Why Zero Trust is now a mandate for Australian government agencies

Public sector cyber breaches no longer begin with a sophisticated technical exploit. Today, attackers are just as likely to sign in using a stolen credential, then move quietly through trusted systems to reach their target. It is a change in attack behaviour that demands a fundamentally different approach to security.
Optus and Zscaler have partnered with The Mandarin, Australia's leading publication for public sector leaders, to explore how government agencies can respond. The result is a new eBook, Zero Trust in the public sector: From concept to capability, setting out what Zero Trust means for Australian government, why it has become a strategic priority, and how agencies can make the transition in a structured, achievable way.
Public sector agencies are high-value targets. They hold large volumes of sensitive personal, financial, and national data, and they operate critical services that citizens and economies depend on. When disruption occurs, the impact is immediate and visible.
Traditional security models were built to defend a network perimeter. But in a world of cloud services, hybrid workforces, and complex digital ecosystems, that perimeter has dissolved. Attackers are no longer breaking in. They are signing in.
Zero Trust addresses this directly. Rather than granting implicit trust based on location, it continuously verifies every access request based on identity, device posture, behaviour and context. Access is limited to only what is required, for only as long as it is needed.
Sean Connelly spent 11 years at the US Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) as Zero Trust Initiative Director. He co-authored the foundational NIST SP 800-207 and CISA Zero Trust Maturity Model. Now Senior Director for Global Zero Trust Strategy and Policy at Zscaler, Connelly is helping governments around the world implement Zero Trust principles.
“Zero Trust is not about buying more tools. It is about interoperability and visibility, enabling faster, better understanding of what is happening across the environment.”
– Sean Connelly, Senior Director, Governance, Risk & Compliance at Zscaler
Connelly's experience implementing Zero Trust across US federal agencies shows that the technology is only part of the challenge. Success depends on stakeholder alignment, clear communication, and a shared understanding of how security enables mission outcomes.
“The agencies that were more successful were the ones that had weekly meetings with different stakeholders and system owners. They explained what Zero Trust was going to mean on a tactical level. Ultimately, they needed to see how security was going to enable their mission in ways that were not possible before.”
– Sean Connelly
Government frameworks are increasingly clear about the direction of travel. The 2025 Protective Security Policy Framework (PSPF) sets mandatory requirements for Commonwealth entities that align closely with Zero Trust principles. The Australian Signals Directorate's Modern Defensible Architecture (MDA), Information Security Manual (ISM), and Essential Eight maturity model form a policy-to-architecture continuum providing agencies with both the obligation and the pathway.
At the state level, Zero Trust is called out explicitly. The NSW 2026–2028 Government Cyber Security Strategy describes it as a critical requirement for cyber resilience. Similar commitments appear in Queensland, South Australia, and Victoria. Globally, the United States, United Kingdom, Singapore, Canada, and the European Union have all directed agencies to adopt Zero Trust principles.
For agencies looking to act, the message from Kavin Arnasalon, Head of Government at Optus Enterprise and Business, is clear: Zero Trust is not a security project. It is an organisation-wide transformation.
"Zero Trust requires organisation-wide architectural change that impacts business operations, risk appetite, and digital transformation, not just security tooling. As such, it requires executive and board-level ownership, not just security leadership."
— Kavin Arnasalon, Head of Government, Optus Enterprise and Business
That means Zero Trust needs to be implemented as a staged, risk-managed program. Capabilities should be sequenced deliberately, starting with high-risk and high-value areas. Identity, visibility, and access control are foundational. Security capabilities need to be integrated so that identity, endpoint, network, and monitoring controls work together to enable consistent, context-aware decisions across the environment.
Optus and Zscaler are working together to help Australian public sector agencies deliver Zero Trust as a structured, outcome-driven transformation. Zscaler provides a cloud-native, identity-led Zero Trust platform. Optus brings the underlying network and security layer, architectural leadership, integration capability, and local operational experience.
Together, the partnership enables agencies to strengthen resilience and contain threats before they escalate, maintain service continuity through a staged transition, align with the PSPF, ASD MDA, and Essential Eight, and reduce architectural complexity while accelerating digital transformation.
Our new eBook, Zero Trust in the public sector: From concept to capability, covers the full picture — the Australian regulatory landscape, lessons from US federal implementation, a practical path to adoption, and how to build a compelling business case for leadership.
Project Aurora: Smarter Satellite Servicing for a connected future
12 August 2026
For decades, the satellite industry followed a simple model: build a satellite, launch it into orbit and operate it until i...
Moving faster from threat detection to response with Optus Managed Threat Monitoring Service
12 August 2026
The average organisation takes days to detect a breach, often because the signals were there, buried under a mountain of al...
Connected care, made simple: enabling smarter healthcare environments
28 July 2026
In healthcare, continuity and reliability are fundamental. When systems fail, the effects ripple quickly through clinical w...
