Skip to main content

A NSW Government website

Digital NSW

Objective 3

Uplift cyber resilience.

Hands typing on a laptop keyboard

What success looks like

NSW Government agencies will continue to strengthen their resilience to cyber security threats and incidents, consistently meeting and building upon the minimum baseline set by the NSW Cyber Security Policy

Agencies will continue to strengthen their OT and IoT controls, with Cyber Security NSW identifying areas for improvement and reinforcing accountability through established governance mechanisms. This includes, but is not limited to, structured oversight and targeted reviews.

Coordination between emergency management and internal cyber response processes will be further strengthened, enabling more systematic prevention, response, and recovery from cyber incidents and related data breaches.

Agencies responsible for critical infrastructure will maintain a consistent and evolving approach to risk management, supported by strong collaboration across government to identify and manage risks.

Vendors supplying to the NSW Government will be rigorously vetted and held to high standards of cyber security best practice, with ongoing efforts to reduce third-party risk and strengthen security across the supply chain.
 

Goal for Objective 3

Strengthen all-of-government cyber resilience.

Progress we’ve made in this area

The NSW Government is actively implementing measures to strengthen cyber resilience. These initiatives are already underway and focus on improving compliance, emergency management, and reducing supply chain risk.

Current initiatives include:

  • Implementing the DCS-2025-04 Circular: Agencies are reporting cyber incidents within 24 hours and developing and maintaining an asset inventory and a register of third-party providers. As part of the NSW Cyber Security Policy reporting cycle, agencies are also required to assess their posture against defined all-of-government risks and submit an asset inventory of their crown jewels.
  • Implementing interim arrangements pending the redesign of the NSW State Cyber Security Emergency Plan and the NSW Cyber Incident Management Arrangements.

Agencies are working to meet requirements under the NSW Cyber Security Policy to ensure cyber security risks to information and systems are effectively managed. All agencies must report annually against the NSW Cyber Security Policy, demonstrating compliance with Mandatory Requirements and applying a risk-based approach to implementing controls.

 

2026–2028 NSW Government Cyber Security Strategy

Download the strategy (PDF, 1.04 MB)

Contact us

Email our team: info@cyber.nsw.gov.au