological, economic and geopolitical trends. We will focus on what matters most and be prepared to move fast where it counts.

Horizon 2 Action Plan

A new program of work to uplift Australia’s cyber maturity under Horizon 2 was announced by the Minister for Cyber Security, the Hon Tony Burke MP, on 11 June 2026.

This program is set out in the Action Plan for Horizon 2 of the 2023–2030 Australian Cyber Security Strategy  (the Horizon 2 Action Plan). It details 19 actions and 64 initiatives for government to deliver by the end of 2028 to achieve three key objectives: 

  • Enabling our workers to be our strongest defence, our ‘human firewall’.
  • Protecting our critical infrastructure and government systems.
  • Shaping, securing and embracing digital technology.

The Horizon 2 Action Plan sets out a program of meaningful, targeted measures which will improve the lives of everyday Australians. The actions and initiatives in the Horizon 2 Action Plan will be led or co-led by 12 different Australian Government agencies in partnership with industry, and supported by numerous contributing agencies.

The delivery of Horizon 2 requires continued co-design, collaboration and support from industry and community partners.

Further information about how we delivered Horizon 1, including the Horizon 1 Action Plan,​​​​ the 2025 Review, ​and how this work informed the development of Horizon 2, is available at Horizon 1: Strengthening our foundations (2023–2025).

Horizon 2 fact sheets

We have prepared the following fact sheets with targeted information about Horizon 2 for members of the public, community groups, not‑for-profit organisations, businesses and industry:

Horizon 2 consultation and engagement

Partnerships with industry, businesses and communities remain at the heart of the Strategy, as the challenges we face over the next Horizon cannot be met by government alone.

Horizon 2 has been developed through a wide-ranging consultation process involving over 170 public submissions, three public town halls and twelve co-design roundtables with key industry partners and stakeholders. To view the Horizon 2 Policy Discussion Paper and public submissions, see Consultation on developing Horizon 2 of the 2023–2030 Australian Cyber Security Strategy.

We remain committed to ongoing collaboration with our industry partners and stakeholders as we work to develop, implement and deliver the initiatives of Horizon 2. This will include holding regular public town halls to allow industry partners and members of the public to hear directly from government about Horizon 2 and find out how to get involved.

Horizon 2 public town hall

We held a Horizon 2 public town hall on Thursday 2 July 2026. This was a chance for members of the public to hear directly from government about the new program of work under Horizon 2.

A recording and transcript of the Horizon 2 public town hall are below. We are also compiling responses to the broad range of questions asked during the town hall, which we will upload here as soon as possible.​

Video recording: Thursday 2 July 2026 ​

 

Greta DOHERTY

We're providing today an overview on the recently launched Horizon 2 Action Plan under the 2023–2030 Australian Cyber Security Strategy. It's lovely to have so many people here and great to see so much interest and engagement with Horizon 2. My name is Greta, I'm the First Assistant Secretary of the Counter Foreign Interference, Cyber and Technology Division in the Department of Home Affairs. My job title is very wordy, but the short version of that is that my team is responsible for driving implementation of Horizon 2 for the Australian Government. And in doing so, we work across government to make sure we're bringing a coordinated and joined up approach.

So I've got members of my team here today and also really pleased to let folk know that we have broad government representation, including from Australian Signals Directorate, Department of Foreign Affairs and Trade, Department of Climate Change and Energy, and a range of subject-matter experts across Home Affairs, including from the National Office of Cyber Security. We've got our critical infrastructure experts, our emerging tech experts, all of the folk are here in case we get into some detailed questions.

Before we start, I would like to acknowledge the traditional custodians of the lands that I'm on today, which is in Canberra. So I pay respects to the Ngunnawal people and also acknowledge other families with connection to this land. I pay my respects to elders past and present, and elders and traditional custodians of the many countries and lands on which everyone is joining us today. And I'd also like to extend acknowledgement and respect to Aboriginal and Torres Strait Islander peoples who are with us here today.

Just a little bit of housekeeping before we kick off. So today's session is being recorded and transcribed and it will be made available on the Home Affairs website, which is a good reminder to me to be a very smooth presenter. To ensure everything goes well, all attendees are muted and cameras are turned off, but we do want this to be an interactive session. So we encourage you to please post questions in the Slido throughout the event. And there's details on the screen for how you can do that, and we'll respond to those at the end of the presentation.

For anyone who's joining us for the first time or catching up via the recording, the Australian Cyber Security Strategy was released on the 23rd of November 2023 after extensive consultation. Its vision is simple but ambitious, which is to make Australia a world leader in cyber security by 2030, ensuring our economy and society can prosper and recover quickly from cyber incidents. The Strategy is built around six shields, each representing a layer of defence that keeps businesses, citizens and governments safe. The Horizon 1 Action Plan outlined a phased approach to delivery over three horizons. So we've just come off Horizon 1, which was about strengthening our foundations. Horizon 2, which is the focus of today's discussion, is about expanding our reach. And Horizon 3 is where we really reach for Australia being that world leader in cyber resilience. The transition points between horizons are really intentional review moments, a chance to test where the Strategy remains fit for purpose in light of emerging tech, economic shifts and global events. And you probably don't need me to tell you that at the moment, all of those things are happening in concert and that review point is particularly critical when we're seeing changes in capabilities almost on the daily.

Just to go back in time a little bit in terms of where we're at for Horizon 2. So the Horizon 2 Action Plan was officially launched by Minister Tony Burke on the 11th of June and it was supplemented in the recent 2026–27 budget with funding of $89.3 million to deliver on initiatives in the Strategy over the next few years. That investment is on top of the $586 million that was already committed when the Strategy was launched back in November 2023. So really, as I said before, Horizon 2 is about building on the foundations we've already put in place and seeking to expand those. Horizon 2 has been shaped with industry and we thank everyone who has been involved in the conversation. We do that simply because we know that government can't do this alone and neither can industry. So we're focusing our efforts where they matter most, moving quickly where it counts, and continuing the strong partnership of engagement that we've built up over the course of the Strategy. At the centre of all of our efforts are Australian businesses and citizens, because lifting national cyber resilience is truly a whole-of-nation effort.

Before we go into the detail of Horizon 2, and I'm going to hand over to a colleague to talk about that so you don't have to listen to me for the full time, I'm just going to quickly take a step back and look at what we achieved through Horizon 1 to sort of set out those strong foundations from which we are building.

So we started the process with listening. A year ago in July 2025, we released a policy discussion paper to get views about where Horizon 2 should focus. And we received over 170 submissions from across the board – from industry, small business, academia, the not-for-profit community and all levels of government. And it's super exciting to know that we have such a broad range of people here today for this session, because that shows ongoing engagement and knows that we've been talking to the people who are interested and who can help take it forward. After that broad engagement, we went a step further and worked directly with stakeholders to co-design the next phase. So this included three public town halls and then 10 more targeted roundtables to really test and refine those ideas. The two-phased approach – so with the broad consultation followed by co-design – was all about making sure we were staying aligned with industry and community and focused on the outcomes that will make a difference.

If you're interested, alongside the launch of Horizon 2 last month, we also published the 2025 Review of Horizon 1. It brings together what we've delivered across all 60 initiatives, as well as the key lessons and insights that we learned along the way. It's a substantial piece of work. So perhaps after this session, if you have a moment to make a cup of tea, I encourage you to sit down and have a look. It's available on the Home Affairs website. I guess the key takeout from the review of Horizon 1 is that it shows exactly what's possible when government, industry and the broader community work together towards shared goals.

So some highlights from Horizon 1. Super proud of the team and the cross-government team because we were able to deliver on all 60 initiatives on time and on budget. So a couple of highlights across the shields. Shield 1 is around strong businesses and citizens, and that's really about supporting Australians to stay secure in their everyday lives. You will have seen the 'Act Now. Stay Secure.' campaign. It's reached millions of Australians, helping lift awareness of simple steps that people can take to protect themselves. We also focused on reaching people in ways that work for them. For example, through grants, over 200 community organisations were able to translate cyber security advice into practical and culturally relevant support for communities. We know that when things go wrong, support matters. And it was great that around 120,000 victims were able to receive tailored help through IDCARE. And we've seen ongoing strong take-up of secure services as well, with more than 15 million Digital IDs used through myID. And at the operational end, Operation Aquila carried out 38 disruptions against major ransomware groups like LockBit, contributing to broader international efforts of takedowns and sanctions.

Shield 2 around safe technology is about shifting the burden of cyber security away from individuals and onto the systems and products that people rely on. A key step here was the 2025 rules for smart devices. This introduced a mandated secure-by-default baseline for consumer smart devices so that they're safer from the moment people start using them and that responsibility for safety moves to the companies best placed to manage risk. We've also been working really closely with industry on a voluntary smart device labelling scheme, which will give consumers clearer information and reward companies that invest in stronger security.

Under Shield 3, which is world-class threat sharing and blocking, this is where we really start to see the power of collective defence in action. A key part of that is the Australian Signals Directorate's threat sharing platform. That platform has distributed nearly 3 million indicators of compromise to around 450 partner organisations. And because that sharing happens machine-to-machine, it allows partners to block threats in near real time, often before they go anywhere near end users. We've also strengthened collaboration through the National Cyber Intelligence Partnership, which has brought together industry leaders and cyber experts to share technical insights and best practice. Capabilities through that partnership have helped streamline intelligence sharing, scale up threat blocking, and better integrate government and industry efforts. Another great example under Shield 3 is the Health Cyber Security Network, it now has 60 members and covers more than 600 health facilities, a sector that holds some of the country's most sensitive data. The health network has made it much easier to share threat information, patch vulnerabilities faster, and identify system-wide gaps that wouldn't have been visible before. And more broadly, these pieces of work all reflect an important shift from organisations sort of defending themselves in isolation to a way more connected and collective model of resilience.

Shield 4 around our protected critical infrastructure is all about safeguarding the essential services Australians rely on every day. We've made strong progress here through reforms to the Security of Critical Infrastructure Act, the SOCI Act as it might come up later, along with enhanced requirements for Systems of National Significance. Together, these changes mean owners and operators are now taking a much more structured approach to identifying, managing and reducing cyber risks. We've also seen real value from the National Cyber Exercise Program, with 97% of participants reporting meaningful insights into their preparedness. That's important because when a cyber incident does occur, preparation and clarity will help us all recover faster, respond faster and recover more quickly as well. Another key step here was the launch of the Systems of Government Significance regime in July 2025, giving government much better visibility over its most critical digital systems and functions so we can prioritise their protection and reduce the risk of catastrophic impacts.

Next, we're moving on to the last two shields, 5 and 6. So Shield 5 is our sovereign capabilities, about building Australia's own cyber strength, our people, our ideas and our innovation. Some quick examples here include the Cyber Workforce Summit and the Cyber Workforce Playbook, which are giving employers practical tools to attract, retain and grow cyber talent. Importantly, we're also making sure that the workforce is more diverse and inclusive. New inclusive recruitment guidance is helping organisations of all sizes to bring in women, First Nations people, and neurodiverse candidates into cyber roles. Taken together, these efforts are making sure that Australia has the skills, capability and the innovation base that we need to stay secure into the future. And finally, Shield 6, resilient region and global leadership, which recognises that our cyber security efforts don't stop at our borders. Through the SEA-PAC cyber program, we've been supporting regional partners directly, including through 12 RAPID deployments, which are rated very highly by our Pacific partners. They provide hands-on support during major cyber incidents. We've also been building preparedness across the region. DFAT's Cyber Exercising Program has delivered 16 table-top exercises with Southeast Asian partners, helping countries strengthen their incident response capabilities before a crisis hits. And at a global level, Australia has been playing a leading role at the United Nations, including helping to establish a new permanent UN Global Mechanism on cyber, which is about reinforcing the rules, norms and governance frameworks that keep the digital environment open, secure and stable. This work all contributes to a safe and interoperable global digital system which underpins regional stability and supports Australian businesses operating internationally.

So building on those Horizon 1 foundations, stakeholder feedback was the other major input shaping Horizon 2. And as I said before, many of you who are here today contributed to that process. A few consistent themes really came through with our feedback on Horizon 2. Those include the need to better support small and medium businesses and the not-for-profit sector, the need for a continued focus on growing and strengthening the cyber workforce, including skills, professionalisation and diversity, and the importance of maintaining strong collaboration between government and industry, as well as a clear call for greater transparency and better ways to measure progress. I want to take a minute to thank again everyone who contributed, whether that was through a formal submission, coming to a workshop, or any of the ongoing conversations that you've been having with any of us across government. That input has really been critical in making sure that Horizon 2 is grounded in real experience and focused on the challenges that you're facing every day.

As I said before, it's been two and a half years since we released the Strategy and the Horizon 1 Action Plan. And again, no one needs me to tell you that the cyber threat landscape has shifted significantly since the launch of that Strategy. We're seeing all of the media reporting and trends in the media backed up by a growing body of evidence with more than 40 public reports each year from government and industry tracking trends. We know the cost of cyber crime is continuing to rise and we know that at the same time threat actors are becoming more sophisticated, including through the use of AI and automation. All of this reinforces something that everyone here will know, which is this is not something we can treat as a 'set and forget'. Our strategy and our responses and our partnership work need to continue to evolve and stay responsive. So thank you for coming on that journey with me. Hopefully some of that is familiar to folk who've been part of the process. What did we do with all of that? I'm going to hand over now to my colleague Lauren, who's heading up the Cyber Policy and Programs Branch here at Home Affairs, to talk through in a bit more detail the actions that we'll be delivering under Horizon 2 of the Strategy.


Lauren DREW 

Thanks Greta and hello everyone. I'm Lauren Drew. I am currently Acting Assistant Secretary for the Cyber Policy and Programs Branch at Home Affairs. So like Greta has indicated, the Horizon 2 Action Plan is now live and available on the Home Affairs website. And if you haven't explored it in more detail and have come here to hear more about it first, I really encourage you to go and engage with that document afterwards. But in short, the Horizon 2 Action Plan sets out a program of targeted, practical measures that will make a real difference for Australians, delivered in close partnership with industry. Altogether, it includes 64 initiatives across 19 action areas to be delivered through to the end of 2028. Those initiatives are organised around three key objectives. The first is strengthening our people, so our workforce becomes our strongest line of defence, or what we call the 'human firewall'. Second, protecting our critical infrastructure and government systems. And third, shaping and securing the technologies that Australians rely on every day. Look, I'm not going to step through all 64 initiatives today, but I will highlight some of the key ones under each objective. And then we'll open it up for questions where we can go into more detail.

So under Objective 1, we will reinforce the 'human firewall' as our nation's first line of cyber defence. We will give support to workers to help uplift the cyber resilience of small and medium businesses, given their centrality to a thriving economy and supply chain security. Establishing the new CyberSmart program, which is a key action under Objective 1, will develop a simple, adaptable and fit-for-purpose cyber security standard for small and medium enterprises to help uplift their cyber resilience. Those that are certified as meeting the standard will then be able to display a trust mark in their communications with customers and suppliers. Another key action under Objective 1 includes uptake of CyberSmart through government procurement and regulatory levers. This initiative will also help to strengthen supply chains, while keeping white tape at a minimum. We will build on the 'Act Now. Stay Secure.' campaign to deal with emerging threats, including AI. And we will deliver tailored cyber education programs to support diverse cohorts and further engage priority communities. Consultation to inform the development of the Strategy found that vulnerable communities, including neurodivergent groups and people with disabilities, faced really unique challenges when engaging with cyber security advice and guidance. While awareness-raising activities will seek to reduce the risk of vulnerable cohorts falling victim to cyber crime at a national level, this program will help to expand the national cyber security awareness campaign to uplift security outreach and literacy among the Australian community. It also recognises the ability of community leaders to deliver trusted and lasting messaging to priority groups to ensure cyber security information is appropriate and is accessible to all Australians. We will also review the cyber security regulatory environment so we can get a clear picture of the regulatory pressure points impacting industry, and work across government in partnership with industry to identify opportunities to centralise cyber incident reporting. The outcomes of this review will then help to support a 'tell us once' experience through a single cyber reporting interface. And finally, we'll take the translation of a technical subject global by developing an international ransomware standards framework. This framework will set practical and achievable global benchmarks for cyber uplift.

Under Objective 2, we will uplift cyber maturity by strengthening the security, the reliability and the resilience of critical infrastructure and government systems. This will be achieved through a proactive investment-led approach that enhances resilience across critical assets and their supply chains. Some of the key actions under Objective 2 include addressing drone security risks and assessing our subsea cable security posture, exploring amendments to the Directions power in the SOCI Act to better protect critical infrastructure, and strengthening supply chain resilience through exercises held by the National Office of Cyber Security, or NOCS. These exercises will be held across critical infrastructure and business to analyse critical interdependencies and vulnerabilities across Australia's critical infrastructure and government supply chains. And it goes without saying that this will also help to develop scalable toolkits and to test preparedness and national coordination arrangements. Objective 2 will also seek to strengthen logging and monitoring standards across government and critical infrastructure, strengthen government procurement arrangements and Systems of Government Significance, and deepen national, state, territory and local government collaboration through a National Cyber Security Compact. This Compact will enable all levels of government in Australia to collaborate on cyber security initiatives and escalate key issues at a national level. Importantly, the Compact will serve as a mechanism for meaningful collaboration and coordination with states, territories and local government on cyber security.

Moving to Objective 3, we will complement the human firewall by reducing cyber risk at its source – that is, the technology environment that Australians rely on each and every day. This will ensure safe adoption becomes the default and includes initiatives such as embedding security into the design, deployment and operation of connected technologies, strengthening protections for data that matters most, and anticipating technology risks. Other key actions under Objective 3 include assessing legislation and policy to ensure industry and the Australian Government can collaborate at speed on defensive cyber measures, supporting telcos and other upstream to block threats at speed and scale, and embedding security into connected technologies in homes and businesses, such as routers, operational technology and consumer energy resources – this will ensure Australian households and small businesses have more confidence in the cyber security of the devices they use to connect to the internet every day. We will also make security the easy choice for consumers through a smart device labelling scheme. We will prepare government and critical infrastructure for emerging technology, including developments in AI and quantum. And we will uplift data security across the Australian economy through the finalisation and promotion of a risk-based framework for datasets of national significance.

I'll pause there and hand across to my colleague, Rebecca Kerlett, for questions and answers. Thanks, Bec.


Rebecca KERLETT

Thanks, Lauren. I'm hoping I won't have to provide too many answers. I'm here to facilitate them, but I'm happy to look at the questions specifically. Before we hit the Q&A portion of today's event, I just wanted to underline the immense amount of attendance we have here today. We have over 490 attendees. I'm sure every single person on the line has a question because that's how these things always work. But it's unlikely we're going to be able to answer everything today. We will take stock of questions and answers, and those that we can't get to, we will aim to answer those out of session. We've included a QR code for access to the Slido and again reiterating what the team has mentioned in the chat that those will be provided anonymously. If you are having dramas accessing Slido or you're happy to throw your questions straight in the chat, please do so and we'll aim to try and balance out our attendance to both. Before I do pass back to our fabulous presenters, I'll take a moment to acknowledge the range of questions that we have received on Slido already and in the Teams chat as they've come through. We can see a range of questions that are touching a number of thematic areas across cyber security, and in no specific order, we can see quite a bit of interest on the implications of artificial intelligence as part of the Horizon 2 program. There's some queries and statements in there around how we can sustain and build on existing engagement and partnerships between government and industry. I know that's something that Greta especially touched on in her opening remarks and very happy to go in more detail through that. There's some really pointed questions around workforce professionalisation and how we can uplift our sovereign capability. So again, looking forward to coming back and addressing those. And there's also pleasingly some remarks around how we also continue to work across critical infrastructure and government.

So we might start almost alphabetically with artificial intelligence. Lauren, I haven't given you much of a break from your remarks as part of the presentation, but I might hand to you first. We have covered this off in your opening remarks and in some of the overview that Greta provided, but I was wondering if you might be able to give us an overview of how AI and engagement on AI as part of the Horizon 2 program will be supported by ongoing and strong industry partnerships as part of this work. If others on the call who are part of this policy agenda of government would also like to jump in once Lauren and Greta have finished their response, we'd be very pleased to also take your support to that. So over to you, Lauren.


Lauren DREW

Thanks, Bec. And yes, I think it's safe to say that AI permeates everything. The key for us here is, in terms of Horizon 2 and recognising that Horizon 2 runs across a three-year period, we're likely to see quite a significant change over that period of time in what we're actually dealing with from both a technical, from a security and from an opportunity perspective as well. So Horizon 2 has been developed to wrap around AI. There's obviously key initiatives that we've included on AI in the Action Plan, but I think it's safe to say that we can essentially have AI as a component of every single initiative that we've included in under Horizon 2. But Greta, was there anything else that you wanted to add there specifically?


Greta DOHERTY

Thanks, Lauren, and thanks for the question. I can see there's a few questions, as Bec said, specific to AI. I think there's a couple of specific actions in the plan that we can talk through, but what we've proposed in Horizon 2 was obviously drafted prior to some of the recent capability jumps that we've seen, but I guess shows that the way that Australia was able to respond and has been able to support industry in recent months shows that we've kind of got the framework and the architecture right there. So what we do going forward, I think will build very much, as I've said before, on what we've done in the past. And that includes things like leveraging our really strong relationships with critical infrastructure post some of those AI capability gaps. We were able to facilitate briefings between frontier AI labs and some of our most trusted providers through the Trusted Information Sharing Network. We were able to get – when I say we, our colleagues at the Australian Signals Directorate – were really quick in being able to get up and out practical advice, both for CISOs in organisations as well as for individuals, around what to do in the face of frontier AI capability jumps and what it might mean for vulnerabilities. So we have sort of targeted information sharing mechanisms. We've got really good engagement on cyber.gov.au already that ASD has been able to draw on to sort of take that information further. And then we've been able to iterate and adapt as different things change, as they seem to do almost every day. I guess specific to the way we're engaging going forward and, you know, to the question, not just talking about Copilot, but what does agentic AI mean for the way that we do cyber security? We're assessing the suitability of our existing crisis management frameworks in response to major AI incidents – so really putting those systems through their steps, and we've already started that at a government level. So looking to test what is there and how well it responds – continuing to collaborate with trusted and private partners on AI threats, including through some of our critical infrastructure and other mechanisms, as well as work that Australia is leading through Five Country Ministerial so that we can tap into international insights and engagements. And I've seen a question, so I'm just going to quickly pivot to post quantum, but post quantum represents, I guess, a capability jump beyond even frontier AI. So we're getting ready for that by pulling together and disseminating actual guidance for both government and industry in terms of what you need to be doing to get ready for post-quantum cryptography. So that's a couple of the examples, but I really just want to say that all of the actions that we're taking forward build on the great work that's underway through partners with ASD, through DFAT's international engagement piece, and then through our colleagues here at Home Affairs and engagement with critical infrastructure. And then I don't know if anyone else wants to jump in. Or we can move on, Bec.


Rebecca KERLETT 

We can move on as the ringleader of the awkward pauses between people being allowed to jump in or not. I think that was awkward enough. Lauren, I might just pass to you as well off the back of Greta's comments. This is a continuation of our discussion on industry partnerships and Greta's provided us that lovely overview of the ecosystem of all the interlocking parts across government and the opportunities to remain engaged on Horizon 2. But as part of your day job, you are involved in the program area that is delivering on a number of Horizon 2 initiatives in partnership across government and you have a great perspective on what that looks like in practice. And thinking through how we have some of these forums set up for ongoing engagement at a high level on cyber security, I was wondering if you could provide us maybe a little bit of a slice of life of what that engagement often looks like in practice.


Lauren DREW

Sure, thanks Bec. Well, as with the development of Horizon 1 and the significant public consultation that was undertaken to support Horizon 2, and as Greta and I have outlined during the presentation, we cannot do this alone. Partnerships are absolutely integral to our work on Horizon 2 and co-design with trusted industry partners is a thread that runs right throughout the Action Plan. So there's lots of opportunities to get involved in the co-design with my team. If there is something specific that anyone on the call here today wants to engage on, please contact the team. But in terms of day-to-day we've already started engaging with industry groupings – particularly, I would have to say, not-for-profit and small to medium business groups have been really energised about Horizon 2, which is fantastic to see. And that work that we're progressing under the Action Plan and the initiatives that we outlined will be absolutely, those partnerships will be absolutely key to being able to deliver something that is the right size and the right shape, and addresses, well, supports cyber security uplift and maturity development without overburdening small to medium businesses who, you know, may not have the resources or the capabilities that they might need to do the full uplift. So initiatives such as the community of practice that we are establishing for not-for-profits will be really key to trying to deliver practical advice in a really tangible way and to build trust with key stakeholders from those sectors. But like I said, my team is already engaging right across the Horizon 2 Action Plan with industry stakeholders and international partners as well as our whole of government colleagues. So if there are specific areas that anyone would like to engage with us on, it is a call to action to please reach out to the team.


Rebecca KERLETT 

Thanks, Lauren. And it is a long horizon. I'm sure the end of 2028 will be here before we know it, but we do have a lovely long lead-in time across the next, now, two and a half years to be collaborating and implementing the initiatives highlighted in the Action Plan. I might use this as a segue, a bit of a warm handover to our colleague Nick from ASD and give you time to find the mute button while I throw to you. I wanted to also get ASD's perspective on partnerships because the relationship between Home Affairs, ASD and others in reaching out and collaborating across industry and government is integral to the success of the cyber security strategy, as well as broader cyber security and resilience uplift activities more broadly. Nick, I wanted to ask if you wanted to comment from ASD's perspective on those partnership arrangements before I throw the question in the chat on PDNS and CTIS to you. But, Nick, over to you.


Kearton, Nick Mr 

Yeah, thanks Rebecca. Can you hear me okay? Excellent. Yeah, so look, thank you for the lead on partnership and it's something that's really important to us. I think just before I go into that, I wanted to quickly address another comment if it's okay, just regarding advice on post-quantum cryptography, similar to the plug a little bit earlier around AI. There's a suite of documents and advice available via cyber.gov.au So it's worth having a bit of a dig through there. We'll continue to kind of provide that advice as things evolve. Regarding partnerships, yeah, industry partnerships are really critical to us. The ASD partnership program continues to expand. There's a lot of detail about that on cyber.gov.au, but it provides opportunity for us to engage with industry, share knowledge, share threat intelligence. There's a pathway for home partners, small to medium business and network partners. So there's a whole range of things and services, products, advisories available under that. So again, I'd encourage you to look through cyber.gov.au. I think critically too, we're really, really focused at the moment, you'll note in here, there's
in Horizon 2, there's a bit of reference to the Essentials series. I noticed a comment in the chat there too, and that's something we're really deeply engaged with industry on currently in the consultation phase of that, which is happening, I think, through to the end of July off the top of my head, but I could have that wrong. So yeah, the partnership angle is critical to us. There's a whole lot of information on cyber.gov.au. It's obviously cyber's a shared responsibility and something that we're really eager to engage on.


Rebecca KERLETT 

Lovely, thank you, Nick. And in the spirit of cross-government collaboration and support, I would like to open up another potential awkward pause, but space for other partner agencies to jump in if they also wanted to provide a comment on partnerships before we maybe duck down a little bit more technical. No, excellent. Okay, well, Nick, I might call you back so you can keep your camera on because this one is for you as well. So we have had a question around what happened to the Protective Domain Name System Cyber Threat Intelligence Sharing feed – this seems to have dropped off since late last year. Is there any additional detail you'd like to provide in response to that one?


Kearton, Nick Mr

I might need to take that one on notice, I'm sorry. Have we got the details for whoever's asked that question? I'm very happy to come back with a little bit of information there.


Rebecca KERLETT 

Yep, we will take that on notice and we'll provide that as part of the package response that goes up. Thanks, Nick, and thanks to the person who asked that question. We might go into more broadly – and Lauren, this is one for you – we do have a supporting area from Home Affairs who unfortunately can't be on the line today, but –


Kearton, Nick Mr

Terrific.


Rebecca KERLETT 

– we're looking at investments into domestic cyber industry growth and cyber startups, noting it's a broader question around investments and grants and when things might be available and when. Is there an overarching response you can provide on grants that might be relevant to that program? And noting as well that anything more specific, we will take on notice and come back to our audience.


Lauren DREW

Thanks, Bec. So I will note that in relation to action item 5.3 in particular, that Home Affairs is working closely with the grants hub within DISR to determine next steps for the proof-of-concept round. Anything beyond that one though, I will need to take on notice, noting that we don't have the appropriate rep on the line here today. On grants more broadly, though, I will note that in developing the package of initiatives for Horizon 2, government gave really careful consideration to outcomes of the 2025 Review of Horizon 1, as well as the views that we received through over 170 submissions that Greta outlined earlier in response to the Horizon 2 policy discussion paper. So while specific grant programs, some of them, had concluded by the end of Horizon 1, the government does remain committed to supporting small and medium businesses, in particular, not-for-profits, community organisations. So the government is still funding a range of initiatives to support smaller entities under Horizon 2, including and principally driven through the CyberSmart program, which includes a tailored small entity cyber security standard and certification regime that I outlined earlier to uplift cyber resilience across the whole of economy. Thanks, Bec.


Rebecca KERLETT 

Thanks, Lauren. And I'll note that the cobwebs seem to have been shaken out from people asking questions because we've had a massive uplift in questions coming through on Slido. Greta, this one's for you. With regard to looking at the uplift of consumer end devices, including things like routers and smart devices, noting existing work on that has been fantastic, but also energy devices like inverters for solar batteries, air con and so on – would you like to provide some comment on what potential uplift activities we would be looking at for those sort of devices or infrastructure and provide a comment generally against how that fits into our focus on ongoing internet-of-things connected devices?


Greta DOHERTY 

Yeah, thanks. Thanks, Bec. And thanks for the question, whoever asked. It is a great question. But we have had, as you point out, a really intense and targeted focus on consumer-grade devices, and consistent with undertakings under the Cyber Security Act, we've committed to co-design with industry a security standard for those consumer-grade edge devices like routers and modems. But that is really underpinned by a range of activities across other kinds of technologies that you pointed out in the question, so I can go through a couple of those. Really looking at exploring options to uplift the security of IoT operational technology. So how do we secure the systems that drive the things in industry is a piece of work that Home Affairs is going to be taking forward under Horizon 2. In terms of cross-government efforts, Home Affairs and a range of others will be working with the department whose own secretary says it's the department with the long name, so I won't attempt to say it, but the department that includes transport, to introduce new national road vehicle cyber security standards consistent with obligations to harmonise with international vehicle regs. So that's another important, I guess, piece of technology that we're really looking to secure there so that people can trust digital products and platforms. To the question specifically about solar and the like, DCCEEW is taking the lead on a national approach to designing cyber security for consumer energy resources, and that's through work that's being undertaken through the Consumer Energy Resources Roadmap. And again, that's a whole-of-government piece across DCCEEW and including Home Affairs and ASD colleagues. So that's sort of, I guess, an overview of what we're doing in a domestic setting to make sure that all of the devices and the pieces of technology that Australian individuals and communities and businesses engage with every day are as secure as they can be. On an international level, we're continuing to track what our international counterparts are doing to make sure that Australian regulation aligns with that best practice and it's fit for purpose. So there's quite a significant body of work underway there. Also, continuing the national voluntary labelling scheme for the cyber security of smart devices that we started and that we've alluded to also under Horizon 1. So really driving that piece of work forward. Thanks, Bec.


Rebecca KERLETT

Thanks very much, Greta. Might change tack a little bit. There's a number of questions going to the role of ASD and Home Affairs around cyber security and engagement more broadly, as well as the experience of incidents –
you'd think after a few years I could say incident – cyber security incident responders when a breach or an incident does occur. I know we have representation from the National Office of Cyber Security on the line. So Matt, I'd love to throw to you for a broad comment on how Home Affairs and ASD work together on the consequence management phase of an incident leading from the initial technical response. And if you would like to provide any commentary on what industry or others might expect when engaging with the National Office when those things do occur, that would be much appreciated. And before I go on mute, of course, opening up the line to our colleagues from ASD once Matt has provided his overview to also jump in. So, over to you, Matt, please.


Matthew WONG

Thanks, Bec. Starting off, here in the National Office of Cyber Security, we manage the cyber security consequences of significant cyber security incidents. So we work really, really closely with ASD, hand in glove with ASD on nearly all incidents, particularly with significant cyber incidents. Things may start off very – could be a very technical type response, but quickly escalates to, you know, in the public domain. Or there are consequences, like unfortunately we see with a lot of data breaches recently, and having that consistent messaging to potential victims, but also sort of onwards reporting to other regulators like the Privacy Commissioner or through the Passport Office or depending on the type of information that is sort of disclosed out there. So I think we work really, really closely together in terms of how incident responders would engage with us. It's sort of that similar process – you would report that cyber incident to 1300 CYBER1 or cyber.gov.au and then engage with us and/or we may proactively engage with you, particularly if we see something in the media or get a tip from another agency where there may be an incident just to see if you need that assistance with consequence management. Sometimes it may not be directly with your CISOs, it could be with your media folks, your government relations folks, or your legal folks, or your MSP, just about how to manage some of those consequence parts of the incidents. We will work with you very closely. We want to partner with you. Engagement with us is voluntary. So we're not necessarily going to tell you what to do, but we can give you some tips on how to manage it and how we can work closely together, particularly across the ecosystem, across government. And one of the key things that we found working with victims is that coming through the NOCS we can streamline some of those engagements with governments. So rather than you as the victim reaching out to the Privacy Commissioner or to your state and territory government or the education department, we can actually help you conduct what we call a coordination call and get the right players in the room. So to make it more efficient, you can engage a selective group of people at once rather than ten groups ten times. So that's some of the efficiencies we've seen with engagement with the NOCS. But I might hand over to ASD if they would like to provide their perspectives as well.


Kearton, Nick Mr 

Thanks, Matt. I think that's a really good summary of it, I suppose. I'd just like to kind of clarify ASD's role in incident management and use this as a bit of an opportunity to plug the need to report quickly. So, I mean, I suppose fundamentally ASD's role, we're here to provide technical incident response advice and assistance and to support on public comms. So –


Matthew WONG 

Yes.


Kearton, Nick Mr

– Matt alluded to, but we receive a lot of reporting through cyber.gov.au. We've also got the 24/7 cyber security hotline, 1300 CYBER1. But yeah, our role is fundamentally around providing that response, advice and assistance. Home Affairs obviously deal with consequence management. I think the other couple of things I'd just be keen to note in there is the importance of reporting through to us and our role in incident response and management. It helps inform a broader cyber security picture at a national level. And that's something that's really critical to understanding and we try to share that advice through products like the Annual Cyber Threat Report. I'd also just be really keen to note that ASD's role in this – we're not a regulator, we are here to help. We've also implemented things like limited use, which provide additional protections to those who are reporting through to us. So yeah, just to clarify, I suppose, we do very much work hand in glove with the National Office for the Cyber Security Coordinator. But yeah, our fundamental role is in providing that advice and assistance.


Rebecca KERLETT 

Thanks, Nick and Matt. I think over the last few years, there's been a strong effort from both agencies and across government to clarify those roles when an incident does occur. And really grateful that you've both continued to reiterate that and to provide that overview to the audience today. This is our last question before handing over to Lauren to end our town hall. With respect to the amount of questions that have come through, particularly in the last 15 minutes, I will reinforce that we are taking stock of those and we will consider and provide a more fulsome response back, including for those ones that we have taken on notice. And we remain very grateful for the audience participation because it's also a great indication of what matters to you and that will help us deliver a stronger Horizon 2 program. So Lauren, can you please round us out with a response to a query around the expected timeline for the ransomware guide, which was to be delivered as part of Horizon 2. I think we're speaking more broadly there to the global standards framework. Apologies if I've misunderstood the question from the attendee who asked it, but what a great opportunity to speak to the global standards framework. So over to you, Lauren, to answer and then to take us home.


Lauren DREW

Thanks, Bec. And it was remiss of me when we were talking earlier about partnerships to not recognise the really strong partnership that Australia has formed with over 70 countries through the International Counter Ransomware Initiative. So the global standards framework, which is being currently developed in consultation with members of the Counter Ransomware Initiative – we anticipate that that will be finalised this year. So it's a really early deliverable for Horizon 2 and that has shown a really strong uptake from members indicating their early support for a global standards framework to provide really tangible, practical uplift measures to help countries baseline their security, cyber security, and to encourage continued maturation of their settings. So a really exciting piece of work that should be coming to finalisation and full rollout by the end of 2026.

One further point too is we've had a query around how do we contact the team for partnerships. So the team will put the email address in the chat but you can email us at CSSH2@homeaffairs.gov.au. So with that, I really would like to thank everyone's time, everyone for donating, giving us your time today, and for the valuable insights and questions that you've shared throughout this session. Your engagement, whether it's through town halls like this one, written submissions, co-design workshops, is really what keeps the Cyber Security Strategy grounded in the realities of our rapidly changing environment. So as Greta mentioned, Horizon 2 is about expanding our reach and deepening collaboration. So a little bit of a call to action, please keep co-designing with us. We will continue to collaborate with industry, community, across all levels of Australian government, to deliver the outcomes that matter most to Australians. There will be industry networks. There will be ongoing engagement with workshops and roundtables, and of course, public reporting and public town halls like this one. So we continue, we plan to continue hosting these town halls on a regular basis to report on progress and answer questions like the plethora that we have received today, for which, you know, thank you. So final note from me, a recording of today's session will be available on the Home Affairs website in the coming days. And a really heartfelt thank you from me and from the team. And a massive thank you to my team for pulling this town hall together today. We look forward to continuing the conversation with you. Greta, any final remarks?


Greta DOHERTY

Just a huge thank you everyone for presenting and asking questions. And yeah, we agree we'll get as many responses as we can back. Thanks everyone.


Lauren DREW

Thanks, all.

CyberSmart

The CyberSmart program will make cyber security certification simple, affordable and accessible for small and medium sized businesses and not-for-profits. It will be centred around a new cyber security certification scheme based on a cyber security standard.

We held a CyberSmart program public town hall on Tuesday 25 August 2026. This was a chance for members of the public to hear directly from government about the new program of work under Horizon 2 of the Australian Cyber Security Strategy 2023-2030.

A recording and transcript of the town hall are below.


 

Ashley BELL
Welcome everyone to our CyberSmart Town Hall. For those I haven't met, my name's Ash Bell and I am the Assistant Secretary of Cyber Policy and Programs here in Department of Home Affairs. And my team and I are the policy leads for cybersecurity, but particularly around the government's 2023 to 2030 Australian Cyber Security Strategy.

Today it is our absolute pleasure to be providing you with an overview of the CyberSmart Program, which was announced by the government as part of the launch of Horizon 2 of the strategy, and an initiative that the team and I are really proud of in terms of the work that we've done and the consultation we've done with industry, but also the work that we have ahead of us as we look to design this scheme.

I'm joined today by Dan Phillips, who's our Director of Cyber Resilience.
And we also have some colleagues, I think, from ASD on the line as well, who will be around for Q&A later in the session.

Before we begin our town hall, I would like to take a moment to acknowledge the traditional custodians of the land on which I'm joining you from today, and that is the Ngunnawal people, and I'd like to pay my respects to elders past and present, and also acknowledge and welcome any Aboriginal and Torres Strait Islander people on the call today.

A couple of things for housekeeping.
Today's session is being recorded and transcribed and will be made available on the Home Affairs website at a later date. To ensure that this is a smooth session, all attendees are muted and cameras are turned off. But we invite you to post questions on Slido throughout the event, and you can refer to the details that are on the screen and we will obviously get to as many of these as we can as part of the Q&A, but if we have more questions than we have time for, we'll certainly take those away and look to come back to you. Please only use the Microsoft Teams chat for any technical issues that arise during the presentation. We'd like to keep all the questions on Slido. And where you can, if you can put your name and contact information on that rather than posting anonymous, helps us to kind of direct questions in the right way.

So, we'll get started because we have heaps and heaps to cover. I'm going to be providing a bit of brief context on situating this program of work in Horizon Two, but I'll zip through that because you probably heard that from me or my team before, but just to help bring everyone up to speed, and then we're going to really dig into the details of the CyberSmart Program as we have it now, and Dan will take us through all of that.

So, as I mentioned, for anyone that's joining for the first time or you're catching up via recording, hello in the future. This was built under the 2023 Australian Cyber Security Strategy, which was released in November 2023. The vision is simple, but ambitious and it's to make Australia a world leader in cybersecurity by 2030. This is about ensuring our economy and society can prosper and recover quickly from cyber incidents. Importantly, what we do under the Strategy is through the three separate horizons is to look at how we can take whole of economy policy reforms, programs, initiatives to uplift our resilience for everyone, whether that's small business, not-for-profits, individuals, critical infrastructure, government. We take a whole of economy look at cyber because cyber is a whole economy challenge.

The strategy itself is built around 6 shields, which each represent a layer of defence that keep business, citizens and government safe. As I mentioned, across the three horizons of the strategy, the idea is that at the completion of each horizon, we're able to look backwards and look forwards and determine where do we need to put our focus and do we need to pivot our policy response. How are those initiatives going, and we have done a lot of work in that space around both considering and consulting.

We started that consultation over a year ago. We spoke to you, we listened to you, we had round tables, we had town halls like this, and one of the things that came through very strongly was the need for in Australia for us to focus on the small and medium businesses and how we can really move from guidance and awareness into something more structural and that's where we're going to go today.
Under Horizon One, with your partnership and support, we delivered all 60 initiatives and then with the development of Horizon Two, we have been looking at policy interventions for what's next.

For Horizon Two, this has been shaped hand in hand with industry. We've had a lot of consultation. We had over 170 submissions from all across Australia, and a number of town halls and roundtables. So, for those that contributed, I want to thank everyone that did that through your formal submissions. We're very conscious that the most precious thing you have is time, and that time is being spent in the public interest is something that we're really thankful for. So, on behalf of my team and I, thanks.

We launched the Horizon 2, that was launched by Minister Burke on 11th of June, with the focus of targeted practical measures to make a real difference. In Horizon 2, we have 64 initiatives across 19 action areas with a delivery scheduled through to end of 2028.

There's three key objectives that most of the work fits around.

The first is around strengthening our people. So, this is about how our workforce becomes the strongest line of defence, or what the minister calls the human firewall. This is also about looking at not just the community, but looking at those that need support in terms of lifting up their resilience, and that's a big part of what we're going to talk about today.

The second objective is around protecting our critical infrastructure and government systems. Naturally, the place for government in terms of this is the big public service facilities, this is critical infrastructure we all rely on is a cross-sectoral elements.
And a lot of that work is being taken forward by our colleagues in the Critical Infrastructure Security Centre, but also, I know there's a lot of consultation going on at the moment around that work, which is very exciting.

And thirdly, it's around shaping and securing the technologies that Australians rely on every day. And really that’s about looking at things like secure by design, looking at where we can extend or expand standards, and making sure that the technology that we buy and use in our businesses every day is a minimum baseline level of security. But it’s also about looking to the future. Looking at the impact of frontier AI on the cyber mission, looking at what quantum will mean for Australian infrastructure and government services. So, it’s really looking at technology in a holistic way but also very much from a retail perspective as well, so, from the macro to the micro.

I’m not going to go through all 64 initiatives today as much fun as that would be, but I did want to just quickly touch on a few that we are highlighting in the context of what are talking about today, which is how we are supporting small entities.

So, as I mentioned, the feedback we received was quite unanimous around significant challenges to small business and medium businesses in managing cyber risk, and that the existing cybersecurity measures or guidance or material that’s out there doesn’t always necessarily fit for smaller entities. And so, the challenge I think has been for us is, it is such a heterogeneous group, small businesses, everything. But it’s also such a major part of the economy, such a huge employer. And in terms of time poor, there’s no one more time poor that a small business owner that is trying to manage a bunch of risks, run their business. So, we wanted to think about ways that we could make cybersecurity much cheaper, more invisible, kind of part of the fabric of the ordinary business and regulatory approach that small business take forward.

So, some of the initiatives that we will be working through in Horizon 2 are about building cyber awareness in the Australian workforce through supply chains, and taking lessons from the Jaguar-Land Rover incident in the UK around the impact that cyber-attacks can have, not just on a big entity, but actually the ripple effect on the supply chain particular small businesses. That’s what they unfortunately found out in the UK where a lot of those small businesses who directly sourced to Jaguar-Land Rover were basically shutted. And so, understanding how we can empower the workforce to be part of our frontline of cyber defence is a critical one.

The next one is driving uplift for the not-for-profit sector through our new community of practice and other support mechanisms, and I’ll come back to that one later because we have a launch event tomorrow which I’m hoping you will all join us for as well.

Weve got co design with industry with the security standards for consumer grade edge devices for use in small businesses as well as our launching labelling scheme that we are working on, and a shout out to our connected technology site next week which we will be talking about those initiatives. That’s a big piece around the technology that we use in our businesses and making sure that comes secure, rather than needing to have businesses be cyber experts as well.

And of course, of CyberSmart initiative which is what we are all here for today. I know you’ve been very patient while Ive set the scene. So, now it’s time to hand over to Dan, the man with the CyberSmart plan, who is our Director for Cyber Resilience, and he and his team have been working incredibly hard in terms of the design of this work, and I know are busting at the seams to get into it. So, Dan, what is the CyberSmart program?

Daniel PHILLIPS
Thanks Ash, and yes, a huge thanks to my team for putting this event together today.

The new CyberSmart program will develop a simple cybersecurity certification framework for small and medium businesses and not-for-profit organisations to help uplift their cyber resilience.

Once certified, organisations will be able to display a Trust Mark in their communications with customers, suppliers and the community. By promoting CyberSmart uptake through government procurement and regulatory levers, this initiative will also help to strengthen supply chains while keeping white tape at a minimum, those kinds of obligations imposed by businesses and other organisation s on each other.

As we develop the CyberSmart initiative, our objective is to ensure that we deliver a program that is, first and foremost, accessible – making cybersecurity uplift and certification simple to access for smaller entities. Making sure its affordable – making it a low-cost program accessible to everyday small businesses and organisations. A highly credible program – underpinned by trusted systems of accreditation, and a program which can scale rapidly to a national level.

The CyberSmart program has six main components that will support the certification framework. I will run through each of these with you in a bit more detail, then we can open up to some questions.

So, central to the program is a conformity assessment scheme. Schemes are established governance mechanisms that are used to manage assessment frameworks, like CyberSmart. It includes all the rules and requirements to ensure the program is maintained appropriately. Schemes are used across a range of industry sectors already that manage standards and assurance requirements, including areas such as food safety or building codes and things like that. The scheme will be a central component of the program and will provide a credible, transparent and nationally recognised certification mechanism. The CyberSmart scheme will be established under the authority of the Joint Accreditation System of Australia and New Zealand, JASANZ.

This is the internationally recognised authority for conformity assessments in Australia. Establishing A scheme under JASANZ provides the highest level of assurance through an independent accreditation framework. And the scheme will include industry representatives in technical and advisory roles to ensure that it's practical, trusted and fit for purpose.
CyberSmart will establish a flexible, nationally consistent cybersecurity framework for small organisations. It will give smaller organisations an achievable starting point, a clear pathway to stronger cybersecurity, and a trusted way to demonstrate their cybersecurity practices.

Cybersecurity standards will provide organisations with published sets of rules, guidelines, and good practises for protecting their digital environments from cyber threats. By leveraging existing industry standards, CyberSmart will remain adaptable and practical and relevant as technology and cyber risks evolve. The particulars of the standards, including associated costs and requirements and accreditation frameworks and things like that, are still the subject of ongoing consideration and we would certainly welcome ongoing engagement as we continue the development of the CyberSmart program. We'll soon be commencing an approach to market, seeking potential delivery partners and cybersecurity standards that are designed for smaller entities. We'll be seeking to implement a tiered standard, providing organisations with an appropriate entry point, recognising that organisations will have different levels of cyber maturity and face different cyber risks.

The appropriate tier can be selected based on factors such as their size, operating environment, and the level of risk that they face. This will allow smaller organisations to begin with practical foundational measures without being required to immediately meet standards designed for larger or more complex entities. By tiering the cyber controls and the requirements, CyberSmart can also be used to support supply chain security outcomes, with certified and smaller suppliers becoming more attractive suppliers by providing greater confidence so they can support the security and resilience requirements of their customers. Over time, levers such as government procurement and critical infrastructure supply chain requirements could also be used to incentivise small businesses to meet specified levels of cyber maturity through the scheme.

The CyberSmart Trust Mark will be the identifiable indicator for organisations to show that they are CyberSmart certified. Its design will be informed by industry consultation and international experience to ensure that it provides meaningful assurance without exposing unnecessary information about an organization's cybersecurity vulnerabilities. The Trust Mark can support certified organisations to easily indicate their commitment to cybersecurity to support contractual requirements and also supply chain confidence.

The CyberSmart Hub will be the primary web platform for the program. We'll be providing a simple, accessible pathway for organisations seeking to improve their cybersecurity and achieve CyberSmart certification. The Hub will be designed around the needs of smaller entities, those that have limited cybersecurity expertise, and particularly small and medium businesses and not-for-profits that otherwise can struggle to navigate the existing guidance and platforms that we have available.

It will guide organisations through the CyberSmart certification process with tailored, plain English guidance, and will support access to accredited certification bodies to assist with the certification program.

It will also contain comprehensive guidance that will support organisations seeking CyberSmart certification to understand and meet the requirements that will be defined in the CyberSmart standards. Guidance will be tailored to smaller organisations, include the use of multimedia and other methods of communicating to make sure that we don't simply stick to the one-size-fits-all approaches and make it easier for different businesses to engage with the requirements and understand what they need to do to meet different levels of the standard.

The department is also looking to enhance the existing Cyber Health Check tool, which no doubt some of you will have seen before, which we launched under Horizon One. It was released in October last year to provide greater functionality and support for organisations seeking to start their journey towards building greater cyber maturity.

Under the Horizon 2 initiatives, we'll continue to provide free self-assessment options through the Cyber Health Check tool for all small and medium-sized businesses and other organisations. But we're looking to do some further integration with CyberSmart to encourage organisations to progress from more basic self-assessment activities towards more formal certification. This integration will provide practical and accessible entry points for organisations who are really just starting out in terms of trying to build their cyber resilience and provide them with actionable advice which is tailored to the responses that they give through the Cyber Health Check tool questions.

I think those are those are the key elements we wanted to discuss today, so I'll pass across to Steve to facilitate some of our Q&A.


Steven BOARDMAN

Thank you both, Ash and Dan, for your presentations and to our audience for listening and all your contributions on Slido that I can already see coming through.

My name is Steve Boardman, Assistant Director of Cyber Resilience, and I'll walk us through the questions that we've already received on Slido.

And there is time still if you'd like to jump on and add additional questions. As you can see there on the screen, you can use that QR code or the link as provided. All right, we jumped straight into it. Our first question from Slido:

Is CyberSmart going to be mandatory?

And I'll throw this one to you, please, if I can, Dan.

Daniel PHILLIPS
Thanks, Steve. No, CyberSmart is not going to be mandatory. The idea behind CyberSmart is to provide something which is accessible to people through a voluntary certification scheme. But we recognise that, you know, organisations increasingly need to be able to demonstrate their cybersecurity maturity, whether that's to their customers and suppliers, the service providers, and to government and other partners in various circumstances.

So, CyberSmart will provide a simple and consistent way for smaller organisations to demonstrate their cybersecurity maturity. In certain high-risk environments, there could be cyber assurance requirements, which become mandated. And so there could be ways in which CyberSmart can be integrated based on the circumstances of those particular things, but the scheme as a whole is not going to be mandatory.

Our goal is certainly not to impose new compliance burdens or anything like that on small businesses, which have enough of those things to do already. Our goal is to provide something which actually makes that easier. To provide something which is nationally recognised and hopes to hopefully streamlines the interactions between different mechanisms that are already there. So that once the CyberSmart certification has been attained, it can be used in different contexts by the business that has got it. So, rather than having to repeat cyber risk assessments or questionnaires or justify their cybersecurity controls in different contexts, if they have the CyberSmart certification, they're able to use that as a way to cut through some of that. So hopefully reducing the need for multiple and overlapping cyber assessments and turn that into something which actually makes it significantly easier for small business to meet those existing burdens.

Steven BOARDMAN
Great, thanks, Dan. Next question from Slido.

Why CyberSmart and how is this different to the ASD Essentials?

And for that, I might throw to you, Ash.

Ashley BELL
Sure. Thanks, Steve. Look, I think there's a few questions around the connection to Essential 8 or the Essentials. And so, I'll kind of sort of take some of those together. One of the things we heard a lot from stakeholders was when it comes to existing standards for small businesses and medium businesses as well, things like the Essential 8 has a number of controls that are incredibly valuable and useful. But for the bulk of small businesses, for the majority of that are starting out their journey towards improving their cyber maturity, they don't translate well to their business.

Now, ASD has done an incredible amount of work working with small businesses and looking at their publications and of course, as the questions premised, are looking at evolving their Essential 8 into the Essential series. And so, we've been working very, very closely with ASD around those elements. But the place where CyberSmart is looking is what we've kind of called the step ladder between, you know, absolutely no controls, no awareness of cyber, what do I do to protect my business, all the way up to some of these frameworks like Essential 8 or NIST or whatever. So, the idea is it's actually trying to fill a hole around getting people on that roadmap, on that journey towards these sophisticated frameworks.

Also, for the majority of small medium businesses, it may be that some basic controls are all that's needed for them. So, the intent is to kind of cater for what we've heard from industry as a sort of a missing part. Obviously, there's standards out there already in the industry that are being adopted to fill that part. And I think what, as Dan explained, what CyberSmart is looking to do is to provide a kind of government mechanism and framework that will help support, encourage and work with industry on that. So, I don't think it's in competition, but it's certainly one that we are working with ASD to make sure that we have good alignment across government around what we're trying to do. Thanks, Steve.

Steven BOARDMAN
Thanks, Ash. Okay, next question.

What does accreditation mean in practise for self-assessed responses?

Dan, can I throw that one to you?

Daniel PHILLIPS
Sure, thanks. I mean, we think that having self-attested tiers is an important part of this program, principally to keep costs down in some areas where having full independent audits for days on end is probably not necessary for some of the things which we're talking about for smaller businesses. And self-attested tiers exist in similar established standards worldwide. There's other things which are equivalent in other countries and provide, cost-effective entry into schemes like this.

The requirements of the self-attested tiers will still be in development, but we're certainly looking to have rigorous process around what that looks like. And I think the key principle is that organisations should be able to access this kind of cyber assurance at a cost which is proportionate to the risks that they face. If every organisation had to go through an intensive audit, I think many small businesses simply wouldn't be able to participate. And that would be obviously counter to what we're trying to achieve here.

So, we're making sure that we still have a rigorous and robust framework in terms of our conformity assessment scheme, and we'll be setting those guidelines and rules in collaboration with JASANZ and making sure that we have that independent accreditation framework over the top, but hopefully in a way which makes this accessible for many small organisations that would otherwise be locked out.

Steven BOARDMAN
Brilliant, thank you. Lots of great questions coming in, so, encourage everyone to jump into the Slido. I might stay with you, Dan, for the next one.

What is the time frame for launching CyberSmart?

 

Daniel PHILLIPS
Yeah, obviously this is a huge amount of work which we still have to do to make sure we get to where we want to be with CyberSmart. At the moment, we're looking to have a pilot of the program in the second-half of next year. So that's where we're working to at the moment, working through what the full level of scheme design and everything is going to be with JASANZ and with other industry stakeholders. I'm hoping to start with a pilot. We're looking at probably a six-month pilot in the back half of next year, and then we'll be looking at a full national rollout in the following year.

So, that's roughly what we're working to, and obviously, depending on how the development process goes, we might be able to bring some of those things forward. But we do want to try and get some further communication about this out as early as possible. So even ahead of the pilot, we'll be looking to put out some additional information about the direction that's going so that people can start to prepare and start to think about the path forward for their organisation once CyberSmart becomes available.

Ashley BELL
If I could jump on that, Dan, I think key message that we want you to take away today is this is really sort of the kick-off part, right? Consultation on something like this is going to need your input, your advice about what will work, what won't work. The small business sector, it's so large and it's so diverse that no doubt, we need to hear from you. We need to hear from actual small businesses that are in the market, from cyber professionals that service those small businesses, from industry associations, from everyone. And so, when it comes to the scheme design, we've obviously got a policy objective that the government's asked us to deliver, but the way that we get there is the piece that we really want to talk to you about. So, we'll have contact details later on the end, but as it was with the Horizon 2 consultation, and I hope the team and I have built up enough cred with you to know that we genuinely want to hear from you, and we are listening.

So, please don't take anything here as it's all locked in and, well, this is just going to happen to us. That's not the case. And these schemes to be successful, they must be built together. And that's what we're seeking to do. So, I know that you hear that a lot from government, but again, I think our kind of track record on this shows we are absolutely keen to build this together.

Steven BOARDMAN
Great, thank you both.

There are a number of questions that relate to the standard and if a standard has already been selected.

I might just pass back to you, Ash, on that one if that's all right.

Ashley BELL

No, so that's the whole design of this, right? So, when we were looking at this as a policy part, just to bring you on the inside a little bit about how we developed this, but also the thinking.
The challenge we have is that there are existing small business tailored standards out in the market. There's a range of these, whether just as examples, you know, the ACE open case, SMB 1001, I think is mentioned in some of the questions as well. There are already those standards. And what we heard from stakeholders when we were asking this question about, well, would a government sort of backed standard for small businesses actually help? The thing we heard a lot was, yes, but we don't want just another standard or we don't want something that is going to just be imposed. And so that kind of set us down a path in terms of the policy design around this JASANZ framework and having that kind of open element of standards that could come in. I think that provides a few things which are really positive. So one is, flexibility around applying a standard that suits your business.

I'm hoping that they're going to be set standards that people will sort of gravitate towards, but it could be that there are certain elements of the small business sector where there should be or needs to be a bespoke standard for particular types of small businesses. And I think the benefit of this approach allows that to be captured as well. It also provides that agility and ability to for standards on there, but then for whatever reason, it's no longer being kept current or there's an issue that it's not sort of just one standard that's relied upon.

So, there's elements there around competitive kind of elements around how they apply. There's parts around there around it being applicable to niche parts of the small business sector, and also there's a transparency element around this, right? It's not about picking winners, it's about making sure that small business have a standard that they can use easily and then rely on as part of the system.

So, that's kind of the thinking and why we didn't go down the road of just picking a standard or making our own and just imposing it through a framework. So, that is a decision in terms of the policy decision. But, in terms of the scheme design and how those standards interrelate, what's required, what's the minimum baseline, all those things are part of the scheme design consultation that we want to do to make sure that what we are allowing in this framework works for small business and meets our policy objectives. So, definitely open for those conversations.

Steven BOARDMAN
Thanks, Ash. And I'll grab one here that flows off the back of that. And Dan, if I could ask you to speak to this one.

Is CyberSmart intended to be another standard in its own right, or is it a framework leveraging existing standards?

Daniel PHILLIPS
Yeah, thanks, Steve. And look, as Ash was just saying, we're certainly not intending to construct or impose a new standard. The CyberSmart in itself is not a standard. It's a framework that allows the endorsement and the leveraging of existing standards. So, continuing to encourage the innovation that's already occurring within private industry to put these things together, make them available for smaller businesses to uplift their cyber resilience.

And CyberSmart really is the layer over the top that can give people the confidence that this is an endorsed standard and that this is a suitable path for them to take forward. And also allow some integration with other government levers, such as procurement, things like looking at the SOCI regulations and things where there is a need for supply chain assurance that is being called out loud and clear and making sure that we have a suitable accreditation mechanism for that. So yeah, we're certainly looking to leverage the work and build upon the work that's already been done by certain prime companies in this space.

Ashley BELL
Just on that, and to qualify my answer before a little bit, we did build in a redundancy within the policy design as it went forward to government, which said, if there were no suitable industry standards, then we would need to make our own. So just to be clear, if there weren't any that were suitable, although, as I said, there's a lot in the market that are doing good work, then government could put one in, just to be absolutely clear.

Steven BOARDMAN
Great. Thank you both.
I'm seeing a question around the length of the certification. So, how long does it last for?

That's been upvoted a few times. So, I might pass to you, Dan, to talk to that please.

Daniel PHILLIPS
This is something which we're going to need to consider as we take the design of the scheme forward. I think we need to balance the competing requirements where we want to make sure that any certifications are kept up to date, make sure that they're credible and current and up to date with current developments in terms of technology and risks and things like that, but also not create a burdensome framework where continual reassessment is going to become too onerous for small businesses to maintain.

So, we're certainly keen to consult industry in relation to what is a suitable cadence for recertification. I think those arrangements will be put into place into the scheme once we've, you know, had that consultation. And I guess that is something that we'll be able to adjust over time if we feel like that it's not working well. That's part of the process that we want to have going through our pilot and the early stages of the scheme to make sure that we have tuned these things correctly.

So, the frequency and the types of the reassessment could also differ across different tiers from the higher tiers to the lower tiers, depending on how the tiers shake out.

That's something that we're going to look to consult further on and, as I said, try and strike that balance between keeping them current, but avoiding an unnecessary burdensome requirements.

Steven BOARDMAN
All right, lots of questions still coming through and we do have some time remaining, so please do keep them coming in. We'll try to get to them, as many of them as we can.

Ash, if I could pass to you one here that says;

What opportunities for the broader IT cyber industry exist in terms of participation and support around CyberSmart and is this planned and do you see this growing in the industry?

Ashley BELL
Thanks. That's a great question, because that's another wonderful piece of this policy work that we are excited about. What I'll talk about now is kind of a future set, but we are very focused on before we can run, we've got to walk and then before we do, we've got to crawl. So, we're going to do the work to set this up with you guys.

In terms of what does this do for the future and what are the sort of drivers and policy drivers for why we think this is a scalable measure that we wanted to put forward in Horizon 2, the big part of this, and this goes to a few things we've heard from industry around how the Australian small business sector is supported. This obviously plays into elements around the cyber workforce, plays into availability of cyber professionals, but it also talks about price points of things like insurance and the penetration of the small medium business market. It talks to other elements around how do people understand the cyber maturity of a particular small business or medium business. And I think the challenge is, it's quite expensive to do that in a way. So, we're hoping that through the CyberSmart and the Trust Mark, that will work together to essentially provide that kind of signal to the market.

I also think as small businesses engage with the standard as they engage with some of the steps and it kind of demystifies the sort of scary elements of cybersecurity and shows these are some things that you can do, pretty practical, pretty sensible things that can be put in place. Like I said before, it gets those small businesses onto a journey. They're starting to look at cybersecurity as a business risk like they would anything else, whether that's locking the front doors of their shop or whether that's getting flood insurance or whether that's many of the other elements that small businesses are already doing to protect their business and protect their livelihood.

We hope that then as they go through that journey and as they start to climb the step ladder, they will be demanding more from the market. And that will provide opportunities for Australia, a dynamic and innovative market to respond to that, like they do with many other parts. So, I'm hopeful that the cyber profession then will be able to build around that and start to provide services bespoke to Australian small business needs. So, I think there's an element here about sparking that demand and getting that attention and providing a solution to, oh okay, this is what I need to do. Now, where do I go to get that help? And I think that plays into the other component of the CyberSmart program, which is the CyberSmart Hub, where we're hoping to then build and co-locate all the information, but an evolution of the CyberSmart Hub, which we're hopeful for, if we can get the traction that we're aiming for, that will be a place to then demystify service offerings and products and things that will be really helpful to small businesses, but they don't know where to go. They don't want to get sold something that they don't need. You know, is that suited for me in Australia? Is that suited for me in this particular small business sector? And so, as we build this community through the CyberSmart Hub, paired with that, we're also hopeful that'll provide a platform for that to come together.

So again, these are down the lines. Let's focus on getting this step in the program set up. But you can kind of see the ambition that we're sort of building up as we go to say, through baselining and transparency and through this government endorsed standard, we're going to get small businesses on the journey, we're going to get that scale. And then from there, we are hopeful that it will provide opportunities. It will provide parts for the cyber industry to support, but also other parts. You can imagine insurers being able to write policies at a much lower cap level if they can be confident about the cyber maturity, banks could be thinking about business risks in a different way. There's probably a lot more things and exciting things that we haven't even thought of yet.

So, welcome those ideas from you as well, or innovative ways that we could leverage this program. We're always open to those kinds of ideas. At the end of the day, the mission is just about uplifting cyber resilience for small medium businesses. So, if you've got a clever way of doing that, or you can think of a particular connection within what we're doing, let us know. We're really open to those ideas. Thanks, Steve.

Steven BOARDMAN
Thank you. All right, we'll keep moving on. And to address a question in the chat, yes, we are monitoring the Slido and those questions that are getting some traction with the thumbs up and we'll try to get to as many of them as we can.

I see a group of questions that all relate to cybersecurity service providers and how it might work in terms of becoming partnered with government to certify SMEs and to issue Trust Marks.

Now, Dan I'll throw this one to you, noting that we are early in the development phase here, but perhaps you could talk to some of the theory behind that.

Daniel PHILLIPS
Sure. The idea here is to allow different bodies to become accredited as assessors for CyberSmart. And so, once the JASANZ scheme is up and running, to actually have an accreditation system there that allows for lots of different providers, small or otherwise, to be able to be involved in this scheme and to be able to conduct the assurance that goes across the certifications. Providers like MSPs and others will be critical in part of this digital ecosystem. Those that are already engaged with small and medium businesses, those that are there on the ground talking to them about their needs and their vulnerabilities and the things that they're seeking to achieve for their business. Those are the people that we want to be engaged with this program so that they can be the ones that go, yes, you're ready to look at a particular level of CyberSmart, you've got the controls in place, or where there are some remaining gaps and vulnerabilities, they'll be in a position to advise on what those businesses need to do in order to reach particular levels, depending on what their organisation is doing, their risk profile and their maturity and all those types of things.

So, I think it's definitely a significant opportunity for service providers in this space to be on the front line of CyberSmart with us and helping to raise the overall cyber maturity and cyber resilience of small and medium businesses and other small organisations across the country, because they're the ones that are out there doing these jobs every day. So, what we're hoping with CyberSmart is to provide a nationally consistent framework that would allow that to provide that level of confidence that at particular tiers or thresholds or however we end up crafting that, that the providers who are dealing with small businesses know what is suitable for the context with that small business or other organisation is trying to operate in.

Steven BOARDMAN
Thank you, Dan. Ash, I might come back to you off the back of what you were talking about earlier. One of the questions that's received a bit of traction in the chat is;

How does the government plan to prevent the Trust Mark becoming another meaningless sticker that doesn't really provide any buyers, any real measure of assurance?

Ashley BELL
Thanks. Appreciate the question, Corch.

So, look, we don't want the Trust Mark to be meaningless. There'd be no point in doing this. Part of the elements which Dan's already gone through in terms of the certification process, we need it to be robust, but at the same time, we can't go too heavy-handed in terms of how we calibrate this, because then it will become too expensive. If we require extensive audits against the standards, up and down, it's going to be cost prohibitive. I'm not even sure that it would be practically viable. And look, I know that's not what you're suggesting in your question, but part of this is thinking about what the right level of either self-attested accreditation or review, and then obviously the frequency of that certification commensurate to the risk that's there. This is a big part of what we want to do in our consultation.

So let me be clear, this is the piece where we need you to come and support us to understand how we calibrate that correctly. There'll be different needs, right? So, you can imagine that there'll be a particular, let's say there's a government agency that is procuring for particular types of services, and they're going to a part of the small business sector where you'd want it to be pretty robust. Now, you're going to want to have a level of accreditation or a tier or whatever that is very different from your baker down the road, who really, based on their risk and threat profile, there's a lot of the basics that they could do, and there's a lot of elements that they could do in terms of securing their kind of IT systems, but the products that they're using, the hyperscalers the Microsoft products, as long as they've got the stuff switched on, as long as they've taken some pretty basic cyber hygiene, they're not the ones that need to go out and have an audited part.

So, the Trust Mark then itself connects to what that maturity level is. So don't get me wrong, we have a lot of work to do together to understand and to best calibrate those. We'll have learning, we'll try and get it as good as we can get it, and then we will continue to refine it as we go forward.

The idea here is that we have a framework, that we have a central point to have that conversation, rather than it being set by a tonne of different standards and a whole bunch of certifiers or other places. The idea is we're actually trying to bring that together and then kind of anchor that within sort of the government component. So, we're all singing off the same hymn sheet in a way. But look, there is no point doing any of this if it's just going to become a meaningless sticker. We don't want compliance. Well, I mean, we do want compliance, but we don't want just empty compliance. There's no point to it. We wouldn't be bothered doing this, and it's not the policy outcome we want.

So, the answer to your question is we're not going to let it become a meaningless sticker because we're going to work together with you guys to design it in a way that it's not. And I'm very open to any feedback. There's going to be 100 different views of different ways that we could do this and we are going to listen to them all. We're going to obviously make a decision, so we do something, but this is one of the ones that I really want us to focus on as part of our consultation. So, if you've got good ideas on this, if you're passionate about this one, definitely get in touch with us. And thank you for the question, Corch, because I know it's something you're passionate about too.

Steven BOARDMAN
Great, thank you, Ash. Okay, we've got about 5 more minutes, so we'll try and fit as many of these in as we can. I've seen a few relating to insurance, which is great to see an interest in cyber insurance. Dan, I might ask you;

Will the insurance industry be engaged to ensure that CyberSmart certificates can have a positive impact on cyber insurance?

Daniel PHILLIPS
Yeah, that's certainly our intention. We're keen to engage with the insurance industry and other important parts of the cyber ecosystem. I think one thing which we've seen in other jurisdictions is where there can be connections between certifications and being linked to the underwriting process for cyber insurance. While we don't want to be intervening in the cyber insurance market in Australia, we are keen to work with the insurance industry on ways in which the scheme which we're proposing and the way in which the design of that is being put together can actually support what they'll be seeking to do in terms of cybersecurity certifications or other elements that form part of the scheme.

So that's certainly on our radar that we want to work with the insurance industry to try and get this integrated into as many parts of the economy as we can to make it as easy for small businesses and others to make the best use of the work they're going to put into CyberSmart.

Ashley BELL
And think of it like, again, I've used flood insurance as an example, but when the government releases those floodplains information, that allows a business to understand what their risk is. That allows them then to determine through market forces and through whatever is out there, to be able to get those products to help ensure their business.

In a similar way, what we're trying to do with CyberSmart is provide the framework from which small businesses are able to identify their cyber risk and then level them the treatment that they need to do, which we are hopeful then will allow for the insurance sector to then support small business.

It's also, to my point before, about increasing demand. So suddenly insurance elements might be a really cost-effective way for a small business to manage its cyber risk, once it's aware. That then will open up hopefully those opportunities. So, we do see a connection, but we are, to Dan's point before, very conscious that we don't want to be distorting the market or kind of connecting anything too formal. We will continue to look at the policy settings around insurance as part of our regular work, and we always welcome feedback on that, especially if you're seeing things in the market which aren't going the way you think they should.

Steven BOARDMAN
Great, thanks, Ash.
I'll throw straight back to you, Ash;

There's some interest out there for an in-person event, perhaps in Sydney, to further talk about CyberSmart.

Ashley BELL
Yes, answer is yes. We would love to do events. We'd love to do engagement. And if there are ideas that you have, if you're from an industry association, if you're from a chamber of commerce, if you've got a group of people, we want to talk to as many people as possible. If you've got an idea about events, particularly we can speak to and understand the views of small businesses directly.

That's one we're really open to. It's really challenging at the Commonwealth government level. You know, we deal in macro and scale for our policy work. So, connecting that to those individual small businesses and providing a platform to do that would be great.

Steven BOARDMAN
Brilliant. Thank you, Ash. Dan, I think we have time for one or two more. How about we go to;

How CyberSmart will support sole traders and small or micro businesses that want to improve their cyber resilience but may not need certification?

Daniel PHILLIPS
So, I guess this goes to part of the work which you touched on earlier in relation to the Cyber Health Check and the other initiatives that we have going. Certainly, at a very entry level, the Cyber Health Check Tool is useful for individuals, small businesses, sole traders of all kinds of small organisations.

But also, part of what we're hoping to achieve with the CyberSmart Hub is to make the resources available and have the guidance available, even if organisations ultimately don't decide that the certification is something that they need to pursue. So certainly, our intent is that CyberSmart will be useful in many different contexts and for organisations of all sizes, including sole traders, and that there'll be lots of value that they can obtain from the resources and the other materials that we have available, even if the certification is not something that they ultimately need. So, at different tiers, hopefully we'll have enough accessible guidance for different maturity levels and different organisational requirements for different businesses, and then everyone will be able to find the information that they need by going to the CyberSmart Hub.

Steven BOARDMAN
Great, thank you. Okay, time for one more, I think. Ash, if I could throw back to you; How does government see this being used in procurement? And will agencies or organisations be encouraged to recognise CyberSmart certification when engaging SMEs?

I think you spoke to this a little earlier.

Ashley BELL
Yeah, I did. So, as part of the policy decision that we've taken forward from government, the intention is to require a CyberSmart accreditation for Commonwealth government procurement. One of the things that we heard a lot from our consultation was, it's all good and well to have a standard or a guidance or a material, but how do you get small businesses to engage? How do you get them to pay attention? And I imagine there'd be a fair few frustrated CISOs on the line that are thinking exactly that. And so one of the elements that we've looked at is the government lever, because we want to uplift Commonwealth Government cybersecurity, and so we need to make sure that our supply chain is secure, much like we're asking for industry to be looking at their supply chain and small businesses and their supply chain and making sure that they're secure. The Commonwealth Government is going to do that and lead by example as well.

We also think that, given the amount of government contracts, that will also provide a strong incentive for small businesses to pick up the CyberSmart certification, particularly when it's so easy and cheap and wonderful. So yes, the intention is to link to that. And it's certainly an element that we will be consulting on how we do it so that we don't create undue regulation for small business. But to be clear, we do want to uplift our Commonwealth cybersecurity, and we do want to encourage uptake of the scheme. So, those are policy drivers that we are working towards.

Steven BOARDMAN
Brilliant. Thank you, Ash, and thank you Dan, for tackling so many of those questions. We have unfortunately run out of time.

And I might pass back over to you, Ash, now if I can, just to wrap us up.

Ashley BELL
Wonderful. Thanks, Steve, and thank you for coordinating the questions. We've got tonnes of them in Slido. We've been going through them all and the team's been kind of organising them all to get it through. So, we've captured all of those questions, which are going to be really important. So, thank you. Apologies if we didn't get to your question. I'll get to the details of how you can reach out to us, but please just e-mail your questions through to us. Like I said, we're very keen to talk.

Before I wrap up, I'd like to give a quick shout out to the launch of the not-for-profit Cyber Uplift Community of Practice, which is the first event tomorrow, online at the same time as today. QR code to register is on the screen. I saw this question come up around, what about not-for-profits? This is the part that we're doing it. Think of it like a TISN for not-for-profits. We're really excited about this. This is another one where we're really keen to build the community and to build our new ideas. And we're working with the ACNC on that as well. And word has it, maybe we might have a minister at the launch event tomorrow. So, you just have to find out tomorrow.

So, look, thank you all for your time and for the valuable insights, questions you've shared throughout your engagement through town halls, submissions, co-design workshops. That's what keeps us moving along. That's what keeps this strategy real and delivering for Australians. So, my call to action is keep co-designing with us. We want to make sure that we're engaged. If you have any other feedback around how we're doing that, what we can do better, we're always open to that as well. We really appreciate the opportunity to improve the way that we're engaging, but also how we're developing the policy. And of course, you've got some details here about how to be engaged. If you are interested in other parts of the strategy, Home Affairs website's the best place to be, or you can kind of monitor Home Affairs and the coordinator's LinkedIn. We usually put our events on those as well.

So lastly, I want a really big thanks to my team for all the work that they've done, both in the leading up to this, but also for the Town Hall. Thank you for your time, and I hope you have a great rest of the day. Thanks.

CyberSmart enquiries

If you have any enquiries about the CyberSmart Program , send us an email at CyberSmart@homeaffairs.gov.au.

Horizon 2 enquiries

If you have any questions or enquiries about Horizon 2, send us an email at CSSH2@homeaffairs.gov.au.

pop-up content starts
pop-up content ends