Australia

Will Australia be a world leader in cyber security by 2030?

August 16, 2026
15 min read

Key Insights:

  • The 2023-2030 Australian Cyber Security Strategy set out a bold vision for protecting the country from digital threats
  • A seven year roadmap aimed to deliver a 'whole-of-nation endeavour' via six cyber shields
  • Horizon 2 of the 2023-2030 Strategy was recently launched to some criticism
  • Federal and State regulators continue to find significant cyber security failings in private and public sector organisations
  • The Australian Prudential Regulation Authority (APRA) has filed a landmark enforcement under the Banking Executive Accountability Regime (BEAR)
  • The New South Wales Auditor-General has found “significant gaps” in compliance with the State's Cyber Security Policy requirements

Regulatory enforcement is growing in Australia

Australia set out an ambitious cyber security vision in 2023. Three years on, State and Federal regulators continue to find significant cyber security failings.

A proposed $8 million penalty against Bendigo Bank by the Australian Prudential Regulation Authority (APRA) last week was a landmark enforcement under the Banking Executive Accountability Regime (BEAR) for cyber and risk governance failures.

But it was not the first cyber-related regulatory penalty in Australia.

In February this year, the Australian Securities and Investments Commission (ASIC) took FIIG Securities Limited (FIIG) to the Federal Court which imposed a $2.5 million penalty for failing to maintain adequate cybersecurity measures.

This marked the first time penalties were awarded under the general Australian financial services (AFS) licence obligations for cybersecurity deficiencies when threat actors gained access to FIIG's network and exfiltrated approximately 385 gigabytes of data, some of which was later published on the dark web.

Are financial penalties a motivation to reduce cyber risk?

"a penalty of $2,500,000 will validate the behaviour and efforts of compliant businesses, and will send a warning to businesses with inappropriate underinvestment in cybersecurity"
Honourable Justice Derrington, Federal Court of Australia

The stolen data included sensitive personal information such as details of driver's licences, passports and Medicare cards, Tax File Numbers and bank account details.

The penalty represented around 20% of FIIG’s net assets and 8% of its annual turnover and was intended by the judge to act as "a warning to businesses with inappropriate underinvestment in cybersecurity."

Back in Novemebr 2025, the Federal Court delivered another first for cyber penalties in the judgement on Australian Information Commissioner v Australian Clinical Labs Limited.

As the first civil penalty imposed under the Privacy Act (AUD $5.8 million) for cybersecurity failure, it's important to note that the decision was handed down under the prior Aussie privacy regime. Since reforms in 2022, the maximum for organisations is now the greater of AUD $50 million, 3x the benefit, or 30% of adjusted turnover.

Public sector agencies continue to be at risk

And it's not just financial sector organisations that are being taken to task.

The Auditor-General for NSW, Bola Oyetunji, has tabled in Parliament a report that analyses the internal controls and governance arrangements of 26 of the State's largest Government agencies.

Less than half of agencies reported compliance with requirements to protect and govern their risk exposure. And some agencies did not assess risks from legacy systems that cannot be patched, increasing their exposure to cyber-attack.

Of the 71 reporting agencies, 33 reported 128 cyber security risks with a significant, high and extreme residual risk that could impact on a critical agency function, or entire agency operations.

Setting out a bold vision for the future

"By 2030, Australia will be a world leader in cyber security. We envisage a future where stronger cyber protections enable our citizens and businesses to prosper, and to bounce back quickly following a cyber attack."
Clare O'Neil, Minister for Home Affairs and Cyber Security - 22 November 2023

The 2023–2030 Australian Cyber Security Strategy set out six cyber shields under which the Australian Government would seek to improve cyber security, manage cyber risks and better support citizens and businesses:

Australia's 2030 Vision in six key areas

Each shield was to provide an additional layer of defence against cyber threats with Australian citizens and businesses at the core:

  • Strong businesses and citizens
  • Safe technology
  • World-class threat sharing and blocking
  • Protected critical infrastructure
  • Sovereign capabilities
  • Resilient region and global leadership.

The Australian Government committed AUD $586.9 million to the Cyber Security Strategy out to 2030:

  • AUD $290.8m to support small and medium business, build public awareness, fight cybercrime, break the ransomware business model, and strengthen the security of Australians’ identities
  • AUD $4.8m to establish consumer standards for smart devices and software
  • AUD $9.4m to build a threat sharing platform for the health sector
  • AUD $143.6m to strengthen critical infrastructure protections and uplift government cyber security
  • AUD $8.6m to professionalise the cyber workforce and accelerate the cyber industry in Australia
  • AUD $129.7m to strengthen regional cooperation, cyber capacity uplift programs, and leadership in cyber governance forums on the international stage.

Investing in regional cyber security

Just this year, $26.2 million was invested to establish Cyber Rapid Assistance for Pacific Incidents and Disasters (Cyber RAPID) teams led by the Department of Foreign Affairs and Trade and other partnerships with Southeast Asian nations.

“We know that cyber attacks are constant. This guarantees we learn from every attack and keep increasing our resilience"
Tony Burke, Minister for Cyber Security

And in May, the Albanese Government established under the Cyber Security Act 2024, a Cyber Incident Review Board.

Modeled on the now-defunct U.S. Cyber Safety Review Board (CSRB), this public–private body will conduct no-fault, post-incident reviews of significant cybersecurity incidents, extract actionable lessons and strengthen national resilience.

Will the 2030 vision be met?

Less than half the agencies self-assessed that they comply with the ‘govern and identify’ and ‘protect’ domain mandatory requirements.

The question Australians should now be asking is surely "is the Strategy working?"

Despite a commitment to invest more than half a billion dollars, the NSW report found that legacy technology and limited resources left cyber risk remediation plan implementation timeframes being set out in months to years.

Full compliance with the NSW Cyber Security Policy is at least four years away for some agencies and only 33% of agencies complied with mandatory requirements in the protect domain, designed to prevent future cyber security incidents.

It's a startling reminder that having a vision and achieving it, may take more money, time and effort than originally planned for.

Similar posts

Identify. Secure. Assure.

Ready to simplify cybersecurity compliance for critical infrastructure?
Book a demo