Cyber security regulation: the Cyber Security Act 2024 

35-50 minutes

How the Cyber Security Act 2024 (Cth) sets security standards for smart devices, requires ransomware payments to be reported, protects information shared about cyber incidents, and establishes the Cyber Incident Review Board.

Learning level
Core Doctrine
Jurisdictions
au-commonwealth
Subjects
intellectual-property-and-technology-law
Topics
cyber-security-regulation

Learning outcomes

  • Identify which Part of the Cyber Security Act 2024 (Cth) a problem engages, and establish a cyber security incident under s 9, including its constitutional connection.
  • Apply the ransomware payment reporting obligation: the elements in s 26, the reporting business entity test, the 72-hour deadline in s 27 and the civil penalty for failing to report.
  • Apply the security standard for consumer smart devices to a manufacturer or supplier, and trace the escalating notices that enforce it.
  • Distinguish the limits on how the Government may use information given under the Act from its inadmissibility against the entity that gave it, and state the exceptions to each.

The Cyber Security Act 2024 (Cth) creates four separate regimes: security standards for smart devices, mandatory reporting of ransomware payments, protected sharing of incident information with the National Cyber Security Coordinator, and after-the-event reviews by the Cyber Incident Review Board (s 3). It is Commonwealth law, applies within and outside Australia (s 5), and operates alongside any State or Territory law capable of operating concurrently (s 7). The first question in any problem is which regime is engaged, because each has its own trigger, obligations and consequences.

Which incidents the Act reaches

Parts 3 and 4 turn on a cyber security incident. Section 9(1) takes the meaning from the Security of Critical Infrastructure Act 2018 (Cth), and s 9(2) confines it to incidents with a constitutional connection1: a critical infrastructure asset, the activities of a constitutional corporation, use of a telecommunications service such as the internet, impairment of a computer's connection to such a service, or serious prejudice to Australia's social or economic stability, defence or national security. Where the facts are uncertain, ss 26(4) and 35(4) presume the connection on the probabilities, but s 26(5) removes Part 3 civil penalty liability if it did not in fact exist. A significant cyber security incident is one carrying a material risk of serious prejudice to stability, defence or national security, or one that is, or could reasonably be expected to be, of serious concern to the Australian people (s 34).

Security standards for smart devices

Part 2 applies to relevant connectable products: broadly, products that can connect to the internet directly or through another product, unless the rules exempt them (s 13). A manufacturer must make them to the security standard set by the rules, and a supplier must not supply a non-compliant product in Australia, where each is aware, or could reasonably be expected to be aware, that the product will be acquired in Australia in the specified circumstances (ss 14–15)2. Both must provide a statement of compliance (s 16).

The Cyber Security (Security Standards for Smart Devices) Rules 2025 (Cth) apply the standard from 4 March 2026 to products for personal, domestic or household use acquired by a consumer, other than desktop and laptop computers, tablets, smartphones, therapeutic goods and road vehicles (rules ss 2, 8)11. The standard requires passwords that are unique per product or set by the user, a published way to report security issues, and a published defined support period for security updates that the manufacturer must not shorten (sch 1 cls 2–4).

Sections 15 and 16 are not civil penalty provisions. The Secretary enforces them through escalating notices (compliance, then stop, then recall), each preceded by at least 10 days for representations and each open to internal review sought within 30 days (ss 17–19, 22)3, and through monitoring and enforceable undertakings (ss 79(2), 80(1)).

Ransomware payment reporting

Part 3 applies where a cyber security incident impacts, or could reasonably be expected to impact, a reporting business entity, an extorting entity makes a demand, and the entity makes, or knows another entity made on its behalf, a payment or benefit directly related to the demand (s 26(1))4. A reporting business entity is a business carried on in Australia with turnover for the previous financial year above $3 million (Cyber Security (Ransomware Payment Reporting) Rules 2025 (Cth) s 6)10, other than a Commonwealth or State body or a critical infrastructure responsible entity; or a responsible entity for an asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies (s 26(2)).

The entity must report to the designated Commonwealth body (the Department and the Australian Signals Directorate unless the rules specify another: s 8) within 72 hours of making the payment or becoming aware that it was made (s 27(1))5. The report covers the incident, the demand, the payment and communications with the extorting entity, so far as the entity knows or can find out by reasonable search or enquiry (s 27(2); rules s 7). Failing to report attracts a civil penalty of 60 penalty units (s 27(5)), and compliance in good faith carries no liability in damages (s 28).

What reported information can and cannot be used for

Two separate protections encourage reporting. The first limits use: information in a ransomware payment report may be used only for listed purposes, such as helping the entity respond (s 29(1)), and not to investigate or enforce the entity's contraventions of other laws, except Part 3 and laws creating criminal offences (s 29(2))6. The second limits evidence: the information is not admissible against the entity in criminal proceedings (other than for the Criminal Code offences of false or misleading information and obstruction), civil penalty proceedings outside Part 3, other proceedings for a breach of a law, including the common law, or tribunal proceedings (s 32(2)). A criminal offence is therefore carved out of the use restriction, but not out of the admissibility rule.

Neither protection applies to a coronial inquiry, a Royal Commission, or a federal proceeding for mandamus, prohibition or an injunction against a Commonwealth officer (s 32(3)). Neither authorises anything the Privacy Act 1988 (Cth) prohibits (s 29(3)), and reporting does not of itself affect a claim of legal professional privilege (s 31). Information shared under Part 4 is protected in the same way (ss 38, 42).

Sharing with the National Cyber Security Coordinator

Part 4 is voluntary. An entity carrying on business in Australia, or a critical infrastructure responsible entity, impacted by an incident that is, or could reasonably be expected to be, a significant cyber security incident may give the Coordinator information, and need not answer a request (s 35 and note to s 35(3))7. The Coordinator leads the whole-of-Government coordination and triaging of the response (s 37). Sharing does not affect any other requirement to provide the information, including under Part 3 (s 44).

The Cyber Incident Review Board

The Board, a Chair and two to six standing members (s 61), reviews incidents after they end and recommends how similar incidents could be prevented, detected, responded to or minimised (s 62). A review needs a referral from the Minister, the Coordinator, an impacted entity or a Board member; an incident meeting a criterion in s 46(3), such as serious prejudice to national security or the use of novel or complex methods; the end of the incident and the immediate response; and the Minister's approval of the terms of reference (s 46)8. Having first requested them, the Chair may require a private entity involved in the incident to produce documents, on pain of a civil penalty of 60 penalty units (ss 48–50). The Board does not find fault: a final report must not apportion blame, provide the means to determine liability, identify an individual without consent, or allow an adverse inference to be drawn from the fact of review (s 52(4)).

Enforcement

Civil penalty provisions are enforced under the Regulatory Powers (Standard Provisions) Act 2014 (Cth) by civil penalty orders, injunctions, enforceable undertakings, monitoring, investigation and infringement notices, in the Federal Court, the Federal Circuit and Family Court of Australia (Division 2) or a State or Territory court with jurisdiction (ss 79–82)9. The Crown is not liable to a pecuniary penalty, although an authority of the Crown is (s 79(8)–(9)), and the rules cannot create an offence or civil penalty (s 87(2)(a)).

Applying this in a problem question

  1. Identify the regime engaged: a product (Part 2), a ransomware payment (Part 3), voluntary sharing (Part 4) or a Board review (Part 5).
  2. For Parts 3 and 4, establish a cyber security incident under s 9(2), using the presumptions in ss 26(4) and 35(4) only where the facts are uncertain.
  3. For a product, confirm it is a relevant connectable product within the consumer class, then test the manufacturer's or supplier's awareness under s 15.
  4. For a payment, prove each element of s 26(1), apply the $3 million threshold, and count 72 hours from the payment or from becoming aware of it.
  5. Apply the use restriction and the admissibility rule separately, each with its exceptions.
  6. State the consequence: the notice sequence for Part 2, or a remedy under the Regulatory Powers Act.

Self-check

  • Have I identified the regime before stating any obligation?
  • Have I established the s 9(2) connection, or relied on a presumption only where one applies?
  • Have I taken the threshold and the standard from the rules, not the Act?
  • Have I kept the use restriction separate from inadmissibility?

Pop quiz

5 quick questions on this article, the authorities it cites and the articles it links to.

  • About 3 minutes, and no time limit.
  • You can only go forwards: each answer locks when you submit it.
  • After each question you see the right answer, why, and where to read more.
  • Free, and no account needed. Log in or create a free account to keep your scores.