Plenty of organisations spend heavily on security and still cannot answer a simple board question: are we safer than we were last year, and how do you know? That gap is what a cybersecurity strategy closes. A strategy is not a firewall or a SIEM. It is the reasoning that decides which risks you treat, in what order, with what budget, and how you measure progress.
This guide walks through building one from a blank page, in a way that fits the Australian regulatory and threat environment. It mirrors the approach we take when delivering a virtual CISO engagement for an organisation that has tools but no plan.
Start with the business, not the technology
The most common failure is to begin with a control checklist. Begin instead with the business. What does the organisation actually do, what makes money or delivers the service, and what would hurt most if it stopped or leaked? A council protecting rates data and citizen services has a different threat model from a fintech holding payment credentials.
Identify your crown jewels: the handful of systems, datasets and processes the organisation genuinely cannot function without. Everything that follows is about protecting those proportionately. A strategy that treats every asset as equally important protects nothing well.
At the same time, capture the constraints: budget reality, available skills, regulatory obligations, and the organisation’s appetite for risk. A strategy that ignores these is a wishlist, not a plan.
Assess where you really are
You cannot plan a route without knowing your starting point. Run an honest current-state assessment against a recognised framework. For Australian organisations, the practical baseline is the Essential Eight, ideally assessed against a target maturity level rather than a simple pass or fail. Layer a broader framework over it, such as the NIST Cybersecurity Framework or ISO 27001, to cover governance, people and process areas the Essential Eight does not reach.
The assessment should cover more than technical controls. Look at governance and accountability, asset and identity management, detection and response capability, third-party and supply-chain risk, and your people and culture. Document the gaps as findings with evidence, not impressions. This becomes the factual basis for every investment decision you later defend to the board.
Be deliberately honest at this stage. The temptation is to grade the organisation generously, especially if the person running the assessment also runs the controls being assessed. That self-assessment bias is one of the most common reasons strategies later fail, because the roadmap is built on an inflated picture of current maturity. Where you can, validate findings with evidence such as configuration exports, logs and ticket data rather than relying on what people believe is in place. An independent assessment is valuable here precisely because an outsider has no incentive to flatter the current state.
Define the target state
Now decide where you need to be, and be specific. The target state is the maturity level you are aiming for in each capability area, justified by your risk appetite and obligations. Not everything needs to reach the highest maturity; that is rarely affordable or necessary. The skill is choosing the right level for each area based on the risk it addresses.
This is where a clear risk-based view earns its keep. If your defined risk appetite says a multi-day outage of a core service is unacceptable, your target state for resilience and recovery must be high. If you can tolerate brief disruption to a non-critical internal tool, do not gold-plate it. Tie every target back to a business reason so the spend is defensible.
Build a sequenced, costed roadmap
The gap between current and target state is your roadmap. Resist the urge to do everything at once; you will exhaust budget and goodwill. Sequence the work by risk reduction per dollar, dependencies, and quick wins that build momentum and credibility.
A practical structure most boards understand:
- Now (0 to 3 months). Close the dangerous, cheap gaps. Enforce MFA, patch internet-facing systems, fix backup and recovery, remove standing admin rights. High risk reduction, low cost.
- Next (3 to 12 months). Build foundational capability. Asset and identity management, centralised logging and detection, an incident response plan that is actually tested, third-party risk processes.
- Later (12 months plus). Mature and optimise. Threat-led testing, automation, security embedded into change and procurement, continuous improvement.
Cost each initiative honestly, including the people and ongoing operational cost, not just the licence. A tool with no one to run it is wasted money, and boards rightly distrust strategies that pretend operations are free.
Account for capability as well as cost. Many organisations buy capable tooling and then never realise its value because no one has the time or skill to operate it. Before adding a new platform to the roadmap, decide explicitly who will run it, whether that is internal staff, a managed service, or an outside partner. For smaller organisations and councils, a sensible roadmap often leans on managed services and a fractional CISO rather than trying to build a full in-house team that the budget cannot sustain.
Address people and supply chain explicitly
Two areas are routinely under-weighted in first strategies, and both deserve their own line in the roadmap. The first is people. Most incidents involve a human element, whether a clicked link, a reused password, or a misconfiguration. A strategy that pours money into technology while ignoring awareness, training and security culture is unbalanced. Build a sustained awareness program into the plan, not a once-a-year compliance video, and treat the security behaviour of staff as a measurable capability you are improving over time.
The second is third-party and supply-chain risk. Your security is only as strong as the suppliers who hold your data or connect to your systems, and several of the most damaging Australian incidents have originated with a vendor rather than the organisation itself. The strategy should include a process to assess suppliers proportionately to the risk they carry, contractual security expectations, and a way to monitor critical vendors over time. This connects directly to broader due diligence work and should not be left as an afterthought.
Set governance and metrics
A strategy without governance drifts. Define who owns it, how often it is reviewed, and how decisions get made when priorities clash. Establish a small set of metrics that show whether you are getting safer, not just busier. Vanity metrics like number of alerts mean little; meaningful metrics include patch latency on critical systems, percentage of privileged accounts with MFA, mean time to detect and respond, and progress against target maturity.
Report these to the board in business language. The board does not need to understand the SIEM; it needs to know whether the top risks are trending down and whether the investment is delivering. Good governance is also what keeps the strategy alive between annual reviews, with the roadmap revisited each quarter against the changing threat landscape.
Get it funded and keep it real
The best strategy fails if it is not funded, and funding follows a clear, honest narrative. Frame each initiative in terms of the risk it reduces and the consequence of inaction, using plain figures rather than fear. Boards fund strategies they understand and trust; they reject ones that feel like a blank cheque.
Finally, treat the strategy as a living document. The threat environment, your business and the regulatory landscape all move. Review formally each year, adjust the roadmap quarterly, and trigger an out-of-cycle review after any major incident, merger or new regulation.
Building a credible strategy from scratch is demanding, and many organisations do not have a full-time CISO to lead it. That is precisely the gap CISO Advisory fills for Australian local government and private sector organisations. If you would like help turning a blank page into a board-ready, funded plan, call 07 2112 8502 or get in touch.
Frequently asked questions
What is a cybersecurity strategy?
A cybersecurity strategy is a multi-year plan that connects your organisation's business objectives and risk appetite to a prioritised set of security investments and capabilities. It defines where you are now, where you need to be, and the sequenced, funded path between the two. It is a governance document, not a tool list.
How long does it take to build a cybersecurity strategy?
A focused strategy for a mid-sized organisation typically takes four to eight weeks: roughly two weeks of current-state assessment, two weeks of analysis and target-state design, and the remainder building the roadmap, costing it, and securing executive sign-off. Larger or regulated entities take longer because of stakeholder consultation.
What framework should an Australian organisation base its strategy on?
Most Australian organisations anchor to the Essential Eight as a baseline and the NIST Cybersecurity Framework or ISO 27001 for broader structure. Government bodies follow ISM and PSPF requirements; APRA-regulated entities must meet CPS 234. Choose the framework your regulators expect, then map controls to it.
Who should own the cybersecurity strategy?
Accountability sits with the board and executive, with the CISO or a virtual CISO owning development and delivery. Security cannot be delegated entirely to IT, because most decisions involve business risk trade-offs that only leadership can make. Clear ownership and an executive sponsor are what separate strategies that get funded from those that gather dust.
How often should a cybersecurity strategy be reviewed?
Review the strategy formally once a year and revisit the roadmap quarterly. Significant changes, such as a major incident, a new regulation, a merger, or a shift in the threat landscape, should trigger an out-of-cycle review. The threat environment moves too quickly for a fixed three-year plan to survive untouched.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.