The Cyber Action Year Readiness Checklist
ASD has moved from awareness to action for 2026. A practical, five-part checklist mapped directly to ASD’s own critical actions, so you know exactly where you stand.
2026 is Cyber Action Year. ASD has set five critical actions every Australian organisation should be prioritising, replacing legacy technology, implementing best practice event logging, choosing secure-by-design products and services, preparing for post-quantum cryptography, and preparing for AI-enabled threats. This checklist maps directly to those five actions, section by section, so you can work through it with confidence that you’re addressing exactly what ASD is asking for, not a generic best-practice list that may or may not line up.
- A direct, section-by-section mapping to ASD’s five stated Cyber Action Year critical actions, not a generic best-practice list
- A practical starting point for post-quantum cryptography transition planning, without needing to become a cryptography expert first
- A shadow IT and AI tool discovery exercise you can run this month, ahead of the Q4 freeze
- Clear, checkable items throughout, built to be worked through with your team, not just read
Related reading:
- Beyond Awareness Training
- Orro’s existing PQC article: Store Now, Decrypt Later: The 2026 Post-Quantum Risk
- Orro’s National Cyber Defence Centre