Back to Resources

Entering Horizon 2: What Cyber Action Year Means as Australia’s National Cyber Strategy Scales Up

Key Takeaways

  • Australia’s 2023–2030 Cyber Security Strategy moved from Horizon 1 into Horizon 2 this year, with the Horizon 2 Action Plan formally launched on 11 June 2026: 19 actions and 64 initiatives for government to deliver by the end of 2028.
  • Horizon 2 is an acceleration of obligations government and public sector technology leaders are largely already carrying, not a reset. Essential Eight and ISM-aligned architecture remain the baseline; ASD’s Cyber Action Year adds an assumed-breach operating posture on top of it.
  • The Essential Eight itself is mid-transition: ASD opened consultation in June 2026 on retiring the framework over roughly two years in favour of a broader “Essentials series,” a signal that the compliance goalposts government teams have relied on for years are genuinely moving, not staying fixed.
  • Government’s classified and long-retention data holdings make it a first-mover priority under ASD’s post-quantum cryptography transition timeline, with a refined transition plan expected by the end of this year.
  • The Strategy’s Sovereign Capabilities shield gives sovereign, Australian-owned delivery a clear strategic rationale for government and public sector technology decisions, separate from any procurement preference.

Most Government Leaders Know the Strategy Exists. Fewer Have Registered What Changed This Year.

Most government and public sector technology leaders are familiar with the outline of Australia’s 2023–2030 Cyber Security Strategy (Department of Home Affairs, 2023). Fewer have registered that 2026 marks a genuine inflection point in it. The Strategy is structured across three horizons, and Horizon 1 (2023–25) was the foundations phase: addressing critical gaps, building initial protections and supporting early cyber maturity uplift (Department of Home Affairs, 2023). That phase has closed. Horizon 2 (2026–28) is focused on strengthening cyber maturity across the Australian economy, society and digital infrastructure (Department of Home Affairs, 2026), and the transition is no longer a future consideration. The formal Horizon 2 Action Plan was launched by the Minister for Cyber Security on 11 June 2026, setting out 19 actions and 64 initiatives for government to deliver by the end of 2028 (Department of Home Affairs, 2026), organised around three objectives: strengthening the workforce as the nation’s “human firewall,” protecting critical infrastructure and government systems, and shaping and securing the technology environment Australians rely on.

At the same time, ASD’s Cyber Action Year reframing (ASD, 2026), introduced in this month’s opening article, is urging Australian organisations to adopt an assumed-breach mindset: planning on the basis of if, not when, a compromise occurs. For government and public sector technology leaders specifically, these two threads intersect directly with obligations already on the books. Essential Eight maturity, ISM-aligned architecture and, as flagged previously this edition, post-quantum cryptography transition planning are not new items on the list. What has changed is the scale and pace at which government is now expected to deliver against them, and the operating posture ASD is asking agencies to adopt while doing so.

Orro’s view is straightforward: Horizon 2 is not a reset. It is an acceleration of work most government and public sector leaders are already mid-way through. The risk is not ignorance of the Strategy. It is treating this year’s cyber posture work as a continuation of business as usual when the goalposts, the maturity targets, the timelines and the assumed-breach model Cyber Action Year introduces, have genuinely moved.

What Horizon 2 Asks of Government Specifically

Horizon 2 is explicitly about scaling maturity, not simply meeting foundational targets that were already in place. For government and public sector technology teams, that scaling sits on top of an existing baseline rather than replacing it. Essential Eight Maturity Level 2 has been a mandatory requirement for non-corporate Commonwealth entities under PSPF Policy 10 since 1 July 2022, with entities also expected to consider whether their threat environment warrants Maturity Level 3 (ASD, 2024). ISM-aligned architecture sits alongside that baseline as a core requirement under PSPF Policy 11. This is the floor Horizon 2 builds from, not a target still to be reached.

What makes this year genuinely different is that the floor itself is under active review. In June 2026, ASD opened national consultation on evolving the Essential Eight into a broader “Essentials series,” grounded in the Information Security Manual, with the first chapter, Essentials for enterprise IT, intended to give organisations more flexibility while preserving a clear path to cyber resilience (ASD, 2026). Consultation closed in July 2026, and ASD has indicated the current Essential Eight will remain the authoritative, supported framework through a staged transition before eventual retirement. For government technology leaders, the practical implication is not that current Essential Eight work becomes redundant. It is that the compliance target government teams have spent several years building toward is itself in motion, which reinforces rather than undermines the case for treating 2026 as a genuine planning inflection point rather than a routine reporting cycle.

Layered on top of that baseline, Horizon 2’s three objectives, strengthening the workforce, protecting critical infrastructure and government systems, and shaping and securing the technology environment (Department of Home Affairs, 2026), translate into direct expectations for government technology teams around logging and monitoring standards, government procurement arrangements, and deeper collaboration across Commonwealth, state, territory and local government through a proposed National Cyber Security Compact. None of this is abstract policy language. It is a work programme with a 2028 delivery horizon and named lead agencies, and it assumes agencies are already operating from the Essential Eight and ISM baseline rather than starting from it.

Evidence Snapshot

  • Horizon 2 (2026–28) is focused on strengthening cyber maturity across the Australian economy, society and digital infrastructure, building on the foundational work delivered under Horizon 1 (Department of Home Affairs, 2026)
  • The Horizon 2 Action Plan sets out 19 actions and 64 initiatives, to be led or co-led by 12 Australian Government agencies, for delivery by the end of 2028 (Department of Home Affairs, 2026)
  • Essential Eight Maturity Level 2 has been mandatory for non-corporate Commonwealth entities under PSPF Policy 10 since 1 July 2022 (ASD, 2024)
  • Cyber Action Year 2026 urges Australian organisations, government included, to adopt an assumed-breach mindset: planning on the premise of if, not when, a compromise occurs (ASD, 2026)
  • Government agencies accounted for 33 per cent of all cyber security incidents responded to by ASD in 2024–25, with 408 incidents reported in the financial year (ASD, 2025)
  • ASD recommends organisations cease using traditional asymmetric cryptography, including RSA, DH, ECDH and ECDSA, by the end of 2030, with a refined transition plan expected by the end of 2026 (ASD, 2025)

The Post-Quantum Priority for Government

Post-quantum cryptography planning was introduced earlier in this edition as a 2026 priority for Australian organisations generally. For government specifically, the case is sharper. Government agencies hold a disproportionate share of the long-lived, highly sensitive data that makes an organisation a priority target for what security agencies describe as “harvest now, decrypt later” activity: encrypted data collected today by an adversary with the patience to hold it until quantum computing capability matures enough to decrypt it. Classified material, ministerial communications and long-retention citizen records commonly carry confidentiality requirements measured in decades rather than years, which is precisely the profile that makes current encryption’s time horizon a genuine planning problem rather than a theoretical one.

ASD’s Information Security Manual recommends ceasing the use of traditional asymmetric cryptography, including RSA, Diffie-Hellman, Elliptic Curve Diffie-Hellman and ECDSA, by the end of 2030, with a recommended milestone of having a refined transition plan in place by the end of this year (ASD, 2025). For government technology leaders, that milestone lands inside the current planning cycle, not a future one. Orro has covered the practical mechanics of prioritising post-quantum migration, including how to run a data longevity assessment across an organisation’s data estate, in a dedicated piece: Store Now, Decrypt Later: The 2026 Post-Quantum Risk. The detail is not repeated here. What is worth stating plainly in a government and public sector context is that the sequencing logic in that piece, prioritising migration by data longevity rather than by when quantum computing is expected to mature, points toward classified and long-retention government data as a first-mover category almost by definition.

Why Sovereign, Australian-Owned Delivery Matters Here

The Strategy’s six cyber shields include Sovereign Capabilities: building Australia’s own cyber strength through its people, ideas and innovation (Department of Home Affairs, 2026). As Horizon 2 scales cyber maturity across government, this shield gives sovereign, Australian-owned delivery a genuine strategic basis rather than a procurement preference dressed up as policy. For government technology leaders assessing managed service and security partners under Horizon 2, the shield translates into practical questions: where security operations are based, who holds and processes threat intelligence, and whether a partner’s operations are subject to Australian law and oversight rather than a foreign jurisdiction that could compel different behaviour.

This is not a case Orro needs to overstate. The Strategy makes it directly. As government agencies scale their cyber maturity programmes under Horizon 2, and as post-quantum migration planning brings classified and long-retention data into sharper focus, the question of where and by whom that data is handled becomes a more material consideration, not a less material one. Sovereign delivery matters more as this scales, precisely because the Strategy’s own architecture says so.

Proof in Practice

Orro’s work with a large Australian state government on a vulnerability management programme reflects the kind of practical maturity uplift Horizon 2 is asking government technology teams to deliver at scale. The engagement centred on moving from point-in-time vulnerability assessment toward a continuous, risk-prioritised approach to identifying and remediating exposure across a complex government technology estate, the same shift from compliance snapshot to operational visibility that underpins much of the Horizon 2 direction. The outcome was a measurable improvement in the agency’s ability to identify, prioritise and close exposure gaps on an ongoing basis, rather than relying solely on periodic assessment cycles to surface risk.

What Government Technology Leaders Should Ask This Month

Horizon 2’s launch is a reasonable prompt to test current assumptions rather than simply file the Action Plan for later reading. Government technology leaders should be asking whether their Essential Eight and ISM baseline is genuinely current, given ASD’s own consultation on evolving the framework, rather than assuming a prior audit result still holds. They should be asking whether their organisation has a refined post-quantum transition plan in progress ahead of ASD’s end-of-2026 milestone, and if not, which data categories would sit first in that plan given their retention and classification profile. They should be asking whether their current security operations and managed service arrangements would hold up against the sovereign capability questions the Strategy’s shields raise, particularly around where threat intelligence is processed and under whose legal jurisdiction. And they should be asking whether their organisation’s posture assumes prevention will hold, or whether it has genuinely adopted the assumed-breach planning Cyber Action Year is asking for.

None of these questions require waiting for further detail from government. The direction is established, the milestones are dated, and the planning window is open now.

Closing

Horizon 2 does not ask government and public sector technology leaders to start again. It asks them to treat 2026 as the year the pace changes, on a foundation most are already building. Between the Essential Eight framework itself moving, the post-quantum transition milestone landing this year, and Cyber Action Year’s assumed-breach expectation, the case for a structured readiness check this month is a practical one. Orro’s Cyber Action Year Readiness Checklist, referenced earlier in this edition, offers a starting point for that check.

Sources & Further Reading