EXPLORE KNOWLEDGE BASE
-
CERI Knowledge Base
-
About the CERI knowledge base
-
Introduction to Australia’s electricity markets
-
Australian consumer insights
-
CER technical and interoperability standards
-
Connecting a customer to an electricity network
-
Connecting a generator to a distribution network
-
Utility interconnection (CSIP-AUS)
-
Dynamic network export and generation control schemes
-
Network load control schemes
-
Network tariffs and network support services
-
Participating in the National Electricity Market
-
Participating in a frequency control market
-
Participating in the RERT
-
Participating in the Wholesale Electricity Market (Western Australia)
-
Participating in the I-NTEM (NT)
-
Cyber security and data privacy arrangements
-
Consumer protection frameworks
-
CER Cybersecurity Roadmap
Last Updated on 4 August 2026
SUGGEST AN EDIT
LIKE THIS PAGE?
Australia’s CER ecosystem comprises millions of internet-connected devices interacting with DNSPs, electricity retailers, VPP operators, equipment manufacturers and third party application developers. This complexity creates vulnerabilities across multiple layers, from device firmware to communication protocols.
The CER Cybersecurity Roadmap was commissioned by the DCCEEW and prepared by Standards Australia to identify existing international standards relevant to CER cybersecurity, assess their applicability to the Australian context, and outline gaps where Australian-specific standards or guidance are needed. It was developed with the Consumer Energy Resource Cybersecurity Advisory Group (CERCAG) comprising stakeholders from AEMC, AEMO, industry, and academia.
The roadmap was published in 2024 and is part of a broader initiative to strengthen cybersecurity across Australia’s distributed energy ecosystem. It sets out an approach for adopting standards to address cybersecurity risks associated with CER technologies.
Key points
- Interconnected CER can introduce cybersecurity risks across devices, communications and operational platforms.
- The CER Cybersecurity Roadmap uses established cybersecurity and threat-modelling frameworks to categorise these risks.
- International standards provide a useful foundation but may require adaptation for Australia’s CER ecosystem.
- IEC 62351 and IEC 62443 are identified as immediate standards priorities.
- Longer-term work includes Australian-specific guidance for incident detection, response and recovery.
How does the roadmap identify cybersecurity threats?
The roadmap adopts the NIST PQC Cybersecurity Framework and STRIDE threat modelling to categorise risks. STRIDE identifies six key threat types: spoofing, tampering, repudiation, information disclosure, denial of service, and elevation of privilege. These categories underpin the analysis of CER-specific risks, including insecure communication networks, lack of patch management, and vulnerabilities in commercial off-the-shelf components.
Which cybersecurity standards are relevant to CER?
Standards Australia, commissioned by the DCCEEW, conducted a gap analysis to identify relevant international standards and areas requiring Australian-specific guidance. Key standards highlighted include:
- IEC 62443 series: Cybersecurity for industrial automation and control systems, applicable to CER environments.
- IEC 62351 series: Data and communications security for power systems.
- ISO/IEC 27001: Information security management systems, adopted in Australia in 2023.
- IEEE 1547 and IEEE 2800: Interconnection and interoperability standards for distributed energy resources.
The roadmap notes that these standards provide a strong foundation, many were developed for different markets and technologies and identifies the need for tailored technical specifications for Australia’s CER ecosystem.
Roadmap priorities and next steps
The roadmap organises standards into priority tiers across subject areas such as power systems management, communication networks, industrial automation security, and electric vehicle charging. Immediate priorities include adopting IEC 62351 for secure power system communications and IEC 62443 for component-level security. Longer-term workstreams involve developing Australian-specific handbooks and guidelines to address gaps in incident detection, response, and recovery.
The CERCAG recommends a multi-pronged approach: adopt and adapt international standards, develop local technical specifications, and promote education and regulatory alignment.