Sitemap

Cybersecurity and the Australian Federal Budget 2026

4 min readMay 12, 2026

--

I looked for the cybersecurity line items in the budget so you don’t have to.

Press enter or click to view image in full size

Initial Thoughts

After the deafening silence and complete lack of net-new cyber spending in the 2025 election-year budget, the government has opened its wallet again.

However, if you were hoping the hiatus would give them time to rethink their strategy, prepare to be disappointed. True to the exact behaviour we’ve tracked since 2021, the Australian government is firmly back to spending its cybersecurity, data, and privacy dollars almost entirely on itself.

In past years, we saw them pour billions into REDSPICE, create massive bureaucratic structures, and frantically secure their own citizen data honeypots. This year, the overarching theme is a massive push towards centralised digital identity and fraud prevention, specifically protecting the government’s own coffers from non-compliance and cyber fraud.

The numbers speak for themselves. When you add up all the cyber, digital security, privacy, and fraud-related items across the portfolios, the total spend comes to a staggering $1.7 billion. Yet, a closer look reveals exactly where that $1.7 billion is going. The government has allocated $654.3 million to the Digital ID system, over $500 million collectively to various fraud taskforces (Medicare, ATO, NDIA), and $160.4 million just on the internal cyber security uplift of Services Australia.

Compare that to the funding allocated to actually execute the 2023–30 Australian Cyber Security Strategy — Horizon 2. That initiative — the one theoretically designed to protect the nation as a whole — was granted just $89.3 million over four years.

Once again, there is a glaring lack of meaningful investment in the broader sovereign cyber ecosystem. Funding regulators to enforce compliance and protecting government payment systems is necessary, but it is not the same thing as supporting businesses to become cyber resilient. Until the government realises that national cyber resilience relies on a healthy ecosystem of local technology and solution providers — not just massively funded federal departments and fraud taskforces — we will continue to spin our wheels.

Spend

Here is a breakdown of the cyber-related items in the budget:

  • $654.3 million over four years from 2026–27 (and $166.7 million per year ongoing) to meet its legislative commitments under the Digital ID Act 2024 and maintain the security and reliability of the Australian Government’s Digital ID System. This funding is split across the Australian Taxation Office, Services Australia, the ACCC, the Department of Finance, the Office of the Australian Information Commissioner, Treasury, and ASIO.
  • $280.1 million over five years from 2025–26 (and $53.0 million per year ongoing) to continue the Fraud Fusion Taskforce and invest in the National Disability Insurance Agency to continue to detect and respond to fraud and non-compliant payments.
  • $160.4 million over four years from 2025–26 for the Services Australia Cyber Security Uplift program.
  • $146.8 million over four years from 2026–27 (and $17.6 million per year ongoing) to establish enhanced, expanded and ongoing Medicare integrity capabilities in the Department of Health, Disability and Ageing and Services Australia to improve non-compliance and fraud detection.
  • $89.3 million over four years from 2026–27 to the Department of Home Affairs to sustain and enhance cyber security initiatives under the 2023–30 Australian Cyber Security Strategy — Horizon 2.
  • $86.3 million over four years from 1 July 2026 (and $9.7 million per year ongoing from 2030–31) to deliver Phase 2 of the Counter Fraud Strategy to modernise the prevention and detection of fraud in the tax and super systems.
  • $66.9 million over four years from 2026–27 (and $21.2 million per year ongoing) to streamline and sustain AusCheck’s background checking services.
  • $62.0 million over two years from 2026–27 to extend the operation and participation in the Consumer Data Right.
  • $33.7 million in 2026–27 to improve the Aged Care Quality and Safety Commission’s ICT governance, delivery processes and internal cyber security capability.
  • $28.0 million over four years from 2026–27 (and $7.2 million per year ongoing) for the Australian Federal Police, Office of the Commonwealth Ombudsman, the Department of Home Affairs, the Australian Criminal Intelligence Commission and the Attorney-General’s Department to continue to support access to data for law enforcement and national security purposes under the AUS-US Data Access Agreement.
  • $26.5 million over three years from 2025–26 to improve the functionality, availability and security of the myGov platform.
  • $26.1 million over two years from 2026–27 to maintain the security and reliability of whole-of-government budget and financial management information and technology systems.
  • $18.5 million over four years from 2026–27 (and $2.2 million per year ongoing) to uplift the Australian Securities and Investments Commission and Australian Prudential Regulatory Authority’s capability to improve the security of systems of national significance.
  • $14.3 million over four years from 2026–27 (and $3.6 million per year ongoing) to continue the Commonwealth Fraud Prevention Centre.
  • $12.7 million in 2026–27 to extend the operation of the National Anti-Scam Centre to continue protecting consumers and businesses from scam activity for a further year.
  • The Government will also introduce a user charge to recover the cost of operating the SMS Sender ID Register from 2026–27.

Ian Yip is the founder and CEO of Avertro, a venture-backed cybersecurity software company.

--

--

Ian Yip
Ian Yip

Written by Ian Yip

Cyber Risk. Cybersecurity. Business. Tech. Entrepreneur. CEO at Avertro. Former CTO at McAfee Asia Pacific.