What success looks like
- NSW Government agencies operate with greater confidence and consistency in managing cyber risks.
- Supported by Cyber Security NSW’s strategic leadership and strengthened governance and assurance, agencies have clearly defined roles and decision-making pathways to enable faster, more coordinated responses to incidents.
- Operational Technology (OT), Internet of Things (IoT) and critical infrastructure are secured through consistent, risk-based practices, aligned with all-of-government standards. Third-party and supply chain risks are proactively managed through improved coordination and shared threat intelligence.
- Compliance with the NSW Cyber Security Policy is robust and transparent, enabling insights that support continuous improvement and informed investment.
- Agencies actively embed the NSW Artificial Intelligence Ethics Policy and comply with the NSW AI Assessment Framework to manage AI safely and adapt to emerging risks in a dynamic digital environment.
Goal for Objective 1
Embed mature, resilient and consistent cyber governance and risk practices.
More objectives
Progress we’ve made in this area
Building foundational capacity in cyber risk management
NSW Government agencies are continuously strengthening their cyber resilience. Departments and agencies are focused on proactively identifying and mitigating potential threats before they escalate into confirmed incidents. Cyber Security NSW is driving a whole-of-government uplift in risk management, governance, and compliance to strengthen cyber resilience.
Mandating targeted initiatives
Cyber Security NSW has issued Directive DCS-2025-04 – Targeted Initiatives for NSW Government, setting clear expectations for NSW Government agencies to prioritise uplift and achieve compliance with key Mandatory Requirements under the NSW Cyber Security Policy.
The directive also introduces additional reporting obligations to Cyber Security NSW.
Strengthening agency responsibilities
All NSW Government agencies must:
- report cyber security incidents within 24 hours
- maintain inventories and lifecycle management plans for all critical assets, including OT, IoT and cloud
- document and assess third-party providers to strengthen cyber supply chain risk management.
Expanding leadership roles
The directive broadens responsibilities for Secretaries, CISOs, and Portfolio CISOs to ensure stronger compliance, collaboration, and governance across government.
New posture and asset reporting requirements
From 31 October 2025, agencies must assess their posture against defined whole-of-government cyber risks and submit an inventory of their crown jewel assets as part of the NSW Cyber Security Policy reporting cycle.
Practical support for agencies
To enable efficient and consistent compliance, Cyber Security NSW has developed practical tools and templates to support the enhanced reporting requirements for agencies.
