Skip to main content

A NSW Government website

Digital NSW

Objective 1

Strengthen risk management, governance and compliance.

People collaborating at computer workstations in a modern office environment

What success looks like

  • NSW Government agencies operate with greater confidence and consistency in managing cyber risks.
  • Supported by Cyber Security NSW’s strategic leadership and strengthened governance and assurance, agencies have clearly defined roles and decision-making pathways to enable faster, more coordinated responses to incidents.
  • Operational Technology (OT), Internet of Things (IoT) and critical infrastructure are secured through consistent, risk-based practices, aligned with all-of-government standards. Third-party and supply chain risks are proactively managed through improved coordination and shared threat intelligence.
  • Compliance with the NSW Cyber Security Policy is robust and transparent, enabling insights that support continuous improvement and informed investment.
  • Agencies actively embed the NSW Artificial Intelligence Ethics Policy and comply with the NSW AI Assessment Framework to manage AI safely and adapt to emerging risks in a dynamic digital environment.

Goal for Objective 1

Embed mature, resilient and consistent cyber governance and risk practices.

Progress we’ve made in this area

Building foundational capacity in cyber risk management

NSW Government agencies are continuously strengthening their cyber resilience. Departments and agencies are focused on proactively identifying and mitigating potential threats before they escalate into confirmed incidents. Cyber Security NSW is driving a whole-of-government uplift in risk management, governance, and compliance to strengthen cyber resilience.

Mandating targeted initiatives

Cyber Security NSW has issued Directive DCS-2025-04 – Targeted Initiatives for NSW Government, setting clear expectations for NSW Government agencies to prioritise uplift and achieve compliance with key Mandatory Requirements under the NSW Cyber Security Policy.

The directive also introduces additional reporting obligations to Cyber Security NSW.

Strengthening agency responsibilities

All NSW Government agencies must: 

  • report cyber security incidents within 24 hours
  • maintain inventories and lifecycle management plans for all critical assets, including OT, IoT and cloud
  • document and assess third-party providers to strengthen cyber supply chain risk management.

Expanding leadership roles

The directive broadens responsibilities for Secretaries, CISOs, and Portfolio CISOs to ensure stronger compliance, collaboration, and governance across government.

New posture and asset reporting requirements

From 31 October 2025, agencies must assess their posture against defined whole-of-government cyber risks and submit an inventory of their crown jewel assets as part of the NSW Cyber Security Policy reporting cycle.

Practical support for agencies

To enable efficient and consistent compliance, Cyber Security NSW has developed practical tools and templates to support the enhanced reporting requirements for agencies.

 

2026–2028 NSW Government Cyber Security Strategy

Download the strategy (PDF, 1.04 MB)

Contact us

Email our team: info@cyber.nsw.gov.au