At the inaugural meeting of the Executive Cyber Council in November 2023, four working groups were established to address key priority areas of the 2023-2030 Australian Cyber Security Strategy (the Strategy) focused on priority areas: cyber workforce development, sovereign cyber capability, emerging technology, and small and medium business resilience.
Cyber Workforce Working Group
The Cyber Workforce Working Group focuses on building cyber workforce capacity, including alignment to a National Cyber Skills Framework (NCSF), development of guidance to support standardisation of Essential Eight cyber roles, and exploration of initiatives to attract and retain a diverse cyber workforce, including First Nations participation.
In February 2025, it hosted the Cyber Workforce Summit to align government and industry perspectives on workforce growth. The Summit provided an opportunity to bring together key government and industry stakeholders to consider how cyber workforce programs can be consistent, scalable and repeatable across industry. These include guidelines for a National Cyber Skills Framework, mapping cyber roles and pathways, and ensuring diversity and inclusion by design. In November 2025 the Australian Cyber Workforce Playbook was published.
The Playbook guides the creation of standardised capability profiles, supports both generalist and specialist skills, addresses emerging technology impacts, and promotes diversity, equity, and inclusion in cyber job opportunities and professional development. The resulting Australian Cyber Workforce Playbook guides the creation of standardised capability profiles, supports both generalist and specialist skills, addresses emerging technology impacts, and promotes diversity, equity, and inclusion in cyber job opportunities and professional development.
Sovereign Cyber Capability Working Group
The Sovereign Cyber Capability Working Group advances national efforts to build, maintain and enhance sovereign cyber capabilities, including the technological and behavioural measures required to support the resilience of critical services.
The Working Group delivered an Australian Cyber Exchange 2025 (ACE25) event in April 2025 to showcase Australia’s emerging cyber sovereign capabilities. ACE25 brought together leaders from government, industry and academia to profile and address critical opportunities and challenges within Australia's cyber security ecosystem.
This Working Group continues to build a Cyber Sovereign Capability Monitoring and Evaluation Framework to map and benchmark Australia’s cyber sovereign capabilities and explore their key dependencies, including the cyber workforce.
The Emerging Technology Working Group
The Emerging Technology Working Group considers how government and industry can collaboratively manage cyber security risks and opportunities associated with emerging technologies. Priority areas identified include artificial intelligence (AI), quantum computing, and Digital ID as major sources of cyber risk and opportunity.
The group is producing research and an industry casebook on AI to guide company boards on emerging technologies and security issues. It has hosted workshops to review current initiatives, explore potential pilot projects and assist in assessing industry's quantum readiness.
The Small and Medium Businesses Working Group
The Small and Medium Businesses Working Group supports small and medium businesses to strengthen their cyber security resilience and capability, aligned to Shield 1 (‘Strong businesses and citizens’) of the Strategy.
The Working Group is also considering how the Council can advocate for and support federally funded small business programs by actively promoting not-for-profit initiatives such as Digital Solutions, Cyber Wardens, and IDCARE.
In October 2024, the group launched the Stop the Hack campaign as part of Cyber Security Awareness Month. This campaign empowered small and medium businesses to implement stronger cyber security practices. They are now exploring how this cohort can continue receiving consistent messaging on cyber uplift including an effort to develop a long-term awareness initiative that ensures consistent messaging on cyber uplift for this cohort.
The Working Group is also considering how the Council can advocate for and support federally funded small business programs by actively promoting not-for-profit initiatives such as Digital Solutions, Cyber Wardens, and IDCARE.
In August 2024, the group hosted a Cyber Insurance Roundtable to provide insights and recommendations on the role cyber insurance could play in enhancing cyber security resilience among Australian small and medium businesses.
Threat Blocking Working Group
In October 2023, the National Cyber Intel Partnership (NCIP) created a smaller Threat Blocking Working Group to focus on phishing as a banking threat and to establish the use case through a small pilot program. This pilot program has matured into a threat blocking capability scheme (The Scheme).
The Scheme has focused on using existing access to threat intelligence data and existing threat blocking capabilities to build a simple connection to test the idea of enhanced information sharing and blocking as a proof of concept.
The Threat Blocking Working Group continues to optimise the Scheme to identify processes and limitations for increased sharing of threat intelligence with ‘threat blockers. Next steps include understanding any future streams to block against different threats, improving the veracity of intelligence sharing, and leveraging and aligning government and industry capabilities to share intelligence and block threats.
A subset of the Threat Blocking Working Group voluntarily participates in The Scheme. Inaugural participants of The Scheme included Westpac, Telstra, Woolworths and the Australian Signals Directorate. This group has since expanded to include ANZ Bank, National Australia Bank (NAB), Commonwealth Bank Australia (CBA), Optus and TPG.