Quick answer: The 2025 Protective Security Policy Framework ends compliance-by-checklist and places ultimate accountability squarely on the Accountable Authority of every entity. What that shift means for government policy, frameworks, and critical systems, services and infrastructure.
Originally published on LinkedIn: 27 February 2026.
For decades, protective security in the Australian public sector was a ghost in the machine, a series of dry, back-office IT checklists managed by siloed departments. The 2025 release of the Protective Security Policy Framework effectively ends that era.
Security is no longer an IT problem
Section 3.4 of the 2025 PSPF mandates an embedded security culture, moving security from the server room to the boardroom and integrating it into the thinking, practice and decision-making of every individual at every level. Embedded accountability now runs through mandatory SES-level oversight via Chief Security Officers and Chief Information Security Officers, with entities required to determine their own Security Risk Tolerance and identify a steward for each risk category.
Foreign ownership, control and influence
Procurement is now a front-line national security activity. Sections 6.1.3 and 6.2 require Accountable Authorities to assess whether a vendor's corporate structure allows a foreign interest to direct or decide matters affecting management or operations, covering jurisdictional risk, covert data collection and foreign government influence over business operations. The high-profile restriction on TikTok, prohibited on government devices except under CISO-approved, isolated, standalone-device arrangements with metadata scrubbing, is the test case for this broader framework.
The insider threat, intentional and unintentional
The framework moves beyond the malicious-spy trope to focus on the trusted insider, every employee and contractor with legitimate access, including the risk of catastrophic harm caused by simple negligence. This underpins a shift from "trust but verify" to a Zero Trust Culture built on continuous verification: no system or user is treated as inherently secure, regardless of prior clearance or tenure.
Preparing for the quantum era
Section 13.10.2 treats cryptographically relevant quantum computing as a today problem, not tomorrow's. Requirement 0212 mandates Post-Quantum Cryptography for all newly procured cryptographic equipment and software, a direct response to "harvest now, decrypt later" attacks in which encrypted data is stolen today to be broken once quantum computing matures.
Conclusion
The common thread across the 2025 release is a move away from the fortress mentality, building high walls and hoping they hold, toward organisational agility. In an environment where a coffee machine or a contractor's smartphone is a potential entry point, culture is now the framework's stated first line of defence.
Tony Ridley provides security, risk, safety and resilience advisory for organisations that need evidence-based, board-ready decision support. Contact us to discuss your requirements.