Start with current state, not future state
Most Australian roadmaps fail because they start with a target operating model. Start with the baseline instead — ACSC Essential Eight maturity, ISO 27001 control coverage, third-party risk posture and incident readiness. The gap between baseline and target is the roadmap.
The four-phase shape
A defensible 36-month structure
- Phase 0 — Establish baseline: Essential Eight maturity, ISO 27001 control coverage, third-party risk posture.
- Phase 1 (0–6 months) — Close high-loss, low-cost gaps: MFA, patching, application control, backups.
- Phase 2 (6–18 months) — Build the management system: ISMS, vendor risk programme, incident response capability.
- Phase 3 (18–36 months) — Strategic capability: identity modernisation, data-centric controls, AI governance under ISO 42001.
- Across all phases — Continuous reporting cadence to the audit committee and board.
How to prioritise initiatives
Score each initiative on three dimensions: reduction in residual risk per dollar, regulatory exposure closed and dependency unlock. The highest-loss, lowest-cost initiatives — MFA, patching, application control, tested backups — sit in Phase 1 every time. Identity modernisation, data classification and AI governance sit in Phase 3 because they deliver compounding value once the baseline is in place.
Tying initiatives to business outcomes
Every initiative on the roadmap should answer one question: what business outcome or obligation does this deliver? Initiatives that cannot answer that question do not belong on the roadmap. Replace "deploy SIEM" with "reduce mean time to detect material incidents from 14 days to 24 hours, supporting CPS 234 obligation 17(c)."
FOR LEADERS BUILDING THE NEXT ROADMAP
Get three ranked roadmap options in under 60 seconds.
FORTE/CYBERx structures the roadmap challenge against Essential Eight, ISO 27001, CPS 234 and your business outcomes — with a tactical plan attached.
Start a free missionReporting cadence the board expects
- Quarterly: roadmap progress, control coverage, residual risk movement.
- Bi-annually: refresh of threat-led scenarios and tabletop outcomes.
- Annually: full strategy review, Essential Eight maturity re-assessment, audit committee deep-dive.
- Post-incident: targeted update with control changes and roadmap re-sequencing.
FAQ
What should an Australian cybersecurity strategy roadmap include?
A defensible roadmap covers current state (against Essential Eight and ISO 27001:2022), target state, the prioritised initiatives that close the gap, sequencing across 18–36 months, investment envelope, ownership and measurable outcomes. It explicitly maps to APRA CPS 234 for regulated entities and to SOCI for critical infrastructure.
How long should a cybersecurity roadmap cover?
18 months is the operational horizon — initiatives with named owners, dependencies and committed budget. 36 months is the strategic horizon — capability themes and investment intent. Anything beyond 36 months in cyber is aspiration, not strategy.
How do you prioritise initiatives on the roadmap?
Prioritise by reduction in residual risk per dollar, regulatory exposure closed and dependency unlock. Use the ACSC Essential Eight maturity model as the operational lens and tie every initiative to a specific business outcome or obligation. Avoid prioritising by vendor demo strength.
Who owns the cybersecurity roadmap?
The CISO (or equivalent) owns the roadmap. The CIO/CTO owns the technology dependencies. The CEO sponsors the investment envelope. The board approves risk appetite. For APRA-regulated entities, the board is ultimately accountable under CPS 234 for the information security capability the roadmap delivers.