Critical infrastructure security: the Security of Critical Infrastructure Act 2018
How the Security of Critical Infrastructure Act 2018 (Cth) identifies critical infrastructure assets and their responsible entities, and imposes register, risk management, cyber incident reporting and enhanced obligations, backed by government directions and serious incident powers.
Learning outcomes
- Determine whether an asset is a critical infrastructure asset under s 9 of the Security of Critical Infrastructure Act 2018 (Cth), identify its responsible entity, and establish which Parts of the Act apply to it.
- Apply the cyber incident notification obligations in ss 30BC and 30BD, distinguishing the 12-hour and 72-hour reporting windows.
- Explain what a critical infrastructure risk management program must do, and the annual report that goes with it.
- Test the statutory preconditions for a ministerial direction under s 32 and for the serious incident powers in Part 3A.
The Security of Critical Infrastructure Act 2018 (Cth) provides a framework for managing risks to critical infrastructure (s 3). It identifies the assets that are critical and the entities responsible for them, then imposes a ladder of obligations: giving ownership and operational information, keeping a risk management program, reporting cyber security incidents and, for the most important assets, enhanced cyber security obligations. Above those sit government powers to direct entities and to respond to serious incidents. It is Commonwealth law, applies within and outside Australia (s 14), and operates alongside State and Territory law capable of concurrent operation (s 16). The first question is whether the asset is a critical infrastructure asset, and the second is whether the relevant Part applies to it.
Which assets and entities are covered
An asset is a critical infrastructure asset if it falls within one of the 22 classes listed in s 9(1), from telecommunications, data storage and banking to water, electricity, hospitals, food and grocery, ports, aviation and defence industry, or if the Minister declares it under s 51 or the rules prescribe it1. The rules may take a class out (s 9(2)), an asset owned by the Commonwealth is excluded unless declared or prescribed (s 9(2A)), and an asset outside Australia is excluded, apart from certain satellites and submarine cables (s 9(2B)–(2D)).
Each asset has a responsible entity, identified class by class in s 12L; for a critical telecommunications asset, for example, it is the carrier or carriage service provider that owns or operates it2. The Act reaches constitutional corporations, entities whose assets are used in interstate or overseas trade and commerce, banking, insurance, defence or communications, and aliens (s 13(1))3, and it does not enable a power to be exercised so as to impair a State's capacity to exercise its constitutional powers (s 17).
Being a critical infrastructure asset is not enough. Parts 2, 2A and 2B each apply only to an asset specified in the rules, or declared under s 51 with a determination that the Part applies (ss 18A, 30AB, 30BB, 51(2A)). The Minister may declare an asset only if it is critical to Australia's social or economic stability, defence or national security and public knowledge of its status would itself be a risk, and disclosing a declaration is an offence (s 51 and the note to s 51(1))4.
The Register
The Secretary keeps a Register of Critical Infrastructure Assets, which must not be made public (ss 19, 22)5. The responsible entity must give operational information about the asset, and each direct interest holder must give interest and control information, by the later of the end of the grace period and 30 days after becoming a reporting entity (s 23). Notifiable events must be reported within 30 days (s 24). Each obligation carries a civil penalty of 50 penalty units.
Risk management programs
Under Part 2A, a responsible entity must adopt and maintain a critical infrastructure risk management program, comply with it, review it regularly and keep it up to date, each on pain of a civil penalty of 200 penalty units (ss 30AC–30AF)6. The program is a written program that must, for each asset, identify each hazard where there is a material risk of a relevant impact on the asset, minimise or eliminate that risk so far as reasonably practicable, and mitigate the impact so far as reasonably practicable, meeting any requirements in the rules (s 30AH(1)). Whether a risk is material depends on the likelihood of the hazard and its impact (s 30AH(7)). Within 90 days after each financial year the entity must give an annual report, approved by its board if it has one (s 30AG(2)); that report is not admissible against it in civil penalty proceedings under the Act (s 30AG(3)).
Reporting cyber security incidents
Part 2B draws the line most problems turn on7:
- Critical incidents. Where the entity becomes aware that a cyber security incident has had, or is having, a significant impact on the availability of the asset, it must report to the relevant Commonwealth body as soon as practicable and in any event within 12 hours (s 30BC(1)). An oral report must be followed by a written record within 84 hours (s 30BC(3)).
- Other incidents. Where an incident has occurred, is occurring or is imminent and has had, is having or is likely to have a relevant impact on the asset, the limit is 72 hours (s 30BD(1)), with a written record of an oral report within 48 hours (s 30BD(3)).
An impact is significant only if the asset is used to provide essential goods or services and the incident has materially disrupted their availability, or the rules say so (s 30BEA). The relevant Commonwealth body is the one the rules specify or, if none is specified, the Australian Signals Directorate (s 30BF). Each obligation carries a civil penalty of 50 penalty units. A responsible entity for an asset covered by Part 2B is also a reporting business entity for ransomware payment reporting under the Cyber Security Act 2024 (Cth) (s 26(2)(b) of that Act)8.
Systems of national significance
The Minister may privately declare a critical infrastructure asset to be a system of national significance, having regard to the consequences of a hazard with a significant impact on it and its interdependencies with other assets (s 52B)9. Part 2C then allows enhanced cyber security obligations to be imposed on its responsible entity: incident response planning, cyber security exercises, vulnerability assessments, and giving system information to the Australian Signals Directorate (ss 30CA, 30CB, 30CM, 30CU).
Government directions and serious incidents
The Minister may direct a reporting entity or operator to do, or refrain from doing, a specified act or thing where satisfied there is a risk of an act or omission prejudicial to security (s 32)10. The Minister must first be satisfied that the direction is reasonably necessary, that reasonable steps have been taken to negotiate in good faith, and that no existing regulatory system could be used instead, and must have received an adverse security assessment, to which the greatest weight is given (s 32(3), (5)). The Minister must consult the relevant State or Territory (s 33), and non-compliance carries a civil penalty of 250 penalty units (s 34).
Part 3A deals with serious incidents. If the Minister is satisfied that an incident has, or is likely to have, a relevant impact on a critical infrastructure asset, that there is a material risk of serious prejudice to stability, defence or national security, and that no existing regulatory system could provide a practical and effective response, the Minister may authorise the Secretary to give three escalating kinds of intervention (s 35AB)11:
- information gathering directions, compliance with which carries a civil penalty of 150 penalty units (ss 35AK, 35AM);
- action directions, only where the entity is unwilling or unable to take all reasonable steps to respond and the direction is necessary, proportionate and technically feasible; breach is an offence punishable by 2 years' imprisonment, 120 penalty units, or both (ss 35AB(7), 35AQ, 35AT);
- intervention requests to the Australian Signals Directorate, only for a cyber security incident, where an action direction would not be practical and effective, and with the agreement of the Prime Minister and the Defence Minister (ss 35AB(10), (13), 35AX).
Neither an action direction nor an intervention request may involve offensive cyber action against the person responsible (s 35AB(9)(b), (12)).
Enforcement and protected information
Civil penalty provisions are enforced through civil penalty orders, injunctions, infringement notices and enforceable undertakings under the Regulatory Powers (Standard Provisions) Act 2014 (Cth), and certain provisions carry criminal penalties (s 4)12. Information obtained or generated under the Act is protected information, with restrictions on its recording, use and disclosure (s 4). The Crown is bound but cannot be prosecuted, although an authority of the Crown can be (s 15).
Applying this in a problem question
- Classify the asset under s 9, checking the rules' exclusions and the Commonwealth-ownership and location limits.
- Identify the responsible entity under s 12L and any direct interest holder.
- Establish which Parts apply to the asset through the rules or a s 51 declaration, and whether it is a declared system of national significance.
- Apply the obligations in turn: Register information within 30 days, the risk management program and annual report, and incident reports within 12 or 72 hours.
- For government intervention, test every statutory precondition in s 32(3) or s 35AB before describing what the power allows.
- State the consequence, and check whether a ransomware payment triggers the separate reporting obligation in the Cyber Security Act 2024.
Self-check
- Have I confirmed that the relevant Part applies to this asset, not only that it is critical infrastructure?
- Have I distinguished a significant impact on availability (12 hours) from a relevant impact (72 hours)?
- Have I tested each precondition before applying a ministerial or Secretary power?