CREST Australia & New Zealand (CREST ANZ) has released a landmark policy paper calling for a new national focus on cyber security assurance to strengthen the resilience of Australia’s critical infrastructure and better protect the essential services upon which communities, businesses and government rely.
Titled Securing Australia’s Critical Infrastructure: A Policy Position on Cyber Security Assurance, Independent Testing and National Resilience, the publication represents the most significant policy initiative undertaken by CREST ANZ to date. Developed over several months through an extensive collaboration between the CREST ANZ Board and member organisations, the paper provides an evidence-based assessment of Australia’s current cyber security landscape, examines leading international practices and presents 25 practical recommendations designed to improve cyber resilience across critical infrastructure sectors.
The policy acknowledges the substantial progress Australia has made through the Security of Critical Infrastructure reforms and the 2023–2030 Australian Cyber Security Strategy. At the same time, it identifies opportunities to further strengthen the nation’s cyber resilience by increasing the use of independent cyber assurance, expanding operational technology security, improving board accountability, strengthening supply chain oversight and adopting nationally consistent approaches to measuring cyber maturity.
Importantly, the paper advocates for a shift in emphasis from regulatory compliance towards demonstrable assurance, arguing that organisations must not only implement cyber security controls but also independently validate that those controls are effective against increasingly sophisticated cyber threats.
CREST ANZ Chair David McEwen said the policy reflects both the maturity of Australia’s cyber security profession and the growing importance of independent assurance in protecting nationally significant infrastructure.
“Australia has established a strong legislative and regulatory foundation for protecting critical infrastructure. The next step is ensuring those frameworks consistently deliver resilient outcomes. This policy provides practical recommendations that build upon existing reforms and supports a collaborative approach between government, regulators, operators and industry to strengthen Australia’s long-term cyber resilience.”
A defining feature of the publication is the significant contribution made by CREST ANZ members. Cyber security professionals and member organisations from across Australia and New Zealand participated in consultations, technical reviews and policy discussions, contributing operational experience and practical insights from across the cyber security sector. Their collective expertise helped ensure the paper reflects the realities faced by organisations responsible for protecting critical infrastructure every day.
Chief Executive Officer George Bej said the publication demonstrates the value of industry collaboration in shaping public policy.
“This paper has been developed by the profession, for the benefit of the nation. Our members have generously shared their expertise, challenged assumptions and contributed practical experience to produce a policy position that is balanced, evidence-based and focused on delivering meaningful improvements in cyber resilience. It highlights the important role that accredited cyber security professionals and trusted assurance providers can play in supporting government and industry as Australia’s cyber security landscape continues to evolve.”
The release marks the first in a planned series of strategic policy publications from CREST ANZ addressing key cyber security issues affecting Australia and New Zealand. A second policy paper focusing on Digital Supply Chain Security is expected to be released in the coming weeks, further reinforcing CREST ANZ’s commitment to providing independent thought leadership, promoting professional standards and supporting practical, evidence-based policy that strengthens the security and resilience of the region’s digital economy.









