Greta DOHERTY
We're providing today an overview on the recently launched Horizon 2 Action Plan under the 2023–2030 Australian Cyber Security Strategy. It's lovely to have so many people here and great to see so much interest and engagement with Horizon 2. My name is Greta, I'm the First Assistant Secretary of the Counter Foreign Interference, Cyber and Technology Division in the Department of Home Affairs. My job title is very wordy, but the short version of that is that my team is responsible for driving implementation of Horizon 2 for the Australian Government. And in doing so, we work across government to make sure we're bringing a coordinated and joined up approach.
So I've got members of my team here today and also really pleased to let folk know that we have broad government representation, including from Australian Signals Directorate, Department of Foreign Affairs and Trade, Department of Climate Change and Energy, and a range of subject-matter experts across Home Affairs, including from the National Office of Cyber Security. We've got our critical infrastructure experts, our emerging tech experts, all of the folk are here in case we get into some detailed questions.
Before we start, I would like to acknowledge the traditional custodians of the lands that I'm on today, which is in Canberra. So I pay respects to the Ngunnawal people and also acknowledge other families with connection to this land. I pay my respects to elders past and present, and elders and traditional custodians of the many countries and lands on which everyone is joining us today. And I'd also like to extend acknowledgement and respect to Aboriginal and Torres Strait Islander peoples who are with us here today.
Just a little bit of housekeeping before we kick off. So today's session is being recorded and transcribed and it will be made available on the Home Affairs website, which is a good reminder to me to be a very smooth presenter. To ensure everything goes well, all attendees are muted and cameras are turned off, but we do want this to be an interactive session. So we encourage you to please post questions in the Slido throughout the event. And there's details on the screen for how you can do that, and we'll respond to those at the end of the presentation.
For anyone who's joining us for the first time or catching up via the recording, the Australian Cyber Security Strategy was released on the 23rd of November 2023 after extensive consultation. Its vision is simple but ambitious, which is to make Australia a world leader in cyber security by 2030, ensuring our economy and society can prosper and recover quickly from cyber incidents. The Strategy is built around six shields, each representing a layer of defence that keeps businesses, citizens and governments safe. The Horizon 1 Action Plan outlined a phased approach to delivery over three horizons. So we've just come off Horizon 1, which was about strengthening our foundations. Horizon 2, which is the focus of today's discussion, is about expanding our reach. And Horizon 3 is where we really reach for Australia being that world leader in cyber resilience. The transition points between horizons are really intentional review moments, a chance to test where the Strategy remains fit for purpose in light of emerging tech, economic shifts and global events. And you probably don't need me to tell you that at the moment, all of those things are happening in concert and that review point is particularly critical when we're seeing changes in capabilities almost on the daily.
Just to go back in time a little bit in terms of where we're at for Horizon 2. So the Horizon 2 Action Plan was officially launched by Minister Tony Burke on the 11th of June and it was supplemented in the recent 2026–27 budget with funding of $89.3 million to deliver on initiatives in the Strategy over the next few years. That investment is on top of the $586 million that was already committed when the Strategy was launched back in November 2023. So really, as I said before, Horizon 2 is about building on the foundations we've already put in place and seeking to expand those. Horizon 2 has been shaped with industry and we thank everyone who has been involved in the conversation. We do that simply because we know that government can't do this alone and neither can industry. So we're focusing our efforts where they matter most, moving quickly where it counts, and continuing the strong partnership of engagement that we've built up over the course of the Strategy. At the centre of all of our efforts are Australian businesses and citizens, because lifting national cyber resilience is truly a whole-of-nation effort.
Before we go into the detail of Horizon 2, and I'm going to hand over to a colleague to talk about that so you don't have to listen to me for the full time, I'm just going to quickly take a step back and look at what we achieved through Horizon 1 to sort of set out those strong foundations from which we are building.
So we started the process with listening. A year ago in July 2025, we released a policy discussion paper to get views about where Horizon 2 should focus. And we received over 170 submissions from across the board – from industry, small business, academia, the not-for-profit community and all levels of government. And it's super exciting to know that we have such a broad range of people here today for this session, because that shows ongoing engagement and knows that we've been talking to the people who are interested and who can help take it forward. After that broad engagement, we went a step further and worked directly with stakeholders to co-design the next phase. So this included three public town halls and then 10 more targeted roundtables to really test and refine those ideas. The two-phased approach – so with the broad consultation followed by co-design – was all about making sure we were staying aligned with industry and community and focused on the outcomes that will make a difference.
If you're interested, alongside the launch of Horizon 2 last month, we also published the 2025 Review of Horizon 1. It brings together what we've delivered across all 60 initiatives, as well as the key lessons and insights that we learned along the way. It's a substantial piece of work. So perhaps after this session, if you have a moment to make a cup of tea, I encourage you to sit down and have a look. It's available on the Home Affairs website. I guess the key takeout from the review of Horizon 1 is that it shows exactly what's possible when government, industry and the broader community work together towards shared goals.
So some highlights from Horizon 1. Super proud of the team and the cross-government team because we were able to deliver on all 60 initiatives on time and on budget. So a couple of highlights across the shields. Shield 1 is around strong businesses and citizens, and that's really about supporting Australians to stay secure in their everyday lives. You will have seen the 'Act Now. Stay Secure.' campaign. It's reached millions of Australians, helping lift awareness of simple steps that people can take to protect themselves. We also focused on reaching people in ways that work for them. For example, through grants, over 200 community organisations were able to translate cyber security advice into practical and culturally relevant support for communities. We know that when things go wrong, support matters. And it was great that around 120,000 victims were able to receive tailored help through IDCARE. And we've seen ongoing strong take-up of secure services as well, with more than 15 million Digital IDs used through myID. And at the operational end, Operation Aquila carried out 38 disruptions against major ransomware groups like LockBit, contributing to broader international efforts of takedowns and sanctions.
Shield 2 around safe technology is about shifting the burden of cyber security away from individuals and onto the systems and products that people rely on. A key step here was the 2025 rules for smart devices. This introduced a mandated secure-by-default baseline for consumer smart devices so that they're safer from the moment people start using them and that responsibility for safety moves to the companies best placed to manage risk. We've also been working really closely with industry on a voluntary smart device labelling scheme, which will give consumers clearer information and reward companies that invest in stronger security.
Under Shield 3, which is world-class threat sharing and blocking, this is where we really start to see the power of collective defence in action. A key part of that is the Australian Signals Directorate's threat sharing platform. That platform has distributed nearly 3 million indicators of compromise to around 450 partner organisations. And because that sharing happens machine-to-machine, it allows partners to block threats in near real time, often before they go anywhere near end users. We've also strengthened collaboration through the National Cyber Intelligence Partnership, which has brought together industry leaders and cyber experts to share technical insights and best practice. Capabilities through that partnership have helped streamline intelligence sharing, scale up threat blocking, and better integrate government and industry efforts. Another great example under Shield 3 is the Health Cyber Security Network, it now has 60 members and covers more than 600 health facilities, a sector that holds some of the country's most sensitive data. The health network has made it much easier to share threat information, patch vulnerabilities faster, and identify system-wide gaps that wouldn't have been visible before. And more broadly, these pieces of work all reflect an important shift from organisations sort of defending themselves in isolation to a way more connected and collective model of resilience.
Shield 4 around our protected critical infrastructure is all about safeguarding the essential services Australians rely on every day. We've made strong progress here through reforms to the Security of Critical Infrastructure Act, the SOCI Act as it might come up later, along with enhanced requirements for Systems of National Significance. Together, these changes mean owners and operators are now taking a much more structured approach to identifying, managing and reducing cyber risks. We've also seen real value from the National Cyber Exercise Program, with 97% of participants reporting meaningful insights into their preparedness. That's important because when a cyber incident does occur, preparation and clarity will help us all recover faster, respond faster and recover more quickly as well. Another key step here was the launch of the Systems of Government Significance regime in July 2025, giving government much better visibility over its most critical digital systems and functions so we can prioritise their protection and reduce the risk of catastrophic impacts.
Next, we're moving on to the last two shields, 5 and 6. So Shield 5 is our sovereign capabilities, about building Australia's own cyber strength, our people, our ideas and our innovation. Some quick examples here include the Cyber Workforce Summit and the Cyber Workforce Playbook, which are giving employers practical tools to attract, retain and grow cyber talent. Importantly, we're also making sure that the workforce is more diverse and inclusive. New inclusive recruitment guidance is helping organisations of all sizes to bring in women, First Nations people, and neurodiverse candidates into cyber roles. Taken together, these efforts are making sure that Australia has the skills, capability and the innovation base that we need to stay secure into the future. And finally, Shield 6, resilient region and global leadership, which recognises that our cyber security efforts don't stop at our borders. Through the SEA-PAC cyber program, we've been supporting regional partners directly, including through 12 RAPID deployments, which are rated very highly by our Pacific partners. They provide hands-on support during major cyber incidents. We've also been building preparedness across the region. DFAT's Cyber Exercising Program has delivered 16 table-top exercises with Southeast Asian partners, helping countries strengthen their incident response capabilities before a crisis hits. And at a global level, Australia has been playing a leading role at the United Nations, including helping to establish a new permanent UN Global Mechanism on cyber, which is about reinforcing the rules, norms and governance frameworks that keep the digital environment open, secure and stable. This work all contributes to a safe and interoperable global digital system which underpins regional stability and supports Australian businesses operating internationally.
So building on those Horizon 1 foundations, stakeholder feedback was the other major input shaping Horizon 2. And as I said before, many of you who are here today contributed to that process. A few consistent themes really came through with our feedback on Horizon 2. Those include the need to better support small and medium businesses and the not-for-profit sector, the need for a continued focus on growing and strengthening the cyber workforce, including skills, professionalisation and diversity, and the importance of maintaining strong collaboration between government and industry, as well as a clear call for greater transparency and better ways to measure progress. I want to take a minute to thank again everyone who contributed, whether that was through a formal submission, coming to a workshop, or any of the ongoing conversations that you've been having with any of us across government. That input has really been critical in making sure that Horizon 2 is grounded in real experience and focused on the challenges that you're facing every day.
As I said before, it's been two and a half years since we released the Strategy and the Horizon 1 Action Plan. And again, no one needs me to tell you that the cyber threat landscape has shifted significantly since the launch of that Strategy. We're seeing all of the media reporting and trends in the media backed up by a growing body of evidence with more than 40 public reports each year from government and industry tracking trends. We know the cost of cyber crime is continuing to rise and we know that at the same time threat actors are becoming more sophisticated, including through the use of AI and automation. All of this reinforces something that everyone here will know, which is this is not something we can treat as a 'set and forget'. Our strategy and our responses and our partnership work need to continue to evolve and stay responsive. So thank you for coming on that journey with me. Hopefully some of that is familiar to folk who've been part of the process. What did we do with all of that? I'm going to hand over now to my colleague Lauren, who's heading up the Cyber Policy and Programs Branch here at Home Affairs, to talk through in a bit more detail the actions that we'll be delivering under Horizon 2 of the Strategy.
Lauren DREW
Thanks Greta and hello everyone. I'm Lauren Drew. I am currently Acting Assistant Secretary for the Cyber Policy and Programs Branch at Home Affairs. So like Greta has indicated, the Horizon 2 Action Plan is now live and available on the Home Affairs website. And if you haven't explored it in more detail and have come here to hear more about it first, I really encourage you to go and engage with that document afterwards. But in short, the Horizon 2 Action Plan sets out a program of targeted, practical measures that will make a real difference for Australians, delivered in close partnership with industry. Altogether, it includes 64 initiatives across 19 action areas to be delivered through to the end of 2028. Those initiatives are organised around three key objectives. The first is strengthening our people, so our workforce becomes our strongest line of defence, or what we call the 'human firewall'. Second, protecting our critical infrastructure and government systems. And third, shaping and securing the technologies that Australians rely on every day. Look, I'm not going to step through all 64 initiatives today, but I will highlight some of the key ones under each objective. And then we'll open it up for questions where we can go into more detail.
So under Objective 1, we will reinforce the 'human firewall' as our nation's first line of cyber defence. We will give support to workers to help uplift the cyber resilience of small and medium businesses, given their centrality to a thriving economy and supply chain security. Establishing the new CyberSmart program, which is a key action under Objective 1, will develop a simple, adaptable and fit-for-purpose cyber security standard for small and medium enterprises to help uplift their cyber resilience. Those that are certified as meeting the standard will then be able to display a trust mark in their communications with customers and suppliers. Another key action under Objective 1 includes uptake of CyberSmart through government procurement and regulatory levers. This initiative will also help to strengthen supply chains, while keeping white tape at a minimum. We will build on the 'Act Now. Stay Secure.' campaign to deal with emerging threats, including AI. And we will deliver tailored cyber education programs to support diverse cohorts and further engage priority communities. Consultation to inform the development of the Strategy found that vulnerable communities, including neurodivergent groups and people with disabilities, faced really unique challenges when engaging with cyber security advice and guidance. While awareness-raising activities will seek to reduce the risk of vulnerable cohorts falling victim to cyber crime at a national level, this program will help to expand the national cyber security awareness campaign to uplift security outreach and literacy among the Australian community. It also recognises the ability of community leaders to deliver trusted and lasting messaging to priority groups to ensure cyber security information is appropriate and is accessible to all Australians. We will also review the cyber security regulatory environment so we can get a clear picture of the regulatory pressure points impacting industry, and work across government in partnership with industry to identify opportunities to centralise cyber incident reporting. The outcomes of this review will then help to support a 'tell us once' experience through a single cyber reporting interface. And finally, we'll take the translation of a technical subject global by developing an international ransomware standards framework. This framework will set practical and achievable global benchmarks for cyber uplift.
Under Objective 2, we will uplift cyber maturity by strengthening the security, the reliability and the resilience of critical infrastructure and government systems. This will be achieved through a proactive investment-led approach that enhances resilience across critical assets and their supply chains. Some of the key actions under Objective 2 include addressing drone security risks and assessing our subsea cable security posture, exploring amendments to the Directions power in the SOCI Act to better protect critical infrastructure, and strengthening supply chain resilience through exercises held by the National Office of Cyber Security, or NOCS. These exercises will be held across critical infrastructure and business to analyse critical interdependencies and vulnerabilities across Australia's critical infrastructure and government supply chains. And it goes without saying that this will also help to develop scalable toolkits and to test preparedness and national coordination arrangements. Objective 2 will also seek to strengthen logging and monitoring standards across government and critical infrastructure, strengthen government procurement arrangements and Systems of Government Significance, and deepen national, state, territory and local government collaboration through a National Cyber Security Compact. This Compact will enable all levels of government in Australia to collaborate on cyber security initiatives and escalate key issues at a national level. Importantly, the Compact will serve as a mechanism for meaningful collaboration and coordination with states, territories and local government on cyber security.
Moving to Objective 3, we will complement the human firewall by reducing cyber risk at its source – that is, the technology environment that Australians rely on each and every day. This will ensure safe adoption becomes the default and includes initiatives such as embedding security into the design, deployment and operation of connected technologies, strengthening protections for data that matters most, and anticipating technology risks. Other key actions under Objective 3 include assessing legislation and policy to ensure industry and the Australian Government can collaborate at speed on defensive cyber measures, supporting telcos and other upstream to block threats at speed and scale, and embedding security into connected technologies in homes and businesses, such as routers, operational technology and consumer energy resources – this will ensure Australian households and small businesses have more confidence in the cyber security of the devices they use to connect to the internet every day. We will also make security the easy choice for consumers through a smart device labelling scheme. We will prepare government and critical infrastructure for emerging technology, including developments in AI and quantum. And we will uplift data security across the Australian economy through the finalisation and promotion of a risk-based framework for datasets of national significance.
I'll pause there and hand across to my colleague, Rebecca Kerlett, for questions and answers. Thanks, Bec.
Rebecca KERLETT
Thanks, Lauren. I'm hoping I won't have to provide too many answers. I'm here to facilitate them, but I'm happy to look at the questions specifically. Before we hit the Q&A portion of today's event, I just wanted to underline the immense amount of attendance we have here today. We have over 490 attendees. I'm sure every single person on the line has a question because that's how these things always work. But it's unlikely we're going to be able to answer everything today. We will take stock of questions and answers, and those that we can't get to, we will aim to answer those out of session. We've included a QR code for access to the Slido and again reiterating what the team has mentioned in the chat that those will be provided anonymously. If you are having dramas accessing Slido or you're happy to throw your questions straight in the chat, please do so and we'll aim to try and balance out our attendance to both. Before I do pass back to our fabulous presenters, I'll take a moment to acknowledge the range of questions that we have received on Slido already and in the Teams chat as they've come through. We can see a range of questions that are touching a number of thematic areas across cyber security, and in no specific order, we can see quite a bit of interest on the implications of artificial intelligence as part of the Horizon 2 program. There's some queries and statements in there around how we can sustain and build on existing engagement and partnerships between government and industry. I know that's something that Greta especially touched on in her opening remarks and very happy to go in more detail through that. There's some really pointed questions around workforce professionalisation and how we can uplift our sovereign capability. So again, looking forward to coming back and addressing those. And there's also pleasingly some remarks around how we also continue to work across critical infrastructure and government.
So we might start almost alphabetically with artificial intelligence. Lauren, I haven't given you much of a break from your remarks as part of the presentation, but I might hand to you first. We have covered this off in your opening remarks and in some of the overview that Greta provided, but I was wondering if you might be able to give us an overview of how AI and engagement on AI as part of the Horizon 2 program will be supported by ongoing and strong industry partnerships as part of this work. If others on the call who are part of this policy agenda of government would also like to jump in once Lauren and Greta have finished their response, we'd be very pleased to also take your support to that. So over to you, Lauren.
Lauren DREW
Thanks, Bec. And yes, I think it's safe to say that AI permeates everything. The key for us here is, in terms of Horizon 2 and recognising that Horizon 2 runs across a three-year period, we're likely to see quite a significant change over that period of time in what we're actually dealing with from both a technical, from a security and from an opportunity perspective as well. So Horizon 2 has been developed to wrap around AI. There's obviously key initiatives that we've included on AI in the Action Plan, but I think it's safe to say that we can essentially have AI as a component of every single initiative that we've included in under Horizon 2. But Greta, was there anything else that you wanted to add there specifically?
Greta DOHERTY
Thanks, Lauren, and thanks for the question. I can see there's a few questions, as Bec said, specific to AI. I think there's a couple of specific actions in the plan that we can talk through, but what we've proposed in Horizon 2 was obviously drafted prior to some of the recent capability jumps that we've seen, but I guess shows that the way that Australia was able to respond and has been able to support industry in recent months shows that we've kind of got the framework and the architecture right there. So what we do going forward, I think will build very much, as I've said before, on what we've done in the past. And that includes things like leveraging our really strong relationships with critical infrastructure post some of those AI capability gaps. We were able to facilitate briefings between frontier AI labs and some of our most trusted providers through the Trusted Information Sharing Network. We were able to get – when I say we, our colleagues at the Australian Signals Directorate – were really quick in being able to get up and out practical advice, both for CISOs in organisations as well as for individuals, around what to do in the face of frontier AI capability jumps and what it might mean for vulnerabilities. So we have sort of targeted information sharing mechanisms. We've got really good engagement on cyber.gov.au already that ASD has been able to draw on to sort of take that information further. And then we've been able to iterate and adapt as different things change, as they seem to do almost every day. I guess specific to the way we're engaging going forward and, you know, to the question, not just talking about Copilot, but what does agentic AI mean for the way that we do cyber security? We're assessing the suitability of our existing crisis management frameworks in response to major AI incidents – so really putting those systems through their steps, and we've already started that at a government level. So looking to test what is there and how well it responds – continuing to collaborate with trusted and private partners on AI threats, including through some of our critical infrastructure and other mechanisms, as well as work that Australia is leading through Five Country Ministerial so that we can tap into international insights and engagements. And I've seen a question, so I'm just going to quickly pivot to post quantum, but post quantum represents, I guess, a capability jump beyond even frontier AI. So we're getting ready for that by pulling together and disseminating actual guidance for both government and industry in terms of what you need to be doing to get ready for post-quantum cryptography. So that's a couple of the examples, but I really just want to say that all of the actions that we're taking forward build on the great work that's underway through partners with ASD, through DFAT's international engagement piece, and then through our colleagues here at Home Affairs and engagement with critical infrastructure. And then I don't know if anyone else wants to jump in. Or we can move on, Bec.
Rebecca KERLETT
We can move on as the ringleader of the awkward pauses between people being allowed to jump in or not. I think that was awkward enough. Lauren, I might just pass to you as well off the back of Greta's comments. This is a continuation of our discussion on industry partnerships and Greta's provided us that lovely overview of the ecosystem of all the interlocking parts across government and the opportunities to remain engaged on Horizon 2. But as part of your day job, you are involved in the program area that is delivering on a number of Horizon 2 initiatives in partnership across government and you have a great perspective on what that looks like in practice. And thinking through how we have some of these forums set up for ongoing engagement at a high level on cyber security, I was wondering if you could provide us maybe a little bit of a slice of life of what that engagement often looks like in practice.
Lauren DREW
Sure, thanks Bec. Well, as with the development of Horizon 1 and the significant public consultation that was undertaken to support Horizon 2, and as Greta and I have outlined during the presentation, we cannot do this alone. Partnerships are absolutely integral to our work on Horizon 2 and co-design with trusted industry partners is a thread that runs right throughout the Action Plan. So there's lots of opportunities to get involved in the co-design with my team. If there is something specific that anyone on the call here today wants to engage on, please contact the team. But in terms of day-to-day we've already started engaging with industry groupings – particularly, I would have to say, not-for-profit and small to medium business groups have been really energised about Horizon 2, which is fantastic to see. And that work that we're progressing under the Action Plan and the initiatives that we outlined will be absolutely, those partnerships will be absolutely key to being able to deliver something that is the right size and the right shape, and addresses, well, supports cyber security uplift and maturity development without overburdening small to medium businesses who, you know, may not have the resources or the capabilities that they might need to do the full uplift. So initiatives such as the community of practice that we are establishing for not-for-profits will be really key to trying to deliver practical advice in a really tangible way and to build trust with key stakeholders from those sectors. But like I said, my team is already engaging right across the Horizon 2 Action Plan with industry stakeholders and international partners as well as our whole of government colleagues. So if there are specific areas that anyone would like to engage with us on, it is a call to action to please reach out to the team.
Rebecca KERLETT
Thanks, Lauren. And it is a long horizon. I'm sure the end of 2028 will be here before we know it, but we do have a lovely long lead-in time across the next, now, two and a half years to be collaborating and implementing the initiatives highlighted in the Action Plan. I might use this as a segue, a bit of a warm handover to our colleague Nick from ASD and give you time to find the mute button while I throw to you. I wanted to also get ASD's perspective on partnerships because the relationship between Home Affairs, ASD and others in reaching out and collaborating across industry and government is integral to the success of the cyber security strategy, as well as broader cyber security and resilience uplift activities more broadly. Nick, I wanted to ask if you wanted to comment from ASD's perspective on those partnership arrangements before I throw the question in the chat on PDNS and CTIS to you. But, Nick, over to you.
Kearton, Nick Mr
Yeah, thanks Rebecca. Can you hear me okay? Excellent. Yeah, so look, thank you for the lead on partnership and it's something that's really important to us. I think just before I go into that, I wanted to quickly address another comment if it's okay, just regarding advice on post-quantum cryptography, similar to the plug a little bit earlier around AI. There's a suite of documents and advice available via cyber.gov.au So it's worth having a bit of a dig through there. We'll continue to kind of provide that advice as things evolve. Regarding partnerships, yeah, industry partnerships are really critical to us. The ASD partnership program continues to expand. There's a lot of detail about that on cyber.gov.au, but it provides opportunity for us to engage with industry, share knowledge, share threat intelligence. There's a pathway for home partners, small to medium business and network partners. So there's a whole range of things and services, products, advisories available under that. So again, I'd encourage you to look through cyber.gov.au. I think critically too, we're really, really focused at the moment, you'll note in here, there's
in Horizon 2, there's a bit of reference to the Essentials series. I noticed a comment in the chat there too, and that's something we're really deeply engaged with industry on currently in the consultation phase of that, which is happening, I think, through to the end of July off the top of my head, but I could have that wrong. So yeah, the partnership angle is critical to us. There's a whole lot of information on cyber.gov.au. It's obviously cyber's a shared responsibility and something that we're really eager to engage on.
Rebecca KERLETT
Lovely, thank you, Nick. And in the spirit of cross-government collaboration and support, I would like to open up another potential awkward pause, but space for other partner agencies to jump in if they also wanted to provide a comment on partnerships before we maybe duck down a little bit more technical. No, excellent. Okay, well, Nick, I might call you back so you can keep your camera on because this one is for you as well. So we have had a question around what happened to the Protective Domain Name System Cyber Threat Intelligence Sharing feed – this seems to have dropped off since late last year. Is there any additional detail you'd like to provide in response to that one?
Kearton, Nick Mr
I might need to take that one on notice, I'm sorry. Have we got the details for whoever's asked that question? I'm very happy to come back with a little bit of information there.
Rebecca KERLETT
Yep, we will take that on notice and we'll provide that as part of the package response that goes up. Thanks, Nick, and thanks to the person who asked that question. We might go into more broadly – and Lauren, this is one for you – we do have a supporting area from Home Affairs who unfortunately can't be on the line today, but –
Kearton, Nick Mr
Terrific.
Rebecca KERLETT
– we're looking at investments into domestic cyber industry growth and cyber startups, noting it's a broader question around investments and grants and when things might be available and when. Is there an overarching response you can provide on grants that might be relevant to that program? And noting as well that anything more specific, we will take on notice and come back to our audience.
Lauren DREW
Thanks, Bec. So I will note that in relation to action item 5.3 in particular, that Home Affairs is working closely with the grants hub within DISR to determine next steps for the proof-of-concept round. Anything beyond that one though, I will need to take on notice, noting that we don't have the appropriate rep on the line here today. On grants more broadly, though, I will note that in developing the package of initiatives for Horizon 2, government gave really careful consideration to outcomes of the 2025 Review of Horizon 1, as well as the views that we received through over 170 submissions that Greta outlined earlier in response to the Horizon 2 policy discussion paper. So while specific grant programs, some of them, had concluded by the end of Horizon 1, the government does remain committed to supporting small and medium businesses, in particular, not-for-profits, community organisations. So the government is still funding a range of initiatives to support smaller entities under Horizon 2, including and principally driven through the CyberSmart program, which includes a tailored small entity cyber security standard and certification regime that I outlined earlier to uplift cyber resilience across the whole of economy. Thanks, Bec.
Rebecca KERLETT
Thanks, Lauren. And I'll note that the cobwebs seem to have been shaken out from people asking questions because we've had a massive uplift in questions coming through on Slido. Greta, this one's for you. With regard to looking at the uplift of consumer end devices, including things like routers and smart devices, noting existing work on that has been fantastic, but also energy devices like inverters for solar batteries, air con and so on – would you like to provide some comment on what potential uplift activities we would be looking at for those sort of devices or infrastructure and provide a comment generally against how that fits into our focus on ongoing internet-of-things connected devices?
Greta DOHERTY
Yeah, thanks. Thanks, Bec. And thanks for the question, whoever asked. It is a great question. But we have had, as you point out, a really intense and targeted focus on consumer-grade devices, and consistent with undertakings under the Cyber Security Act, we've committed to co-design with industry a security standard for those consumer-grade edge devices like routers and modems. But that is really underpinned by a range of activities across other kinds of technologies that you pointed out in the question, so I can go through a couple of those. Really looking at exploring options to uplift the security of IoT operational technology. So how do we secure the systems that drive the things in industry is a piece of work that Home Affairs is going to be taking forward under Horizon 2. In terms of cross-government efforts, Home Affairs and a range of others will be working with the department whose own secretary says it's the department with the long name, so I won't attempt to say it, but the department that includes transport, to introduce new national road vehicle cyber security standards consistent with obligations to harmonise with international vehicle regs. So that's another important, I guess, piece of technology that we're really looking to secure there so that people can trust digital products and platforms. To the question specifically about solar and the like, DCCEEW is taking the lead on a national approach to designing cyber security for consumer energy resources, and that's through work that's being undertaken through the Consumer Energy Resources Roadmap. And again, that's a whole-of-government piece across DCCEEW and including Home Affairs and ASD colleagues. So that's sort of, I guess, an overview of what we're doing in a domestic setting to make sure that all of the devices and the pieces of technology that Australian individuals and communities and businesses engage with every day are as secure as they can be. On an international level, we're continuing to track what our international counterparts are doing to make sure that Australian regulation aligns with that best practice and it's fit for purpose. So there's quite a significant body of work underway there. Also, continuing the national voluntary labelling scheme for the cyber security of smart devices that we started and that we've alluded to also under Horizon 1. So really driving that piece of work forward. Thanks, Bec.
Rebecca KERLETT
Thanks very much, Greta. Might change tack a little bit. There's a number of questions going to the role of ASD and Home Affairs around cyber security and engagement more broadly, as well as the experience of incidents –
you'd think after a few years I could say incident – cyber security incident responders when a breach or an incident does occur. I know we have representation from the National Office of Cyber Security on the line. So Matt, I'd love to throw to you for a broad comment on how Home Affairs and ASD work together on the consequence management phase of an incident leading from the initial technical response. And if you would like to provide any commentary on what industry or others might expect when engaging with the National Office when those things do occur, that would be much appreciated. And before I go on mute, of course, opening up the line to our colleagues from ASD once Matt has provided his overview to also jump in. So, over to you, Matt, please.
Matthew WONG
Thanks, Bec. Starting off, here in the National Office of Cyber Security, we manage the cyber security consequences of significant cyber security incidents. So we work really, really closely with ASD, hand in glove with ASD on nearly all incidents, particularly with significant cyber incidents. Things may start off very – could be a very technical type response, but quickly escalates to, you know, in the public domain. Or there are consequences, like unfortunately we see with a lot of data breaches recently, and having that consistent messaging to potential victims, but also sort of onwards reporting to other regulators like the Privacy Commissioner or through the Passport Office or depending on the type of information that is sort of disclosed out there. So I think we work really, really closely together in terms of how incident responders would engage with us. It's sort of that similar process – you would report that cyber incident to 1300 CYBER1 or cyber.gov.au and then engage with us and/or we may proactively engage with you, particularly if we see something in the media or get a tip from another agency where there may be an incident just to see if you need that assistance with consequence management. Sometimes it may not be directly with your CISOs, it could be with your media folks, your government relations folks, or your legal folks, or your MSP, just about how to manage some of those consequence parts of the incidents. We will work with you very closely. We want to partner with you. Engagement with us is voluntary. So we're not necessarily going to tell you what to do, but we can give you some tips on how to manage it and how we can work closely together, particularly across the ecosystem, across government. And one of the key things that we found working with victims is that coming through the NOCS we can streamline some of those engagements with governments. So rather than you as the victim reaching out to the Privacy Commissioner or to your state and territory government or the education department, we can actually help you conduct what we call a coordination call and get the right players in the room. So to make it more efficient, you can engage a selective group of people at once rather than ten groups ten times. So that's some of the efficiencies we've seen with engagement with the NOCS. But I might hand over to ASD if they would like to provide their perspectives as well.
Kearton, Nick Mr
Thanks, Matt. I think that's a really good summary of it, I suppose. I'd just like to kind of clarify ASD's role in incident management and use this as a bit of an opportunity to plug the need to report quickly. So, I mean, I suppose fundamentally ASD's role, we're here to provide technical incident response advice and assistance and to support on public comms. So –
Matthew WONG
Yes.
Kearton, Nick Mr
– Matt alluded to, but we receive a lot of reporting through cyber.gov.au. We've also got the 24/7 cyber security hotline, 1300 CYBER1. But yeah, our role is fundamentally around providing that response, advice and assistance. Home Affairs obviously deal with consequence management. I think the other couple of things I'd just be keen to note in there is the importance of reporting through to us and our role in incident response and management. It helps inform a broader cyber security picture at a national level. And that's something that's really critical to understanding and we try to share that advice through products like the Annual Cyber Threat Report. I'd also just be really keen to note that ASD's role in this – we're not a regulator, we are here to help. We've also implemented things like limited use, which provide additional protections to those who are reporting through to us. So yeah, just to clarify, I suppose, we do very much work hand in glove with the National Office for the Cyber Security Coordinator. But yeah, our fundamental role is in providing that advice and assistance.
Rebecca KERLETT
Thanks, Nick and Matt. I think over the last few years, there's been a strong effort from both agencies and across government to clarify those roles when an incident does occur. And really grateful that you've both continued to reiterate that and to provide that overview to the audience today. This is our last question before handing over to Lauren to end our town hall. With respect to the amount of questions that have come through, particularly in the last 15 minutes, I will reinforce that we are taking stock of those and we will consider and provide a more fulsome response back, including for those ones that we have taken on notice. And we remain very grateful for the audience participation because it's also a great indication of what matters to you and that will help us deliver a stronger Horizon 2 program. So Lauren, can you please round us out with a response to a query around the expected timeline for the ransomware guide, which was to be delivered as part of Horizon 2. I think we're speaking more broadly there to the global standards framework. Apologies if I've misunderstood the question from the attendee who asked it, but what a great opportunity to speak to the global standards framework. So over to you, Lauren, to answer and then to take us home.
Lauren DREW
Thanks, Bec. And it was remiss of me when we were talking earlier about partnerships to not recognise the really strong partnership that Australia has formed with over 70 countries through the International Counter Ransomware Initiative. So the global standards framework, which is being currently developed in consultation with members of the Counter Ransomware Initiative – we anticipate that that will be finalised this year. So it's a really early deliverable for Horizon 2 and that has shown a really strong uptake from members indicating their early support for a global standards framework to provide really tangible, practical uplift measures to help countries baseline their security, cyber security, and to encourage continued maturation of their settings. So a really exciting piece of work that should be coming to finalisation and full rollout by the end of 2026.
One further point too is we've had a query around how do we contact the team for partnerships. So the team will put the email address in the chat but you can email us at CSSH2@homeaffairs.gov.au. So with that, I really would like to thank everyone's time, everyone for donating, giving us your time today, and for the valuable insights and questions that you've shared throughout this session. Your engagement, whether it's through town halls like this one, written submissions, co-design workshops, is really what keeps the Cyber Security Strategy grounded in the realities of our rapidly changing environment. So as Greta mentioned, Horizon 2 is about expanding our reach and deepening collaboration. So a little bit of a call to action, please keep co-designing with us. We will continue to collaborate with industry, community, across all levels of Australian government, to deliver the outcomes that matter most to Australians. There will be industry networks. There will be ongoing engagement with workshops and roundtables, and of course, public reporting and public town halls like this one. So we continue, we plan to continue hosting these town halls on a regular basis to report on progress and answer questions like the plethora that we have received today, for which, you know, thank you. So final note from me, a recording of today's session will be available on the Home Affairs website in the coming days. And a really heartfelt thank you from me and from the team. And a massive thank you to my team for pulling this town hall together today. We look forward to continuing the conversation with you. Greta, any final remarks?
Greta DOHERTY
Just a huge thank you everyone for presenting and asking questions. And yeah, we agree we'll get as many responses as we can back. Thanks everyone.
Lauren DREW
Thanks, all.