If you work in or supply to the NSW public sector, the NSW Cyber Security Policy is the document that defines your baseline obligations. It sets out the mandatory cyber security requirements for NSW Government agencies, ties them to an annual attestation signed by the agency head, and anchors maturity in the ACSC Essential Eight. This guide explains what the policy requires and how agencies meet it in practice.
What the NSW Cyber Security Policy is
The NSW Cyber Security Policy is the whole-of-government instrument that establishes mandatory cyber security requirements for NSW Government agencies. It exists to lift and standardise cyber resilience across the state public sector, moving agencies away from ad hoc, uneven security towards a consistent, measurable and accountable baseline.
Importantly, the policy is mandatory, not advisory. Agencies are required to implement its requirements and to report on how well they are doing so. It is best understood as the NSW state equivalent in spirit to the Commonwealth’s combination of the Protective Security Policy Framework and the Information Security Manual, though it is a distinct instrument with its own requirements and reporting lines. NSW agencies report through NSW Government channels, not through Commonwealth ones.
The mandatory requirements
The policy groups its obligations around a set of mandatory requirements that, taken together, cover the lifecycle of managing cyber risk. While the exact wording evolves between versions, the consistent themes agencies must address include the following.
- Leadership and governance. Agencies must allocate clear responsibility for cyber security, including a senior responsible officer, and embed it in their governance and risk management.
- A cyber security plan. Agencies are expected to maintain a plan that addresses their specific risks, integrates with broader risk management and is reviewed regularly.
- Building a cyber security culture. Awareness and training requirements ensure staff understand their role in protecting information and systems.
- Managing cyber security risks. Agencies must identify their crown jewels, assess risks and apply controls proportionate to those risks.
- Implementing the Essential Eight. The policy requires agencies to assess and uplift their maturity against the ACSC Essential Eight mitigation strategies.
- Detecting, responding to and recovering from incidents. Agencies must have incident response and reporting arrangements, including reporting significant incidents through the required channels.
The thread running through all of these is that cyber security is a governance responsibility, not just a technical one. The policy deliberately pushes accountability up to agency leadership, which is why the annual attestation matters so much.
The annual attestation and reporting
The defining accountability mechanism of the NSW Cyber Security Policy is its annual attestation and reporting cycle. Each year, agencies are required to attest to their level of compliance with the mandatory requirements and to report on their cyber security maturity, including their Essential Eight maturity.
The attestation is signed by the agency head. That signature is the point. It converts cyber security from something a CIO or security team quietly manages into an explicit, named accountability of the most senior person in the organisation. An agency head signing an attestation is personally affirming the state of their agency’s cyber posture, which changes the tenor of the conversation around resourcing and risk acceptance.
This is also why honesty in reporting is non-negotiable. The temptation to present a rosier picture than reality, particularly on Essential Eight maturity, is real, but it is the wrong move. Where an agency cannot meet a requirement, the policy’s risk-based approach expects the gap to be documented, the residual risk assessed, and the position accepted at the appropriate level. An accurate attestation that acknowledges gaps and a credible uplift plan is far more defensible than an optimistic one that does not survive scrutiny after an incident.
The central role of the Essential Eight
The Essential Eight sits at the heart of the NSW policy’s measurable expectations. The eight mitigation strategies, which include application control, patching applications and operating systems, configuring Microsoft Office macro settings, user application hardening, restricting administrative privileges, multi-factor authentication and regular backups, give agencies a concrete, assessable yardstick.
Because maturity against the Essential Eight is reported, agencies need a genuine, evidence-based understanding of where they sit across each strategy and each maturity level. This is more demanding than it first appears: maturity is assessed holistically, and partial implementation of a strategy does not earn the maturity level. Many agencies discover during honest assessment that they sit lower than assumed. Our Essential Eight explained guide sets out what each maturity level genuinely requires, and our broader Essential Eight service helps agencies move from a current-state assessment to a realistic uplift roadmap.
Reporting incidents and the wider ecosystem
The policy does not treat agencies as isolated islands. It sits within a wider NSW Government cyber security ecosystem coordinated centrally, and one of its consistent requirements is that agencies report significant cyber security incidents through the designated channels. This central visibility matters because attackers frequently reuse the same techniques across multiple agencies; an incident reported promptly by one agency can become an early warning that protects others.
For agency leaders, the practical implication is that incident handling cannot be purely internal and informal. There must be a defined trigger for what constitutes a reportable incident, a known process for escalating it, and people who understand their obligations before an incident happens rather than after. Bolting this together mid-crisis is how reportable incidents go unreported and how agencies compound a technical problem with a governance failure. A tested incident response plan that explicitly includes NSW Government reporting obligations is the answer.
Why agencies struggle, and what good looks like
In practice, the agencies that find the policy hardest tend to share a few characteristics: no dedicated security leadership, fragmented or undocumented systems, and a habit of treating the attestation as a once-a-year document exercise rather than the output of a continuous programme. The result is a last-minute scramble each year, optimistic maturity scores that nobody can fully evidence, and an agency head asked to sign an attestation they cannot truly stand behind.
What good looks like is markedly different. Mature agencies maintain a live picture of their Essential Eight maturity, supported by evidence they could produce on any given day. They have a multi-year uplift roadmap that ties investment to risk reduction, so each year’s attestation shows measurable progress. They have clear ownership, with a named senior responsible officer who briefs the agency head well before signing. And they integrate cyber risk into their enterprise risk management, so it competes for attention and funding alongside other organisational risks rather than sitting in a technical silo. The difference between these two postures is rarely budget alone; it is governance discipline and an honest baseline.
How NSW agencies should approach compliance
Meeting the policy well, rather than merely surviving the attestation, follows a logical path.
- Assign accountability. Confirm who the senior responsible officer is and ensure the agency head understands what they will be attesting to.
- Know your crown jewels. Identify the systems and information whose compromise would cause the most harm, and prioritise accordingly.
- Run an honest baseline. Assess current maturity against the mandatory requirements and the Essential Eight, with evidence rather than self-flattering assumptions.
- Build a prioritised uplift plan. Sequence improvements by risk reduction per dollar, and resource it realistically.
- Strengthen detect and respond. Ensure incident response, reporting and recovery arrangements are tested, not just documented.
- Prepare the attestation early. Treat it as the output of a year-round programme, not an end-of-year scramble.
Getting practical help
The NSW Cyber Security Policy is demanding precisely because it is meant to be: it pushes accountability to the top and insists on measurable, reported maturity. For agencies without a full-time chief information security officer, meeting it consistently year after year is a genuine challenge. This is where independent advisory support earns its keep, providing the baseline assessment, the uplift roadmap and the governance discipline that a credible attestation rests on.
CISO Advisory works with NSW Government departments and agencies, as well as local government across the state, to assess Essential Eight maturity, build practical uplift plans and prepare for attestation with evidence that holds up. Our virtual CISO and government and council cyber security services are designed for exactly this. To discuss your agency’s position ahead of the next reporting cycle, call 07 2112 8502.
The policy is not going to get less rigorous. Agencies that treat it as a continuous risk-management programme, anchored in honest Essential Eight maturity and senior accountability, will find the annual attestation becomes a confirmation of work already done rather than a moment of exposure.
Frequently asked questions
Who must comply with the NSW Cyber Security Policy?
The policy applies to NSW Government agencies, setting out mandatory requirements they must meet. Departments and agencies across the NSW public sector are expected to implement it, and many state-owned entities and bodies that handle NSW Government information are brought within its scope through their governance or contractual arrangements.
What is the annual attestation?
Each year, NSW agencies are required to attest to their compliance with the mandatory requirements of the policy and to report on their cyber security maturity. The attestation is signed by the agency head, making cyber security an explicit accountability of senior leadership rather than something delegated entirely to technical teams.
Does the NSW Cyber Security Policy require the Essential Eight?
Yes. The policy aligns with and requires implementation of the ACSC Essential Eight mitigation strategies. Agencies are expected to assess and improve their maturity against the Essential Eight, making it a core, measurable component of NSW Government cyber security obligations rather than optional best practice.
How is the NSW policy different from the Commonwealth PSPF and ISM?
The PSPF and ISM apply to Commonwealth entities, while the NSW Cyber Security Policy governs NSW state agencies. They share common ground, particularly the Essential Eight and a risk-based approach, but they are separate instruments with separate reporting lines. NSW agencies report through NSW Government channels, not Commonwealth ones.
What happens if an agency cannot meet a mandatory requirement?
The policy is risk-based, so where an agency cannot fully meet a requirement, it is expected to document the gap, assess the residual risk and have it accepted by the appropriate accountable officer. Honest reporting of gaps is far better than overstating maturity, because the attestation is a senior accountability and inaccurate reporting carries real governance consequences.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.