Chris Cubbage speaks with CyberPath technical program lead Jakub Zvěřina about Australia’s CyberPath Capability Framework and its role in the 2023–2030 Australian Cyber Security Strategy.
We unpack how the program aims to move beyond tick-box certifications toward evidence-based recognition, a dynamic guild model for industry input, and clear accountability in a human–AI augmented security landscape.
CyberPath, led by the Australian Computer Society (ACS) with AISA and Aus3C, has opened consultation on a national
capability model that would put greater weight on demonstrated, real-world performance as AI-enabled attacks increase the pressure on cyber teams.
The proposed model would:
- Keep qualifications and certifications as important evidence, but not proof of full proficiency on their own
- Allow capability to be demonstrated through workplace performance, simulations, incident records and independently validated work
- Set clearer expectations around where AI can perform cyber tasks and where human accountability must remain
- Help employers assess whether someone can perform under pressure, not just whether they hold the right credential
- The consultation comes as Australia needs another 54,000 cyber workers by 2030, while attacks are becoming faster and more automated.




