PSPF Changes Explained for Security Leaders episode artwork

EPISODE · Jan 21, 2026 · 33 MIN

PSPF Changes Explained for Security Leaders

from Day One®

Episode SummaryThe Protective Security Policy Framework is meant to guide how government manages security risk, but constant updates make it harder to implement than to understand. In this episode of Secured, Cole Cornford is joined by Toby Amodio, Practice Lead at Fujitsu Cybersecurity Services and former senior cybersecurity leader across Australian government, to break down what actually changed in the latest PSPF update and why it matters in practice.They examine the growing focus on personnel security and foreign interference risk, the inclusion of AI guidance that adds little beyond basic risk assessment, and the long overdue recognition of Secure Service Edge and SASE as compliant gateways. The conversation also explores why deny lists and centralised risk sharing sound sensible on paper but are far harder to enforce in reality, and why most security failures still come down to behaviour, accountability, and how technology is actually used rather than what policy says.Timestamps00:00 – Intro01:18 – What the PSPF is and why it exists02:49 – Annual updates, directives, and policy advisories04:19 – What actually changed in the 2025 PSPF update05:36 – AI in the PSPF and why it adds little value08:14 – Tool hype vs implementation risk10:32 – The AI policy advisory and trusted vendors14:25 – Directive 3 and clearance disclosure risks17:21 – Personnel security and enforcement reality19:41 – Secure Service Edge and SASE recognition23:39 – Commonwealth Technology Management directive25:28 – Deny lists, transparency, and security through obscurity28:05 – Centralised risk sharing and assessment overload29:52 – Policy wonk or policy gronk31:12 – Final takeaways and closing🐙 Secured is grateful to be sponsored and supported by Chainguard.Chainguard is the trusted source for open source. Get hardened, secure, production-ready builds so your team can ship faster, stay compliant, and reduce risk. Download your free CVE Reduction Assessment at https://dayone.fm/chainguardMentioned in this episode:Download your free CVE Reduction AssessmentChainguard is the trusted source for open source. Get hardened, secure, production-ready builds so your team can ship faster, stay compliant, and reduce risk.December 2025 - ChainguardCall for FeedbackThis podcast uses the following third-party services for analysis: Podtrac - https://analytics.podtrac.com/privacy-policy-gdrpSpotify Ad Analytics - https://www.spotify.com/us/legal/ad-analytics-privacy-policy/

Episode metadata supplied by the publisher feed · Published Jan 21, 2026

Embed this episode

Ready to play

PSPF Changes Explained for Security Leaders

0:00 33:14

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

Frequently Asked Questions

How long is this episode of Day One®?

This episode is 33 minutes long.

When was this Day One® episode published?

This episode was published on January 21, 2026.

Can I download this Day One® episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!