Key Takeaways
- Australia’s current cybersecurity approach relies heavily on guidance and voluntary compliance, which is no longer adequate given the rising frequency and impact of cyber incidents.
- Modeling a cybersecurity regulator on bodies like the Therapeutic Goods Administration (TGA) would give the Australian Cyber Security Centre (ACSC) authority to set standards, certify high‑risk products, investigate major breaches, and enforce remediation.
- The Australian Signals Directorate (ASD) would retain its operational cyber‑defence, intelligence, and national‑security missions, creating a clear split between regulation and defence.
- The Cyber Security Act 2024 is an important first step, but a mature regulatory framework—building on that act—is needed to treat cybersecurity as a public‑safety and national‑resilience issue.
- Key regulator functions would include establishing mandatory baseline standards, certifying critical technologies, conducting formal incident investigations, mandating corrective actions, and imposing penalties for non‑compliance.
Current State of Australia’s Cybersecurity Framework
Over the past decade Australia has developed a relatively mature cybersecurity ecosystem, characterised by national strategies, information‑sharing centres, and partnership programs with industry. However, the core of this system remains advisory: agencies issue guidance, promote best‑practice frameworks, and rely on organisations to adopt measures voluntarily. While this approach has yielded improvements in awareness and basic hygiene, it lacks the teeth to compel uniform, risk‑appropriate safeguards across critical sectors. As cyber threats grow more sophisticated and damaging, the limits of a purely voluntary model become evident, prompting calls for a more authoritative regulatory presence.
Why Voluntary Measures Are Insufficient
Market forces alone do not consistently drive sufficient investment in cybersecurity because the costs of failure are often externalised onto customers, citizens, and the broader economy. Organisations may view security as a cost centre rather than a competitive advantage, leading to underinvestment, especially where short‑term profits are prioritised. Recent high‑profile incidents—massive data breaches, ransomware attacks on health providers, supply‑chain compromises, and intrusions into critical infrastructure—demonstrate that systemic weaknesses persist despite widespread awareness of cyber risk. When the consequences of a breach can affect national safety, economic stability, and essential services, reliance on voluntary compliance is increasingly untenable.
Lessons from Other Regulated Sectors
Australia already trusts specialised regulators to protect public safety in domains such as medicines (TGA), aviation, food, and nuclear facilities. These bodies set mandatory standards, conduct product certification, monitor compliance, and enforce penalties when standards are not met. The underlying principle is that certain risks are too consequential to be left to market discipline alone. Cybersecurity now mirrors those sectors: vulnerabilities in software, hardware, or services can precipitate cascading failures that threaten health, energy, finance, and governance. Applying a similar regulatory logic to cybersecurity would align Australia’s approach with proven models of risk management.
The Cyber Security Act 2024 as a Foundation
The Cyber Security Act 2024 introduced new obligations, reporting mechanisms, and assurance measures, signalling a shift away from a purely voluntary paradigm. It established baseline reporting requirements for significant cyber incidents, expanded the scope of entities covered, and created pathways for assurance assessments. However, the act is best viewed as an initial step rather than a finished product—much like early health‑and‑safety legislation that later gave rise to modern regulators such as the TGA and ARPANSA. To realise the act’s full potential, Australia needs an empowered institution capable of translating its provisions into enforceable rules, certification schemes, and compliance oversight.
Proposed Role and Powers of an Empowered ACSC
The Australian Cyber Security Centre should evolve into a formal cybersecurity regulator with a mandate comparable to that of the TGA in health. Its core functions would include: setting minimum cybersecurity standards for critical sectors, certifying high‑risk products and services before deployment, investigating major cyber incidents, mandating remediation of identified vulnerabilities, and enforcing compliance through civil penalties or other sanctions. By assuming these responsibilities, the ACSC would shift from a primarily advisory and support role to one that can compel action, thereby reducing reliance on goodwill and raising the overall security baseline.
Setting Mandatory Cybersecurity Standards
A regulator‑led ACSC would establish compulsory baseline requirements tailored to the risk profiles of essential services—energy, water, telecommunications, finance, health, and government operations. These standards could encompass secure‑by‑design principles, mandatory multi‑factor authentication, comprehensive vulnerability‑management programs, timely patching, incident‑reporting obligations, and supply‑chain assurance measures. Unlike voluntary guidelines, compliance would be demonstrable through audits, certifications, or regular reporting, ensuring that organisations cannot simply opt out of necessary protections.
Certification of High‑Risk Technologies and Services
Just as medical devices must satisfy safety standards before entering the market, software and digital products used in critical environments should undergo independent security assessment prior to deployment. The ACSC could certify items such as industrial control systems, cloud service platforms supporting government functions, telecommunications equipment, and high‑risk artificial‑intelligence applications. Certification would provide a trusted signal that a product meets minimum security thresholds, reducing the likelihood of vulnerable components being embedded in national‑critical systems and giving procurers a clear basis for risk‑based purchasing decisions.
Incident Investigation, Remediation, and Enforcement
Presently, organisations affected by a cyber incident receive technical assistance and advice, but there is limited power to compel corrective action or sanction negligence. An empowered ACSC would have the authority to launch formal investigations into significant breaches, analyse root causes, issue public findings, and order specific remediation steps. Where entities fail to comply with directives, the regulator could impose fines, mandate audits, or, in extreme cases, restrict operation of non‑compliant systems. Such enforcement would create a stronger pre‑emptive incentive for organisations to invest in resilience, knowing that lapses will attract tangible consequences.
Separation of Regulatory Oversight from Operational Defence
To avoid conflating rule‑making with frontline defence, the Australian Signals Directorate (ASD) would retain its core mission of cyber threat intelligence, offensive cyber operations, incident‑response support, and national cyber defence. The ACSC, as an independent regulator, would focus exclusively on standards, certification, compliance monitoring, and public accountability. This separation mirrors arrangements in other sectors—where safety regulators set rules while operational agencies manage day‑to‑day activities and emergency response—ensuring that each body can excel in its distinct function without conflict of interest.
Strategic and National‑Security Rationale
Australia’s strategic environment is becoming more contested, with state‑sponsored cyber campaigns, increasing reliance on digital technologies, and the convergence of cyber risk with traditional national‑security concerns. A successful cyberattack can cripple energy grids, telecommunications networks, health services, financial markets, and government functions without a single kinetic shot. Treating cybersecurity as a matter of public safety and national resilience is therefore not merely prudent; it is essential for sustaining sovereignty and societal well‑being. Elevating the ACSC to a regulator aligns cybersecurity management with the rigor applied to other high‑impact risks, providing a durable framework to meet evolving threats.
Conclusion: Moving Toward a Mature Cyber Regulatory Model
The evidence is clear: voluntary guidance alone cannot safeguard Australia’s critical digital infrastructure against today’s sophisticated and pervasive cyber threats. By empowering the ACSC to act as a cybersecurity regulator—setting standards, certifying high‑risk technologies, investigating incidents, mandating remediation, and enforcing compliance—the nation would establish a proactive, accountable system akin to those that protect public health, safety, and other vital sectors. The Cyber Security Act 2024 offers a solid legislative foundation; building upon it with a dedicated regulator would complete the transition from advisory guidance to a mature, enforceable cybersecurity regime, bolstering national resilience in an increasingly digital world.

