shield_person Andrew Roberts Advisory

Briefing No. 031

What the ACS Digital Pulse Tells Directors

·7 min read·1,452 words

Your management team tells you the technology strategy is on track. The ACS Digital Pulse says the Australian digital economy is under structural pressure. One of those two positions deserves more scrutiny than it is probably getting at your board table.

Does this apply to you?

ASX-listed: Digital capability and cyber risk are material to investor disclosure obligations and to board oversight duties under the Corporations Act. [1] The Digital Pulse benchmarks give you an external reference point for assessing whether management claims hold up.

APRA-regulated: Technology and cyber workforce constraints identified in the Digital Pulse directly affect your capacity to meet prudential obligations around operational resilience and risk management. [2]

NFP / SME: Workforce shortages and AI adoption pressures described in the Digital Pulse apply to organisations of every size. Smaller entities often carry more concentrated risk because there is less redundancy in the team.

What the Digital Pulse actually is

The ACS Digital Pulse is the authoritative annual assessment of Australia's digital economy, produced by the professional body for Australia's technology and cyber workforce. [3] It measures the size and shape of the technology workforce, digital skills supply and demand, sector investment levels, and Australia's position relative to comparable economies.

Directors should treat it as an independent external benchmark, not as an IT industry document. When the report identifies a gap between the skills the economy needs and the skills it has, that gap lands directly on your organisation's risk register. Talent shortages do not stay in the labour market. They become operational risk, delivery risk, and cyber risk inside your organisation.

The workforce risk directors are underestimating

The Digital Pulse consistently identifies a structural shortfall in Australia's technology and cyber workforce. [4] Demand for digital skills is outpacing supply across almost every sector. The pipeline of new talent entering the workforce is not closing that gap at the pace required.

For directors, this has three practical consequences. First, your organisation is competing for a constrained pool of people to build, run, and defend your technology environment. Second, when a critical role turns over, the replacement timeline is longer and more expensive than historical benchmarks suggest. Third, the people you retain are carrying higher workloads, which increases error rates and fatigue-related security failures.

This is not a human resources observation. It is a risk management observation. If your board is not receiving workforce pipeline reporting alongside cyber and technology risk reporting, you have a visibility gap.

AI adoption: the governance gap the Digital Pulse exposes

Each edition of the Digital Pulse tracks AI adoption and investment across the Australian economy. The pattern it reveals is consistent: adoption is accelerating, but governance is not keeping pace.

Organisations are deploying AI tools, automating decisions, and integrating third-party AI services faster than they are building the oversight frameworks to manage those systems. At the board level, this translates directly into accountability risk. Directors have a duty of care under the Corporations Act to act with reasonable diligence. [5] Approving or permitting AI deployment without a governance framework in place is not a defensible position, regardless of whether an incident has occurred yet.

The ACS, as the professional body for Australia's technology practitioners, has consistently called for ethical, accountable AI governance. The Digital Pulse gives that call an economic context. AI investment is rising. The boards overseeing that investment need to be asking harder questions about what controls exist, not just what the returns are expected to be.

Australia's global position and what it means for your sector

The Digital Pulse benchmarks Australia against other developed economies on digital readiness, investment, and workforce capability. Australia performs well in some areas and poorly in others. The gaps the report identifies are not abstract national statistics. They map directly onto the competitive conditions your organisation operates in.

Where Australia lags on digital infrastructure or skills investment, organisations in those sectors face higher costs to achieve the same technology outcomes as peers in better-positioned economies. Where Australia is advancing, there is a genuine competitive window that boards should be pressing management to exploit.

Directors do not need to become technologists to use this information. They need to ask whether management has read it, whether the findings are reflected in the technology strategy, and whether the board is seeing an honest assessment of how the organisation sits relative to the national and international picture the Digital Pulse describes.

What directors should actually do

The Digital Pulse is published annually. It should be a standing item on the board's governance calendar, reviewed and discussed at the board or risk committee level each year. Not delegated to management. Not treated as background reading. Reviewed, with implications drawn out and recorded.

Governance red flags

  • The board has never discussed the ACS Digital Pulse or an equivalent external benchmark for digital capability and workforce risk.
  • Technology workforce risk, including retention and succession for critical roles, does not appear on the risk register in any form.
  • AI tools are being adopted across the organisation but no AI governance framework has been presented to or approved by the board.
  • Management's technology strategy does not reference external benchmarks, only internal milestones and vendor projections.
  • The board has no visibility over how Australia's digital skills shortage is affecting the organisation's ability to fill technology and cyber roles.

Questions to ask management

  1. Has the executive team reviewed this year's ACS Digital Pulse, and what specific findings have been mapped to our technology and workforce strategy?
  2. How many critical technology and cyber roles are currently vacant or at retention risk, and what is the average time to fill those roles against current market conditions?
  3. What AI tools or automated decision systems are currently in use or in deployment across the organisation, and what governance controls apply to each?
  4. How does our digital capability benchmark against the national picture described in the Digital Pulse, and where are we materially behind?
  5. Is the board receiving sufficient reporting to assess technology and cyber workforce risk as a standalone risk category, separate from general IT operations?

The Digital Pulse does not make comfortable reading for directors who have been accepting reassurance from management without independent verification. Australia's digital economy has real structural pressures, and those pressures are sitting inside your organisation right now. The question is whether your board can see them clearly enough to govern them.

"The board reviewed the current ACS Digital Pulse findings and resolved that management provide a formal response addressing digital workforce risk, AI governance adequacy, and the organisation's capability position relative to the national benchmarks identified in the report, to be tabled at the next risk committee meeting."

Suitable for board minutes or a risk register entry

Frequently Asked Questions

Is the Digital Pulse relevant to my organisation if we are not a technology company?

Every organisation depends on technology and on the people who build and run it. The Digital Pulse documents the conditions of the market those people come from. Workforce shortages, skills gaps, and AI adoption pressures affect every sector, not only organisations that sell technology products or services.

How do I use the Digital Pulse at the board level without getting lost in the detail?

Focus on three things: the workforce supply and demand picture and what it means for your organisation's critical roles, the AI adoption and governance findings and whether your organisation's oversight framework is adequate, and the benchmark data that lets you assess whether management's technology strategy is realistic given market conditions. You do not need to read every section to extract governance-relevant insight.

Does the ACS Digital Pulse carry regulatory weight?

The ACS is the professional body for Australian technology practitioners, not a statutory regulator. The Digital Pulse is authoritative industry intelligence, not a compliance instrument. Its governance value is as an independent external benchmark that directors can use to test management's claims and identify blind spots in the board's technology risk picture.

How often should the board formally consider the Digital Pulse findings?

Annually, aligned to each new publication. The findings should be tabled formally, discussed at the board or risk committee level, and the implications for the organisation's technology strategy and risk register should be documented. A standing agenda item is a simple and defensible way to demonstrate active board oversight of technology risk.

If this resonates, I would welcome a conversation about the Founder Advisory Session, or get in touch directly.

Andrew Roberts

Briefing by

Andrew Roberts

Founder and Principal Advisor at Andrew Roberts Advisory. I help Australian boards translate cyber and AI governance obligations into clear, defensible oversight. Former ASX-listed Group CEO, AICD and ACS member, ACS MACS (Snr) CP (Cyber).

Sources

Related briefings

More Briefings

Cyber Governance & Oversight

Cyber Governance for Boards Australia: Moving Beyond Technical Metrics to Defensible Oversight

Apr 29, 2026
Cyber Governance & Oversight

What is a Technology Consultant? A Director’s Guide to Strategic Advisory in 2026

Apr 30, 2026
Governance Strategy & Advisory

Digital Strategy Consulting: A Board-Level Governance Template for 2026

May 01, 2026
Cyber Governance & Oversight

Defensible Oversight: A Cyber Security Audit Checklist for Australian Boards

May 04, 2026
Governance Strategy & Advisory

Tech Consulting for Australian Boards: Bridging the Governance Gap in 2026

May 06, 2026
AI Governance

AI Ethics Governance for Australian Boards: A Director's Framework

May 08, 2026
Board Reporting & Disclosure

Cyber Risk Reporting to the Board Australia: Establishing Defensible Oversight in 2026

May 11, 2026
AI Governance

AI Risk Management Framework for Directors: A Defensible 2026 Guide for Australian Boards

May 13, 2026
Regulation & Compliance

Regulatory Settlement Agreements: A Director’s Guide to Defensible Governance

May 15, 2026
Cyber Governance & Oversight

Cyber Security for Australian Boards: Moving from Technical Metrics to Defensible Oversight

May 18, 2026
Regulation & Compliance

Privacy Act Obligations and the Crimes Act: A Director’s Guide to Defensible Oversight

May 20, 2026
Third-Party & Supply Chain Risk

Third Party Cyber Risk Governance Australia: A Director’s Guide to Defensible Oversight

May 22, 2026
Cyber Governance & Oversight

Board Cyber Governance Strategy Australia: A 2026 Reference for Directors

May 25, 2026
Cyber Governance & Oversight

How to Challenge a CISO Report: A Director’s Guide to Defensible Oversight

May 27, 2026
AI Governance

Board Oversight of Generative AI Risks: A Defensible Governance Framework for 2026

May 29, 2026
AI Governance

AI Governance Reporting for Boards: A Guide to Defensible Oversight

Jun 01, 2026
AI Governance

Questions for Boards to Ask About Corporate AI Strategy: A 2026 Director’s Checklist

Jun 05, 2026
AI Governance

Director's Guide to Artificial Intelligence Risks: Defensible Oversight in 2026

Jun 08, 2026
Board Reporting & Disclosure

Linking Cyber Risk to Financial Impact: A Director’s Guide to Defensible Board Reporting

Jun 10, 2026
Regulation & Compliance

APRA CPS 234: Board Obligations Checklist for Directors

Jun 03, 2026
Board Reporting & Disclosure

Investor Expectations for Board Cyber Oversight in 2026

Jun 10, 2026
Cyber Governance & Oversight

Essential Eight Board Oversight for Australian Directors

Jun 12, 2026
Regulation & Compliance

Cyber Security Act 2024: Australian Director Obligations

Jun 05, 2026
Cyber Governance & Oversight

Board Cybersecurity Duties: A Director's Guide to Defensible Oversight in Australia

Jun 15, 2026
Cyber Governance & Oversight

AICD Cyber Security Governance Principles Version 2: What Australian Directors Need to Know

Jun 16, 2026
Third-Party & Supply Chain Risk

Third-Party Cyber Risk: A Director's Guide to Defensible Board Oversight in Australia

Jun 17, 2026
AI Governance

What an Independent AI Governance Review Actually Involves for Australian Boards

Aug 02, 2026
Cyber Governance & Oversight

The Origin Hack: What Directors Need to Do Now

Aug 09, 2026
Cyber Governance & Oversight

Does the board need to hire a CISO?

Aug 17, 2026
Cyber Governance & Oversight

Hiring the Right Tech Executive: What Boards Need to Know About AI and Cyber Skills

Aug 24, 2026