Skip to content
HOME / CYBERSECURITY / AUSTRALIA HORIZON 2 CYBER 3 weeks AGO

Cybersecurity

Australia Horizon 2 Cyber Strategy

Australia Horizon 2 Cyber Strategy

Last Updated on June 29, 2026 by Arnav Sharma

As a security architect working across Australian regulated environments, I have watched the 2023-2030 Australian Cyber Security Strategy move from foundation-setting to genuine economy-wide reach. The Australia Horizon 2 Cyber Strategy is the moment that shift becomes operational. On 11 June 2026, the Minister for Cyber Security, the Hon Tony Burke MP, announced the Horizon 2 Action Plan, a new program of work that runs from 2026 to the end of 2028. If Horizon 1 was about strengthening foundations, Horizon 2 is about scaling cyber maturity across the whole economy, and that has direct consequences for how you plan, fund, and defend your organisation over the next three years.

This article breaks down what changed, what the Horizon 2 Action Plan actually contains, how it was developed through the consultation on developing Horizon 2, and the practical steps senior practitioners should take now.

What is Horizon 2 of the 2023-2030 Australian Cyber Security Strategy?

The Australian Government released the 2023-2030 Australian Cyber Security Strategy on 21 November 2023. The strategy is structured in three phases, each described as a horizon. Horizon 1 (2023-2025) focused on strengthening Australia’s cyber security foundations. Horizon 2 (2026-2028) scales maturity across the economy. Horizon 3 (2029-2030) aims to advance the global frontier and position Australia as a world leader in cyber security by 2030. Australia’s cyber security strategy is, in other words, a single national cyber security roadmap delivered in three deliberate stages toward a safer digital future.

Horizon 2 of the 2023-2030 commences in 2026 and continues to the end of 2028. According to the Department of Home Affairs, the cyber threat environment has changed materially since the strategy’s launch in November 2023, shaped by technological, economic, and geopolitical trends. Horizon 2 has been developed to respond to those shifts, with a stated intent to focus on what matters most and move fast where it counts.

The headline framing from government is straightforward: Horizon 1 built the shields, and Horizon 2 expands their reach. Where Horizon 1 concentrated on critical infrastructure and large organisations, Horizon 2 pushes cyber maturity out to small business, supply chains, and the broader ecosystem. For practitioners, that is the single most important structural change to understand.

Horizon 1 vs Horizon 2: what actually changed

The clearest way to see the shift is to compare the two phases side by side. Horizon 1 addressed critical gaps in Australia’s cyber shields to build stronger businesses and citizens through deep partnerships across industry and government. Horizon 2 takes that foundation and broadens both the audience and the ambition.

DimensionHorizon 1 (2023-2025)Horizon 2 (2026-2028)
ThemeStrengthening our foundationsExpanding our reach
Primary focusCritical infrastructure and large organisationsWhole-of-economy cyber maturity
Core goalAddress critical gaps in Australia’s cyber shieldsScale cyber maturity across society and digital infrastructure
Audience emphasisGovernment and major businessesSmall business, supply chains, workforce, communities
Signature conceptCyber shieldsThe human firewall
Delivery artefactHorizon 1 Action PlanHorizon 2 Action Plan
TimeframeTwo yearsAlmost three years, to end of 2028

The reframing from cyber shields to a human firewall is not just messaging. Minister Tony Burke described Horizon 2 as building a human firewall and uplifting cyber capacity the whole way through the economy, with explicit attention to small business and staff-targeted social engineering. That signals where funding, campaigns, and obligations are likely to concentrate.

Inside the Horizon 2 Action Plan: 19 actions and 64 initiatives

The Horizon 2 Action Plan sets out 19 actions and 64 initiatives for government to deliver by the end of 2028. These are led or co-led by 12 Australian Government agencies, with support from contributing agencies. The plan is built around three stated objectives, and each one maps to a different part of the threat landscape that senior teams already manage.

Strengthening workforce cyber resilience (the human firewall)

The first objective targets people. The government’s own framing, building a human firewall, recognises that social engineering and credential-based attacks remain the most reliable path into Australian organisations regardless of technical control maturity. For practitioners, this objective is the policy backing for sustained investment in awareness, phishing-resistant authentication, and role-based security training that goes beyond annual compliance modules.

This is also where small and medium business sits. Much of the Horizon 1 to Horizon 2 transition is about reaching organisations that never had a dedicated security function, which is exactly where staff-targeted attacks land hardest.

Critical infrastructure and government systems

The second objective continues uplifting cyber security for critical infrastructure and government systems. This is the line of continuity from Horizon 1. For entities regulated under the Security of Critical Infrastructure Act (SOCI), Horizon 2 does not replace existing obligations, it intensifies the surrounding program of work. Cyber Security Coordinator Lieutenant General Michelle McGuinness has flagged expanding cyber exercise programs to test readiness across the supply chains that support government and critical infrastructure.

If you operate a responsible entity under SOCI, expect more exercises, more supply chain scrutiny, and more pressure to demonstrate that third parties meet a baseline. Aligning your control environment to the Essential Eight remains the pragmatic starting point.

Secure uptake of new and emerging technologies

The third objective supports the secure uptake of new and emerging technologies. In practice, the dominant emerging technology in scope is AI. The risk surface that AI introduces, from prompt injection against AI agents to model supply chain exposure and AI-enabled social engineering, is precisely the kind of fast-moving problem Horizon 2 was designed to address. Every new capability brings its own risks and opportunities, and each new model or agent expands the vulnerability surface that real-world attackers probe first. For architects, this objective is the strategic cover to treat AI governance as a distinct security domain, supported by a clear control framework, rather than an extension of existing application security. It also recognises that cybersecurity is no longer confined to one team or one sector: every sector now carries digital risk.

Horizon 2 objectiveWhat it coversPractitioner priority
Workforce cyber resiliencePeople, awareness, social engineering, the human firewallPhishing-resistant MFA, role-based training, SMB uplift
Critical infrastructure and government systemsSOCI entities, supply chains, exercisesEssential Eight alignment, third-party assurance
Secure uptake of emerging technologiesAI adoption, new technology riskAI governance as a distinct domain

How Horizon 2 was developed: the consultation on developing Horizon 2

Horizon 2 was not written in isolation. To commence the consultation process, the Department of Home Affairs released a Policy Discussion Paper titled Charting New Horizons: Developing Horizon 2 of the 2023-2030 Australian Cyber Security Strategy on 29 July 2025, seeking submissions from industry partners and stakeholders. The consultation included a Snapshot Paper and a Policy Discussion Paper, with an appendix of questions to guide each submission.

According to the Department of Home Affairs, Horizon 2 has been developed through a wide-ranging consultation process involving over 170 public submissions, three public town halls, and twelve co-design roundtables with key industry partners and stakeholders. Bodies including auDA, the Law Council of Australia, the Australian Chamber of Commerce and Industry, the Clean Energy Council, and the Australian Information Security Association all lodged submissions, many of them focused on how to lift cyber maturity for small and medium business without overburdening resource-constrained organisations.

To view the Horizon 2 policy discussion paper and the public submissions, the Department of Home Affairs maintains a dedicated consultation page. This matters for two reasons. First, the breadth of the consultation, 170 public submissions across town halls and co-design roundtables, signals that the resulting actions reflect genuine industry input rather than a top-down mandate. Second, the government has committed to ongoing engagement. A public town hall to discuss delivery of the Horizon 2 Action Plan is scheduled for Thursday 2 July 2026, where industry and the public can hear directly from government about the new program of work and how to get involved.

What Horizon 2 means for Australian organisations now

The launch of an action plan is a policy event. Translating it into your security roadmap is the practitioner’s job. Here is how the impact of the strategy lands across two common positions.

For critical infrastructure and SOCI-regulated entities

If you are a responsible entity under the SOCI Act, Horizon 2 reinforces the direction of travel rather than changing it. The combination of expanded cyber exercises and a sharper focus on supply chains means you should expect your own readiness, and that of your critical suppliers, to be tested more rigorously. Practical moves: refresh your critical asset register, confirm your risk management program addresses supply chain dependencies, and rehearse incident response with the third parties you actually depend on, not just internal teams.

For small and medium business and supply chains

This is the cohort Horizon 2 is designed to reach. Many submissions during the consultation argued for a practical, lightweight pathway to baseline security for smaller organisations. If you sit inside a larger entity’s supply chain, anticipate that your customers will increasingly pass down baseline expectations, often anchored to the Essential Eight maturity model. Getting ahead of that, rather than waiting for a contractual demand, is the lower-cost path.

How to prepare: a practitioner action checklist

You do not need to wait for individual initiatives to land before acting. The direction is clear enough to plan against now.

  • Map your current control environment against the Essential Eight and identify your real maturity level, not your aspirational one.
  • Treat the human firewall objective as a budget signal. Strengthen phishing-resistant authentication and move training from annual modules to role-based, scenario-driven exercises.
  • For SOCI-regulated entities, extend incident response rehearsals to include critical third parties and supply chain partners.
  • Stand up AI governance as a distinct domain now, covering acceptable use, model and data supply chain risk, and monitoring for AI-enabled social engineering.
  • If you sit in a supply chain, pre-empt customer baseline expectations rather than reacting to contract clauses.
  • Register for the public town hall on 2 July 2026 to hear delivery detail directly from government and feed it into your planning cycle.
  • Track the Horizon 2 Action Plan and its contributing agencies so you can tie specific initiatives to your own roadmap as they are delivered.

The organisations that benefit most from each horizon are the ones that treat the strategy as a forward signal, not a compliance afterthought. Horizon 2 tells you where Australian government attention, funding, and likely future obligation are heading. Align early and the next horizon becomes a tailwind rather than a scramble.

Arnav Sharma
Arnav Sharma Microsoft MVPMCT
Microsoft Certified Trainer · Cloud · Cybersecurity · AI

I help organisations secure their cloud infrastructure and stay ahead of evolving cyber threats. Microsoft MVP and Certified Trainer, author of Mastering Azure Security, and founder of arnav.au — a platform for practical Cloud, Cybersecurity, DevOps and AI content.

Frequently Asked Questions

KEEP READING

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.