Home Affairs issues new PSPF Direction in wake of Medicare incident
In the wake of the recent OpenAI hack of Medicare data, the Secretary of the Department of Home Affairs issued on Tuesday a mandatory Direction under the Protective Security Policy Framework (PSPF) to government entities in order to manage a protective security risk to the Commonwealth.
PSPF Direction 002-2026 — Commonwealth Cyber Posture Against Al-Enabled Risks requires Australian Government entities to reduce cybersecurity risks arising from vulnerable legacy technology systems and to strengthen cyber posture across Australian Government systems.
The direction states that “in the contemporary cyber threat environment, where frontier Al capabilities have targeted the Commonwealth’s technology estate, the continued operation of vulnerable legacy technology systems, coupled with the accumulation of exploitable cyber security vulnerabilities, poses an unacceptable risk to the Australian Government”.
The Direction also states that agencies should prioritise Systems of Government Significance (SoGS), while balancing system availability with security, particularly where systems are public-facing. Strengthening existing vulnerability and patching management processes for the entire technology estate are deemed critical.
Agencies are required to conduct a stocktake of legacy systems, prioritising public-facing systems, then develop and maintain a Legacy Technology Risk Management Plan to be incorporated into the agencies’ cybersecurity strategies. Agencies are also required to incorporate these measures and report completion to the Department of Home Affairs by 31 December this year.
Agencies should also apply the advice provided in Policy Advisory 001-2026 — Cyber Security Readiness in the Frontier AI Era.
Direction 002-20026 can be found here.
ACSC raises critical alert for vulnerabilities in two Citrix products
The ACSC has raised a critical 'act now' alert for vulnerabilities in Citrix NetScaler...
ACSC updates guidance on detecting and mitigating AD compromises
The Australian Cyber Security Centre has released updated guidance on detecting and mitigating...
Splunk advancements help deliver trusted AI on premises
Splunk AI features are now available on-premises with the release of Cisco AI POD...
