Cyber Action Year 2026: What Australian Organisations Should Do
October 2026 is Cyber Security Action Month, not Cyber Security Awareness Month. The campaign has a new name, and this year it sits inside Cyber Action Year 2026, the Australian Signals Directorate's first year-long program to move Australian organisations from awareness to action. Whether you run a ten-person practice, a multi-venue hospitality group or a regulated financial services business, the ask is the same: pick the actions that fit your environment, start them in October and keep going for the rest of the year.
Below: what changed, what ASD's critical actions mean at different sizes, and the everyday habits for staff this month.
"Awareness alone is not enough."
Australian Signals Directorate, Cyber Action Year 2026What Is Cyber Action Year 2026?
Cyber Action Year is an ASD-led, industry-driven program running through 2026. For the first time, government, industry and critical infrastructure are working to a shared list of practical, measurable security outcomes rather than a single month of messaging. Cyber Security Action Month, run by the Department of Home Affairs every October, is the public-facing part of that effort, with the 2026 theme "Take a second. Stay secure."
Underneath both is an assumed breach mindset. Instead of only asking how to stop an attack, you also plan for what happens when one gets through: how quickly you would notice, how far it could spread, and how fast you could get back to operating. For a smaller business, that means knowing your answers before you need them. For a larger organisation, it means testing whether one compromised account can still reach the rest of the network.
ASD's Critical Actions, Scaled to Your Organisation
ASD's Cyber Action Year page lists six critical actions. Here is what each looks like in practice:
- Replace or mitigate legacy technology. Smaller teams should list out-of-support devices, such as PCs still on Windows 10 (end of support October 2025), old routers and POS terminals. Larger environments need a register of unsupported servers and line-of-business applications, with a replace or mitigate decision for each.
- Implement best practice event logging. At minimum, Microsoft 365 audit logging should be on and retained long enough to investigate a suspicious login. Larger organisations should centralise logs across endpoints, cloud and network so incidents are detected in hours, not months.
- Choose secure by design products and services. Ask vendors about multi-factor authentication and patching before buying. At scale, build this into procurement and third-party risk reviews.
- Prepare for AI-enabled cyber threats. AI makes phishing and voice impersonation more convincing. Every organisation needs a call-back rule for payment and bank detail changes. Larger organisations should also govern which AI tools staff can use with company data.
- Prepare for post-quantum cryptography. ASD recommends moving away from traditional asymmetric cryptography by the end of 2030. Larger organisations holding long-life sensitive data should start a cryptographic inventory now. Smaller ones should keep systems updatable and ask key vendors about their plans.
- Plan for isolation. Critical infrastructure entities should be ready to isolate systems and networks for up to three months. If you supply services to critical infrastructure, expect your clients to ask how you would support that.
For regulated organisations, these actions map directly to existing obligations: APRA CPS 234 and CPS 230 for financial services, and PCI DSS 4.0 for venues taking card payments. The ACSC Essential Eight remains the practical baseline to measure against while ASD consults on its successor, the Essentials series.
Five Everyday Actions for Cyber Security Action Month
The October campaign is aimed at people, not systems, so these apply to every staff member, from a sole bookkeeper to a 500-person workforce:
- Apply updates. Keep computers, phones and apps patched. Attackers scan for known, unpatched weaknesses automatically.
- Set long, unique passphrases. One reused password can unlock email, finance systems and remote access at once. A password manager makes this practical.
- Turn on multi-factor authentication. Start with email, banking and anything with admin access.
- Back up and test the restore. A backup nobody has restored is a guess. Test that files and systems actually come back.
- Pause on unexpected requests. Urgent payment changes and updated bank details are where many losses start. Confirm by phone using a number you already have.
Where to Get Free Help
The government's free Cyber Health Check at cyber.gov.au gives any organisation a plain-language starting point, and Scamwatch and ReportCyber are where to report a scam or incident. Smaller businesses can use the Cyber Wardens program for free staff training. The Parliamentary Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations is also running a preparedness survey until 29 January 2027.
Turning One Month Into a Year of Action
The point of Cyber Action Year is that none of this belongs to October alone. A workable rhythm is to run the everyday actions with staff this month, review legacy systems and logging before the end-of-year change freeze, and test backups and incident contacts every quarter.
Assumed breach planning scales with the organisation. For a small business it can fit on one page: which systems matter most, who you call first and who can approve shutting something down. For a larger organisation, run a tabletop exercise against a realistic scenario, such as a compromised executive mailbox, and fix the gaps it exposes.
How All IT Handles This
All IT works through these actions with clients all year, from small offices to multi-site groups: patching schedules, multi-factor authentication and passphrase hygiene, logging, legacy system planning, and the vendor coordination that comes with POS, TAB, gaming, payment gateway and compliance systems.
Support runs on monthly contracts with no lock-in, and chat response is under three minutes.
Cyber Security Action Month 2026 Stakeholder Toolkit, Department of Home Affairs
Planning for Post-Quantum Cryptography, Australian Signals Directorate
Select Committee on Cyber Security for Small to Medium Sized Businesses and Organisations, Parliament of Australia
ASD to retire Essential Eight cyber security framework within next two years, iTnews
All IT is a Sydney-based managed IT provider supporting SMB, mid-market and enterprise organisations across Sydney, Melbourne, Brisbane, the Gold Coast and Orange/Central West NSW.
Frequently Asked Questions
Take a Second This October
We will help you check your organisation against ASD's Cyber Action Year critical actions during Cyber Security Action Month.
