All Guides
Workforce Strategy

The Australian Cyber Workforce Playbook: what it means for your business

The Department of Home Affairs published the Australian Cyber Workforce Playbook to address the national cyber skills shortage. Here is what it actually says, what the numbers look like, who it affects, and what Australian businesses should do about it in plain English.

Last reviewed September 202615 min read

What the Playbook is

The Australian Cyber Workforce Playbook is a guidance document published by the Department of Home Affairs as part of the 2023-2030 Australian Cyber Security Strategy. It sits under Shield 4 of the strategy: a sovereign and resilient cyber industry. It is aimed at employers, educators, and government agencies, and it sets out how Australia will grow domestic cyber security capacity over the next decade.

The short version: Australia does not have enough cyber security professionals to meet demand, the gap is widening, and the Playbook describes the pathways the country will use to close it. Vocational education, university, apprenticeships, and bringing in career changers, women returning to work, and Australian Defence Force veterans.

The Playbook does not mandate anything. It is not legislation. But it is the closest thing Australia has to a national reference for what a healthy cyber workforce looks like, and it is what cyber insurers, prime contractors and procurement teams increasingly point to when they ask "show us your security people".

Read the original Playbook on homeaffairs.gov.au

By the numbers

Key figures cited across the Playbook, the APS Data, Digital and Cyber Workforce Plan 2025-30, and AustCyber's Sector Competitiveness Plan.

~30,000

Estimated cyber workforce shortfall in Australia by 2026 (Home Affairs / APS Data, Digital and Cyber Workforce Plan 2025-30)

AU$6.9B

Annual economic contribution of the Australian cyber security sector (Sector Competitiveness Plan 2023)

6 Shields

Strategic pillars of the 2023-2030 Australian Cyber Security Strategy. The Playbook sits under Shield 4: a sovereign cyber industry.

17%

Approximate share of the Australian cyber workforce who are women, well below the broader tech sector average

Numbers shift between reports. The Playbook itself does not pin down a single shortfall figure. The 30,000 figure cited above is from the APS Data, Digital and Cyber Workforce Plan 2025-30. AustCyber and the OECD have both documented similar magnitudes. Treat them as directional, not precise.

Why it matters for Australian businesses

Most Australian SMBs and mid-market businesses cannot recruit a full cyber security team. Even larger organisations struggle to fill senior roles, particularly outside Sydney and Melbourne. At the same time, expectations are going up. Cyber insurers, prime contractors, the Privacy Act 1988 notifiable data breaches scheme, the Security of Critical Infrastructure Act 2018, and the Defence Industry Security Program (DISP) all want documented security capability, not just intent.

The Playbook is the federal government acknowledging the problem and laying out the supply-side response. The demand-side response, on individual businesses, is to be honest about what they can hire, what they need to outsource, and how they will document the arrangement.

Three things are converging. The threat environment is getting worse (see the ASD Annual Cyber Threat Report 2024-25). The compliance environment is getting tighter (Privacy Act reforms, SOCI Act expansion). And the talent pool is not growing fast enough. The Playbook is the federal response to that pressure. Your business response is what you do next.

The four workforce pathways

The Playbook centres on four ways more Australians become cyber security professionals. Each has different time-to-productivity and different role suitability.

Vocational and TAFE

Cyber security traineeships and Certificate IV / Diploma pathways through TAFE NSW, TAFE Queensland, RMIT and others. Practical, faster to market, well suited to L1 and L2 SOC and helpdesk roles.

Strengths: Fast (12 to 24 months). Earn while you learn. Strong fit for SOC analyst, helpdesk and junior engineering roles.

Trade-offs: Less depth in governance, risk and compliance work. Graduates need a structured workplace mentor for at least the first year.

University

Undergraduate and postgraduate programs at Edith Cowan, UNSW, QUT, Deakin, Macquarie and others. Stronger fit for engineering, GRC, vCISO and cloud security roles where deeper theory matters.

Strengths: Strong theoretical foundation. Better fit for cloud security, identity engineering, GRC, threat intelligence and senior advisory roles.

Trade-offs: Slow (3 to 5 years). Graduates can lack practical operational experience. Often need a graduate program to bridge the gap.

Apprenticeships and traineeships

Federally supported cyber security apprenticeships under the Australian Apprenticeships system. Earn while you learn. The Playbook flags this as the fastest way to grow domestic capacity.

Strengths: Federal funding and incentives. Builds loyalty. Combines structured learning with real on-the-job exposure.

Trade-offs: Requires meaningful supervisor capacity inside the business. Not realistic for organisations under roughly 100 staff without an MSP partner.

Career changers and veterans

Mid-career professionals, ADF veterans, women returning to work, and people from adjacent IT roles. Often underused. The Playbook explicitly calls these groups out as untapped capacity.

Strengths: Mature judgement, existing professional networks, transferable skills. Veterans bring strong incident discipline.

Trade-offs: Often need a 6 to 12 month conversion pathway and modern tooling exposure. Pay expectations sometimes need calibration.

Roles, salaries and what they actually do

"Cyber security professional" covers a wide range of roles. Salaries below are indicative AUD ex super, drawn from public market data and Hays / Robert Walters salary surveys for FY25. Use them as a planning baseline, not a binding number.

RoleIndicative salaryWhat they actually do
Service desk / L1 SOC analyst$65k to $85kEntry-level. Most often filled via TAFE, traineeships and career changers. Backbone of co-managed IT delivery.
L2 SOC analyst / endpoint specialist$85k to $115kTwo to four years experience. EDR, identity, phishing triage, ticket escalation. Core MSP capability.
Identity / cloud security engineer$120k to $160kMicrosoft Entra, Conditional Access, Intune, Defender, Azure security. Hardest role to recruit for in regional Australia.
GRC / compliance lead$130k to $170kEssential Eight, ISO 27001, SMB1001, DISP. Often the first hire when a business is preparing for government or prime contractor work.
Penetration tester$120k to $180kCREST or OSCP credentialed. Very few sit in-house outside the big four banks and Defence primes.
CISO / Head of Information Security$200k to $400k+Realistic for organisations of roughly 250+ staff with specific compliance drivers. Most SMBs use a vCISO retainer instead.

Add roughly 25% on top of base salary for super, leave, training, tooling and recruiter fees when modelling true cost.

Metro vs regional reality

The national workforce shortage is not evenly distributed. Where you are based dramatically changes what is realistic. The Playbook acknowledges this and explicitly calls out regional Australia as a priority. Here is how that plays out in practice.

Sydney and Melbourne

Deepest talent pool. Strongest competition. Salaries trend toward the top of national bands. Time to hire 3 to 6 months for mid-level roles.

Brisbane, Perth and Canberra

Solid candidate pools, especially for government, Defence supply chain and resources sectors. Time to hire 4 to 8 months for senior roles.

Adelaide, Hobart and Darwin

Smaller pools but real capability, particularly via Defence and university feeds. Senior hires often need a relocation package.

Regional Queensland, NSW and WA

Acute shortages. Mackay, Townsville, Toowoomba, Newcastle, Bunbury, Karratha. Hiring a senior security engineer in-house is rarely viable. Co-managed IT is the norm, not the exception.

What it means for Australian SMBs

The Playbook is genuinely useful, but it is written for the country, not for a 40-person business in Mackay or a 120-person firm in Brisbane. For SMBs and mid-market businesses, the practical question is simpler: which security work do we do internally, and which do we outsource to a partner who already has the people?

Realistic options for Australian businesses

Hire a senior security lead

Realistic for organisations of roughly 250+ staff or those with specific compliance drivers. Expect 6 to 12 months to recruit in metro markets, longer in regional Australia. Salary $200k+ before super.

Co-managed IT with an Australian MSP

Your internal team focuses on business technology. The MSP delivers SOC, EDR, identity hardening, patching and incident response. Most common pattern for 30 to 250 staff. Predictable monthly cost.

Virtual CISO (vCISO) on retainer

Strategic security leadership without a full-time hire. Suits boards needing risk reporting, cyber insurance evidence, Essential Eight uplift or DISP readiness. Typically a few days per month.

Train internally with vendor pathways

Microsoft, Cisco, ACSC, AustCyber and TAFE all offer structured pathways. Slow but builds long-term capacity. Best paired with a co-managed arrangement during the build.

Apprenticeship or traineeship intake

For organisations of 100+ staff. Aligns with the Home Affairs Playbook recommendation. Federal funding and incentives are available through the Australian Apprenticeships system.

Sectors with the biggest workforce gaps

Some sectors feel the workforce shortage harder than others, usually because their compliance obligations are higher or because they operate outside metro markets where talent is concentrated.

Critical infrastructure (SOCI Act assets)

Energy, water, telco, ports, designated mining assets. CIRMP obligations under the Security of Critical Infrastructure Act 2018 require people who understand both OT and IT. Genuine national shortage.

Healthcare and aged care

Privacy Act 1988, Aged Care Act and My Health Records Act obligations on top of clinical pressure. Most providers cannot recruit a full-time CISO and rely on co-managed or vCISO arrangements.

Government and Defence supply chain (DISP)

Defence Industry Security Program membership requires documented security personnel and clearances. Hard to staff in regional Australia. Real impact on contract eligibility.

Mining services and engineering

FIFO crews, prime contractor security questionnaires, Essential Eight evidence. Few in-house security people. Most rely on outsourced uplift.

Professional services (legal, accounting, finance)

High-value targets for business email compromise and ransomware. Often run lean IT teams without a dedicated security function. Trust account fraud is the biggest exposure.

Education

Universities and large independent schools have CISOs. Most independent and Catholic schools do not. The OAIC Notifiable Data Breaches scheme still applies and student data is a high-value target.

Co-managed and vCISO as a workforce strategy

For most Australian businesses with 30 to 250 staff, the realistic answer to the Workforce Playbook is a co-managed IT arrangement, a vCISO retainer, or both. You keep the IT capability you have and you supplement it with a partner that already has SOC analysts, identity engineers, and senior security advisors on the bench.

Outsourcing security work does not remove your accountability. The Privacy Act 1988, the SOCI Act and your contractual obligations still sit with your business. A good partner documents the arrangement clearly so the responsibilities are obvious to insurers, auditors, and prime contractors.

Use Real Bytes as your MSP and MSSP

The Workforce Playbook describes the people Australian businesses need. We are one practical way to access those people without building the team yourself. Real Bytes operates as a combined Managed Service Provider (MSP) and Managed Security Service Provider (MSSP), based in Australia, with engineers and analysts you deal with by name.

That means one partner covers both your day-to-day IT (helpdesk, Microsoft 365, devices, infrastructure) and your security operations (SOC, EDR, identity hardening, incident response, Essential Eight uplift, vCISO advisory). No finger-pointing between an IT vendor and a separate security vendor when something goes wrong.

How we map to the Playbook's workforce roles

Role the Playbook expects you to haveHow Real Bytes covers it
L1 / L2 SOC analystAustralian-based service desk and SOC. Triage, EDR alerts, phishing review, ticket escalation, after-hours cover.
Identity and cloud security engineerMicrosoft Entra ID, Conditional Access, Intune, Defender for Endpoint and Defender for Office hardening, ongoing review.
Patch and vulnerability managementWindows, macOS, third-party app patching, server patching, vulnerability scanning, monthly evidence pack.
Incident response leadDocumented incident response runbook, OAIC notifiable data breach support, coordination with insurers and legal.
GRC / compliance leadEssential Eight uplift, SMB1001 / CyberCert preparation, cyber insurance evidence, prime contractor questionnaires, DISP support.
Strategic security leadership (CISO)Virtual CISO retainer. Board reporting, risk register, IT roadmap, annual security review.
Security awareness and trainingPhishing simulation, staff training campaigns, onboarding and offboarding security checks.

What you get from a single MSP / MSSP relationship

Australian staff, named engineers

No offshore handoff. Same team across IT and security so context does not get lost.

One contract, one invoice

Helpdesk, infrastructure, M365, SOC, EDR, vCISO and incident response under a single managed service agreement.

Evidence ready for insurers and primes

Documented Essential Eight maturity, patch evidence, identity policy, backup test logs, IR plan.

Predictable monthly cost

Per-user pricing with a clear baseline. No surprise invoices when something goes wrong.

Workforce capacity that scales

Add or reduce users without recruiting, training or losing institutional knowledge.

Aligned to Australian regulation

Privacy Act 1988, OAIC NDB scheme, SOCI Act, DISP, ACSC Essential Eight, SMB1001 / CyberCert.

Not sure which model fits?

Most Australian businesses with 30 to 250 staff use a co-managed IT arrangement plus a vCISO retainer. Larger organisations with a stronger internal team often use us as a pure MSSP for SOC, EDR and incident response only. We can talk you through which model fits your size, sector and compliance drivers in 30 minutes.

Book a workforce gap conversation

Common mistakes Australian businesses make

We see the same five patterns when we sit down with a new client and review their security workforce. The Playbook addresses most of them indirectly. Here they are explicitly.

Hiring a single in-house security person and assuming you are covered

One person cannot run identity, endpoint, email, patching, monitoring, incident response, GRC and board reporting. They will burn out or leave. Plan for at least three people, or use a co-managed arrangement.

Treating cyber as an IT problem only

The Playbook is explicit: cyber is a workforce, governance and culture problem. Boards, HR, finance and operations all need defined cyber responsibilities. Insurers and auditors will ask.

Outsourcing without documenting accountability

You can delegate the work. You cannot delegate the legal accountability under the Privacy Act, the SOCI Act or your contractual obligations. Document who does what, in writing.

Skipping training because you have an MSP

Even with the best MSP, your staff are still the entry point for phishing, BEC and accidental data leaks. Annual security awareness training is a baseline expectation under most cyber insurance policies.

Over-relying on offshore talent

Offshore SOC and helpdesk can work, but Defence, government and many cyber insurance policies require Australian-based staff. Check your contracts before assuming offshore is fine.

A practical seven-step action plan

If you are reading the Playbook and wondering where to start, this is the order we usually recommend.

Map your current security workload across identity, endpoint, email, backup, monitoring and incident response. Be honest about what is actually being done versus what should be.
Identify the two or three areas where you have no in-house capability at all. These are your highest risk gaps.
Decide which gaps you will close internally over the next 12 months and which you will close through a co-managed or vCISO arrangement.
Document your security workforce plan as part of your broader IT roadmap. Cyber insurers, prime contractors and DISP assessors increasingly ask for this.
If you are eligible, explore federally supported cyber apprenticeships and traineeships through the Australian Apprenticeships system.
Add security awareness training, phishing simulation and a basic incident response runbook for non-technical staff. The Playbook treats this as workforce capacity, not just user training.
Review the plan annually against the Home Affairs Playbook and the 2023-2030 Australian Cyber Security Strategy refresh cycle.

Frequently asked questions

What is the Australian Cyber Workforce Playbook?

It is a guidance document published by the Department of Home Affairs that outlines how Australian organisations can attract, develop and retain cyber security talent. It sits under Shield 4 of the 2023-2030 Australian Cyber Security Strategy and identifies vocational, university, apprenticeship and career-change pathways into the profession.

How big is the cyber workforce shortage in Australia?

The APS Data, Digital and Cyber Workforce Plan 2025-30 references an estimated cyber workforce shortfall of around 30,000 by 2026. AustCyber and successive Home Affairs reports have flagged a similar order of magnitude. The exact figure shifts each year, but the consistent message is that demand outstrips domestic supply, particularly in regional Australia and in OT-aware roles for SOCI Act critical infrastructure.

Does the Playbook apply to small and medium businesses?

Yes. While much of the language is framed around national capacity, the recommendations on apprenticeships, career changers and structured training pathways are directly applicable to SMBs. For most Australian SMBs, a co-managed IT or vCISO arrangement is the practical way to act on the Playbook without trying to hire a full security team.

How does this connect to the Essential Eight, SMB1001 and the SOCI Act?

The ACSC Essential Eight and SMB1001 (CyberCert) are control frameworks. The SOCI Act and DISP are regulatory regimes. The Workforce Playbook is about the people needed to implement and maintain those controls and meet those obligations. You can buy tools but you still need someone, internal or external, to run them. Most Australian SMBs solve this by combining a small internal team with a co-managed MSP.

What does it actually cost to staff a small in-house security function?

A realistic minimum in-house function is one identity / cloud engineer ($120k to $160k), one SOC analyst ($85k to $115k) and a part-time GRC lead ($60k to $80k pro-rata). Add roughly 25% on top for super, leave, training, tooling and recruiter fees. Most businesses under 200 staff find a co-managed IT arrangement is cheaper and more resilient than hiring all three.

Where can I read the original document?

The Australian Cyber Workforce Playbook is published by the Department of Home Affairs and available on the homeaffairs.gov.au cyber security site. We recommend reading it alongside the 2023-2030 Australian Cyber Security Strategy, the APS Data, Digital and Cyber Workforce Plan 2025-30, and the ACSC Essential Eight Maturity Model.

Can Real Bytes help us act on the Playbook?

Yes. We work with Australian businesses across Brisbane, regional Queensland and nationally. Most of our clients use a combination of co-managed IT, vCISO advisory and structured Essential Eight uplift to close workforce gaps without trying to recruit a full internal security function.

Sources and further reading

All figures and references in this guide are drawn from publicly available Australian government and industry sources.

Cannot hire a full security team? Most Australian SMBs cannot.

Real Bytes works alongside your internal IT team or replaces it where needed. Co-managed IT, vCISO advisory, and Essential Eight uplift, all delivered from Australia.