Cyber security is now a central component of the Defence Industry Security Program (DISP). For organisations seeking to work with Defence, meeting DISP cyber security requirements is no longer optional or secondary, it is a core expectation.
Many organisations underestimate this aspect of DISP, assuming that cyber security is only relevant to large contractors or highly classified environments. In reality, cyber security obligations apply across all DISP membership levels, with requirements scaling according to the sensitivity of information handled.
This article explains how cyber security fits within DISP, what is expected of organisations, and how cyber requirements increase as DISP membership levels rise.
Why cyber security matters under DISP
DISP exists to protect Defence information across the entire supply chain. As Defence systems, communications, and operations rely heavily on digital infrastructure, cyber compromise represents a significant security risk.
Cyber security under DISP is not only about protecting data. It is about preventing unauthorised access to Defence systems, protecting sensitive operational information, ensuring continuity of services supporting Defence activities, and reducing supply chain vulnerabilities.
For this reason, cyber security is treated as an integral part of an organisation’s overall security posture.
Where cyber security fits within DISP
DISP assesses security across four core domains: security governance, personnel security, physical security, and information and cyber security.
Cyber security requirements sit within the information and cyber security domain, but they intersect with governance, personnel behaviour, and physical controls. An organisation cannot meet DISP requirements by addressing cyber security in isolation. Policies, processes, and technical controls must align.
Cyber security expectations are risk-based
DISP cyber security requirements are risk-based, not one-size-fits-all.
The level of cyber maturity expected of an organisation depends on its DISP membership level, the classification of information handled, the systems used to store or process Defence information, and whether those systems connect to Defence or government networks.
As DISP membership levels increase, cyber security expectations increase accordingly.
Cyber security at Entry Level DISP
At Entry Level, organisations typically handle OFFICIAL or OFFICIAL: Sensitive information.
Cyber security expectations at this level focus on basic cyber hygiene, clear governance and accountability, and awareness of information handling obligations. Organisations are expected to demonstrate that information is stored and transmitted securely, systems are protected from common threats, and personnel understand their responsibilities.
While Entry Level cyber requirements are less prescriptive than higher levels, Defence still expects evidence of considered and implemented controls rather than informal practices.
Cyber security at DISP Level 1
DISP Level 1 applies where organisations handle PROTECTED information.
At this level, cyber security expectations become more structured. Organisations are expected to implement documented cyber security policies, control access to systems handling PROTECTED data, manage user privileges appropriately, protect systems against malware and unauthorised access, and have the ability to detect and respond to cyber incidents.
Controls must be demonstrable and consistently applied, not merely described in policy.
Cyber security at DISP Level 2
DISP Level 2 applies where organisations handle information classified up to SECRET.
Cyber security at this level is significantly more rigorous. Organisations are expected to implement stronger technical controls, apply structured risk management practices, demonstrate active monitoring and incident response capability, and protect systems against more sophisticated threats.
At Level 2, cyber security is often one of the most closely scrutinised aspects of DISP assessment, particularly where systems interface with Defence environments or store classified information.
Cyber security at DISP Level 3
DISP Level 3 applies where organisations handle TOP SECRET information.
At this level, cyber security controls are highly restrictive and tightly governed. Expectations typically include controlled system architectures, strict access segregation, enhanced monitoring and audit capability, formalised incident response and recovery planning, and strong assurance that systems cannot be compromised without detection.
Level 3 cyber security arrangements are uncommon and generally limited to organisations supporting highly sensitive Defence and national security activities.
Alignment with Australian Government cyber frameworks
DISP cyber security requirements are aligned with broader Australian Government cyber security expectations.
While DISP does not operate as a technical certification scheme, organisations are expected to demonstrate that their cyber controls align with recognised government standards appropriate to their risk profile. Defence focuses on whether controls are suitable, implemented, and effective, rather than whether a particular framework has been adopted in name alone.
How the Essential Eight fits into DISP cyber expectations
The Australian Government’s Essential Eight is a widely recognised cyber security framework designed to reduce exposure to common cyber threats.
While DISP does not mandate a single technical framework, organisations are increasingly expected to demonstrate that their cyber security controls align with recognised government standards. In practice, this often includes demonstrating alignment with the Essential Eight, particularly where systems handle PROTECTED or higher classified information.
The extent of Essential Eight implementation expected under DISP depends on the organisation’s DISP membership level, the classification of information handled, the systems and environments in use, and the level of risk associated with the organisation’s role.
For some organisations, this may involve partial implementation or staged uplift. For others—particularly those operating at higher DISP levels—more mature implementation may be expected.
Importantly, Defence assesses whether cyber controls are appropriate, implemented, and effective, rather than whether a framework has been adopted in name alone.
Cyber security governance under DISP
Cyber security under DISP is not purely technical.
Organisations are expected to demonstrate clear accountability for cyber security, defined roles and responsibilities, incident reporting and escalation processes, and ongoing risk assessment and review. Governance gaps are a common cause of DISP cyber findings, even where technical controls exist.
Common cyber security issues identified during DISP assessment
Several issues frequently delay DISP accreditation or require remediation. These include policies that are not implemented in practice, inconsistent access controls across systems, poor visibility of user privileges, limited incident response capability, and lack of evidence supporting claimed controls.
DISP assessments focus on evidence, not intention.
Maintaining cyber compliance after accreditation
Cyber security obligations do not end once DISP accreditation is granted.
Organisations must maintain cyber controls, monitor for emerging threats, update policies and systems as required, report incidents appropriately, and reflect changes in business operations. Cyber security is an ongoing operational requirement under DISP, not a one-time compliance activity.
Final thoughts
Cyber security is now a defining element of DISP accreditation.
For organisations working with Defence, cyber security demonstrates the ability to protect sensitive information in a connected, digital environment. Expectations scale with risk, but they apply to all DISP members.
Understanding cyber security requirements early allows organisations to plan realistically, align controls with operational needs, and avoid delays during DISP assessment. In DISP environments, cyber security is not separate from security, it is part of it.



