Skip to main content

A NSW Government website

Digital NSW

Objective 2

Improve incident response and cyber intelligence capability.

Two IT professionals working in a data center, monitoring server racks using a laptop and network testing device

What success looks like

The NSW Government is working towards a more integrated and real-time understanding of the cyber threat landscape. This will enable earlier detection, faster risk minimisation, and more confident incident response.

Information sharing between agencies, Cyber Security NSW, and the Australian Government will become more streamlined, supporting intelligence-led decisions and reducing duplication.

Agencies will continue to report real or suspected cyber incidents, enabling Cyber Security NSW to synthesise intelligence, anticipate threats, and coordinate countermeasures that strengthen system-wide resilience and recovery.
 

Goal for Objective 2

Embed an intelligence-led and coordinated cyber response.

Progress we’ve made in this area

The cyber threat landscape has continued to shift in response to global events and evolving threat actor priorities. Cyber Security NSW is advancing the state’s cyber resilience through enhanced intelligence and coordinated response capabilities.

More frequent threat insights

NSW Government agencies report key threats, risks, incidents and mitigation activities to Cyber Security NSW under the NSW Cyber Security Policy. This reporting forms a critical part of the cyber security landscape, enabling Cyber Security NSW to monitor sector-wide activity, identify recurring vulnerabilities, and detect emerging trends.

To improve timeliness, Cyber Security NSW has shifted from an annual to a tri-annual threat assessment model. This ensures agencies and executive leaders receive relevant intelligence more often, enabling faster, better-informed decisions. These insights support a more informed and coordinated approach to cyber risk management across the NSW Government.

Strengthening NSW’s cyber emergency response capability

A major uplift of NSW’s cyber emergency response arrangements is underway, including a comprehensive uplift of incident and emergency response frameworks to enable faster, more coordinated action during significant cyber events. These reforms align NSW with national arrangements and address issues identified in a recent review around processes, escalation pathways, and post-incident practices.

Agencies will be required to implement these changes as part of their cyber security obligations. Interim measures are already in place, including a mandatory 24-hour incident reporting requirement, ensuring timely escalation and visibility across government.

Key activities currently underway include:

  • redesigning the State Cyber Security Emergency Plan and the NSW Cyber Incident Management Arrangements
  • embedding a revised incident categorisation matrix and integrating business continuity planning into these frameworks
  • the Cyber Incident Emergency Management Leadership Forum, established under the Cyber Security Steering Committee, is driving cross-government collaboration to ensure the new arrangements are coordinated, fit-for-purpose and aligned with agency needs.

 

2026–2028 NSW Government Cyber Security Strategy

Download the strategy (PDF, 1.04 MB)

Contact us

Email our team: info@cyber.nsw.gov.au