Last Updated on June 29, 2026 by Arnav Sharma
As a security architect working across Australian regulated environments, I have watched the 2023-2030 Australian Cyber Security Strategy move from foundation-setting to genuine economy-wide reach. The Australia Horizon 2 Cyber Strategy is the moment that shift becomes operational. On 11 June 2026, the Minister for Cyber Security, the Hon Tony Burke MP, announced the Horizon 2 Action Plan, a new program of work that runs from 2026 to the end of 2028. If Horizon 1 was about strengthening foundations, Horizon 2 is about scaling cyber maturity across the whole economy, and that has direct consequences for how you plan, fund, and defend your organisation over the next three years.
This article breaks down what changed, what the Horizon 2 Action Plan actually contains, how it was developed through the consultation on developing Horizon 2, and the practical steps senior practitioners should take now.
What is Horizon 2 of the 2023-2030 Australian Cyber Security Strategy?
The Australian Government released the 2023-2030 Australian Cyber Security Strategy on 21 November 2023. The strategy is structured in three phases, each described as a horizon. Horizon 1 (2023-2025) focused on strengthening Australia’s cyber security foundations. Horizon 2 (2026-2028) scales maturity across the economy. Horizon 3 (2029-2030) aims to advance the global frontier and position Australia as a world leader in cyber security by 2030. Australia’s cyber security strategy is, in other words, a single national cyber security roadmap delivered in three deliberate stages toward a safer digital future.
Horizon 2 of the 2023-2030 commences in 2026 and continues to the end of 2028. According to the Department of Home Affairs, the cyber threat environment has changed materially since the strategy’s launch in November 2023, shaped by technological, economic, and geopolitical trends. Horizon 2 has been developed to respond to those shifts, with a stated intent to focus on what matters most and move fast where it counts.
The headline framing from government is straightforward: Horizon 1 built the shields, and Horizon 2 expands their reach. Where Horizon 1 concentrated on critical infrastructure and large organisations, Horizon 2 pushes cyber maturity out to small business, supply chains, and the broader ecosystem. For practitioners, that is the single most important structural change to understand.
Horizon 1 vs Horizon 2: what actually changed
The clearest way to see the shift is to compare the two phases side by side. Horizon 1 addressed critical gaps in Australia’s cyber shields to build stronger businesses and citizens through deep partnerships across industry and government. Horizon 2 takes that foundation and broadens both the audience and the ambition.
| Dimension | Horizon 1 (2023-2025) | Horizon 2 (2026-2028) |
|---|---|---|
| Theme | Strengthening our foundations | Expanding our reach |
| Primary focus | Critical infrastructure and large organisations | Whole-of-economy cyber maturity |
| Core goal | Address critical gaps in Australia’s cyber shields | Scale cyber maturity across society and digital infrastructure |
| Audience emphasis | Government and major businesses | Small business, supply chains, workforce, communities |
| Signature concept | Cyber shields | The human firewall |
| Delivery artefact | Horizon 1 Action Plan | Horizon 2 Action Plan |
| Timeframe | Two years | Almost three years, to end of 2028 |
The reframing from cyber shields to a human firewall is not just messaging. Minister Tony Burke described Horizon 2 as building a human firewall and uplifting cyber capacity the whole way through the economy, with explicit attention to small business and staff-targeted social engineering. That signals where funding, campaigns, and obligations are likely to concentrate.
Inside the Horizon 2 Action Plan: 19 actions and 64 initiatives
The Horizon 2 Action Plan sets out 19 actions and 64 initiatives for government to deliver by the end of 2028. These are led or co-led by 12 Australian Government agencies, with support from contributing agencies. The plan is built around three stated objectives, and each one maps to a different part of the threat landscape that senior teams already manage.
Strengthening workforce cyber resilience (the human firewall)
The first objective targets people. The government’s own framing, building a human firewall, recognises that social engineering and credential-based attacks remain the most reliable path into Australian organisations regardless of technical control maturity. For practitioners, this objective is the policy backing for sustained investment in awareness, phishing-resistant authentication, and role-based security training that goes beyond annual compliance modules.
This is also where small and medium business sits. Much of the Horizon 1 to Horizon 2 transition is about reaching organisations that never had a dedicated security function, which is exactly where staff-targeted attacks land hardest.
Critical infrastructure and government systems
The second objective continues uplifting cyber security for critical infrastructure and government systems. This is the line of continuity from Horizon 1. For entities regulated under the Security of Critical Infrastructure Act (SOCI), Horizon 2 does not replace existing obligations, it intensifies the surrounding program of work. Cyber Security Coordinator Lieutenant General Michelle McGuinness has flagged expanding cyber exercise programs to test readiness across the supply chains that support government and critical infrastructure.
If you operate a responsible entity under SOCI, expect more exercises, more supply chain scrutiny, and more pressure to demonstrate that third parties meet a baseline. Aligning your control environment to the Essential Eight remains the pragmatic starting point.
Secure uptake of new and emerging technologies
The third objective supports the secure uptake of new and emerging technologies. In practice, the dominant emerging technology in scope is AI. The risk surface that AI introduces, from prompt injection against AI agents to model supply chain exposure and AI-enabled social engineering, is precisely the kind of fast-moving problem Horizon 2 was designed to address. Every new capability brings its own risks and opportunities, and each new model or agent expands the vulnerability surface that real-world attackers probe first. For architects, this objective is the strategic cover to treat AI governance as a distinct security domain, supported by a clear control framework, rather than an extension of existing application security. It also recognises that cybersecurity is no longer confined to one team or one sector: every sector now carries digital risk.
| Horizon 2 objective | What it covers | Practitioner priority |
|---|---|---|
| Workforce cyber resilience | People, awareness, social engineering, the human firewall | Phishing-resistant MFA, role-based training, SMB uplift |
| Critical infrastructure and government systems | SOCI entities, supply chains, exercises | Essential Eight alignment, third-party assurance |
| Secure uptake of emerging technologies | AI adoption, new technology risk | AI governance as a distinct domain |
How Horizon 2 was developed: the consultation on developing Horizon 2
Horizon 2 was not written in isolation. To commence the consultation process, the Department of Home Affairs released a Policy Discussion Paper titled Charting New Horizons: Developing Horizon 2 of the 2023-2030 Australian Cyber Security Strategy on 29 July 2025, seeking submissions from industry partners and stakeholders. The consultation included a Snapshot Paper and a Policy Discussion Paper, with an appendix of questions to guide each submission.
According to the Department of Home Affairs, Horizon 2 has been developed through a wide-ranging consultation process involving over 170 public submissions, three public town halls, and twelve co-design roundtables with key industry partners and stakeholders. Bodies including auDA, the Law Council of Australia, the Australian Chamber of Commerce and Industry, the Clean Energy Council, and the Australian Information Security Association all lodged submissions, many of them focused on how to lift cyber maturity for small and medium business without overburdening resource-constrained organisations.
To view the Horizon 2 policy discussion paper and the public submissions, the Department of Home Affairs maintains a dedicated consultation page. This matters for two reasons. First, the breadth of the consultation, 170 public submissions across town halls and co-design roundtables, signals that the resulting actions reflect genuine industry input rather than a top-down mandate. Second, the government has committed to ongoing engagement. A public town hall to discuss delivery of the Horizon 2 Action Plan is scheduled for Thursday 2 July 2026, where industry and the public can hear directly from government about the new program of work and how to get involved.
What Horizon 2 means for Australian organisations now
The launch of an action plan is a policy event. Translating it into your security roadmap is the practitioner’s job. Here is how the impact of the strategy lands across two common positions.
For critical infrastructure and SOCI-regulated entities
If you are a responsible entity under the SOCI Act, Horizon 2 reinforces the direction of travel rather than changing it. The combination of expanded cyber exercises and a sharper focus on supply chains means you should expect your own readiness, and that of your critical suppliers, to be tested more rigorously. Practical moves: refresh your critical asset register, confirm your risk management program addresses supply chain dependencies, and rehearse incident response with the third parties you actually depend on, not just internal teams.
For small and medium business and supply chains
This is the cohort Horizon 2 is designed to reach. Many submissions during the consultation argued for a practical, lightweight pathway to baseline security for smaller organisations. If you sit inside a larger entity’s supply chain, anticipate that your customers will increasingly pass down baseline expectations, often anchored to the Essential Eight maturity model. Getting ahead of that, rather than waiting for a contractual demand, is the lower-cost path.
How to prepare: a practitioner action checklist
You do not need to wait for individual initiatives to land before acting. The direction is clear enough to plan against now.
- Map your current control environment against the Essential Eight and identify your real maturity level, not your aspirational one.
- Treat the human firewall objective as a budget signal. Strengthen phishing-resistant authentication and move training from annual modules to role-based, scenario-driven exercises.
- For SOCI-regulated entities, extend incident response rehearsals to include critical third parties and supply chain partners.
- Stand up AI governance as a distinct domain now, covering acceptable use, model and data supply chain risk, and monitoring for AI-enabled social engineering.
- If you sit in a supply chain, pre-empt customer baseline expectations rather than reacting to contract clauses.
- Register for the public town hall on 2 July 2026 to hear delivery detail directly from government and feed it into your planning cycle.
- Track the Horizon 2 Action Plan and its contributing agencies so you can tie specific initiatives to your own roadmap as they are delivered.
The organisations that benefit most from each horizon are the ones that treat the strategy as a forward signal, not a compliance afterthought. Horizon 2 tells you where Australian government attention, funding, and likely future obligation are heading. Align early and the next horizon becomes a tailwind rather than a scramble.
I help organisations secure their cloud infrastructure and stay ahead of evolving cyber threats. Microsoft MVP and Certified Trainer, author of Mastering Azure Security, and founder of arnav.au — a platform for practical Cloud, Cybersecurity, DevOps and AI content.
Frequently Asked Questions
The Australia Horizon 2 Cyber Strategy is the second phase of the 2023-2030 Australian Cyber Security Strategy, running from 2026 to the end of 2028. It was announced by Minister Tony Burke on June 11, 2026, and builds on Horizon 1's foundation-setting work by scaling cyber maturity across the entire Australian economy rather than focusing only on critical infrastructure and large organisations.
Horizon 1 (2023-2025) focused on strengthening cyber security foundations for critical infrastructure and large organisations, while Horizon 2 (2026-2028) expands this reach to include small business, supply chains, and the broader workforce. Horizon 2 shifts from the concept of 'cyber shields' to building a 'human firewall' across the entire economy.
The Horizon 2 Action Plan contains 19 actions and 64 initiatives for government to deliver by the end of 2028. These are led or co-led by 12 Australian Government agencies, with support from additional contributing agencies, organised around three key objectives.
The three objectives are: (1) Strengthening workforce cyber resilience through building a 'human firewall' to address social engineering and credential-based attacks, (2) Continuing to uplift cyber security for critical infrastructure and government systems with expanded exercises and supply chain scrutiny, and (3) Supporting the secure uptake of new and emerging technologies, particularly artificial intelligence.
Senior practitioners across all organisations, especially those in small and medium business and entities regulated under the Security of Critical Infrastructure Act (SOCI), should begin planning now. Organisations should prioritise investment in staff awareness training, phishing-resistant authentication, align control environments to the Essential Eight, and prepare for increased supply chain scrutiny and cyber exercise programs.