Part 1—Preliminary
Read this container only1 Short title
This Act is the Cyber Security Act 2024.
2 Commencement
- (1) Each provision of this Act specified in column 1 of the table commences, or is taken to have commenced, in accordance with column 2 of the table. Any other statement in column 2 has effect according to its terms.
Commencement information
| Column 1 Provisions |
Column 2 Commencement |
Column 3 Date/Details |
|---|---|---|
| 1. Part 1 and anything in this Act not elsewhere covered by this table | The day after this Act receives the Royal Assent. | 30 November 2024 |
| 2. Part 2 | A single day to be fixed by Proclamation. | |
| However, if the provisions do not commence within the period of 12 months beginning on the day this Act receives the Royal Assent, they commence on the day after the end of that period. | 29 November 2025 | |
| 3. Part 3 | A single day to be fixed by Proclamation. | |
| However, if the provisions do not commence within the period of 6 months beginning on the day this Act receives the Royal Assent, they commence on the day after the end of that period. | 29 May 2025 | |
| 4. Part 4 | The day after this Act receives the Royal Assent. | 30 November 2024 |
| 5. Part 5 | A single day to be fixed by Proclamation. | |
| However, if the provisions do not commence within the period of 6 months beginning on the day this Act receives the Royal Assent, they commence on the day after the end of that period. | 29 May 2025 | |
| 6. Parts 6 and 7 | The day after this Act receives the Royal Assent. | 30 November 2024 |
Note: This table relates only to the provisions of this Act as originally enacted. It will not be amended to deal with any later amendments of this Act.
- (2) Any information in column 3 of the table is not part of this Act. Information may be inserted in this column, or information in it may be edited, in any published version of this Act.
3 Objects
The objects of this Act are to:
- (a) improve the cyber security of products that:
- (i) can connect directly or indirectly to the internet; and
- (ii) will be acquired in Australia;
by requiring manufacturers and suppliers of those products to comply with security standards specified in the rules; and
- (b) encourage the provision of information relating to the provision of payments or benefits (called ransomware payments) to entities seeking to benefit from cyber security incidents by imposing reporting obligations on entities in relation to the payment of such payments or benefits; and
- (c) facilitate the whole of Government response to significant cyber security incidents by providing for the National Cyber Security Coordinator to lead across the whole of Government the coordination and triaging of action in response to significant cyber security incidents; and
- (d) prevent, improve the detection of, improve the response to and minimise the impact of cyber security incidents by establishing the Cyber Incident Review Board to:
- (i) cause reviews to be conducted in relation to certain cyber security incidents; and
- (ii) make recommendations to government and industry about actions that could be taken to prevent, detect, respond to or minimise the impact of, incidents of a similar nature in the future; and
- (e) improve the response to and minimise the impact of cyber security incidents (including imminent incidents) through encouraging entities impacted, or probably impacted, by such cyber security incidents to provide information to the Australian Government about the incidents by ensuring that:
- (i) the information provided is only used and disclosed for limited purposes; and
- (ii) the information provided is not admissible in evidence in proceedings against the entities that provided the information; and
- (f) to facilitate the sharing of information about cyber security incidents with State and Territory Governments for limited purposes, with their consent that the information is only to be used and disclosed for limited purposes.
4 Simplified outline of this Act
:::box This Act provides for mandatory security standards for certain products that can directly or indirectly connect to the internet (called relevant connectable products).
This Act also provides an obligation to report payments or benefits (called ransomware payments) provided to an entity that is seeking to benefit from a cyber security incident.
Information may be voluntarily provided to the National Cyber Security Coordinator in relation to a significant cyber security incident. The National Cyber Security Coordinator’s role is to lead across the whole of Government the coordination and triaging of action in response to a significant cyber security incident.
The Cyber Incident Review Board is established by this Act. Its functions include causing reviews to be conducted in relation to certain cyber security incidents. A review will make recommendations to Government and industry about actions that could be taken to prevent, detect, respond to or minimise the impact of, incidents of a similar nature in the future.
Information provided by entities under provisions of this Act may only be used and disclosed for limited purposes. Certain information provided to the Australian Government under this Act is not admissible in evidence in proceedings against the entity that provided the information.
A range of compliance and enforcement powers are provided for, including by applying the Regulatory Powers (Standard Provisions) Act 2014.
This Act also deals with administrative matters such as delegations and the power to make rules. :::
5 Extraterritoriality
This Act applies both within and outside Australia.
Note: This Act extends to every external Territory.
6 Act binds the Crown
- (1) This Act binds the Crown in each of its capacities.
- (2) This Act does not make the Crown liable to be prosecuted for an offence.
Note: The Crown (other than a Crown authority) is not liable to a pecuniary penalty for the breach of a civil penalty provision or to be given an infringement notice: see subsections 79(8) and 82(7).
- (3) The protection in subsection (2) does not apply to an authority of the Crown.
7 Concurrent operation of State and Territory laws
This Act is not intended to exclude or limit the operation of a law of a State or Territory to the extent that that law is capable of operating concurrently with this Act.
8 Definitions
In this Act:
ASD means the Australian Signals Directorate.
benefit includes any advantage and is not limited to property.
business has the same meaning as in the Income Tax Assessment Act 1997.
Chair means the Chair of the Cyber Incident Review Board.
civil penalty provision has the same meaning as in the Regulatory Powers Act.
Commonwealth body means:
- (a) a Minister of the Commonwealth; or
- (b) a Department of State of the Commonwealth; or
- (c) a body (whether incorporated or not) that:
- (i) is established, or continued in existence, for a public purpose by or under a law of the Commonwealth; and
- (ii) is not an authority of the Crown.
Commonwealth enforcement body means:
- (a) the Australian Federal Police; or
- (b) the Australian Prudential Regulation Authority; or
- (c) the Australian Securities and Investments Commission; or
- (d) the Inspector of the National Anti‑Corruption Commission; or
- (e) the Office of the Director of Public Prosecutions; or
- (f) the National Anti‑Corruption Commissioner; or
- (g) Sport Integrity Australia; or
- (h) another Commonwealth body, to the extent that it is responsible for administering, or performing a function under, a law that imposes a penalty or sanction for a criminal offence.
Commonwealth officer has the same meaning as in Part 5.6 of the Criminal Code.
computer has the same meaning as in the Security of Critical Infrastructure Act 2018.
coronial inquiry means a coronial inquiry, coronial investigation or coronial inquest under a law of the Commonwealth, or of a State or Territory.
critical infrastructure asset has the same meaning as in the Security of Critical Infrastructure Act 2018.
Cyber Incident Review Board or Board means the Cyber Incident Review Board established by section 60.
cyber security incident has the meaning given by section 9.
designated Commonwealth body means:
- (a) a Department, or a body established by a law of the Commonwealth, specified in the rules; or
- (b) if no rules are made for the purposes of paragraph (a)—the Department and ASD.
draft review report has the meaning given by subsection 51(1).
entity means any of the following:
- (a) an individual;
- (b) a body corporate;
- (c) a partnership;
- (d) an unincorporated association that has a governing body;
- (e) a trust;
- (f) an entity that is a responsible entity for a critical infrastructure asset.
Expert Panel means the Expert Panel established by the Board under section 70.
final review report has the meaning given by subsection 52(1).
intelligence agency means:
- (a) the agency known as the Australian Criminal Intelligence Commission established by the Australian Crime Commission Act 2002; or
- (b) the Australian Geospatial‑Intelligence Organisation; or
- (c) the Australian Secret Intelligence Service; or
- (d) the Australian Security Intelligence Organisation; or
- (e) ASD; or
- (f) the Defence Intelligence Organisation; or
- (g) the Office of National Intelligence.
internet‑connectable product has the meaning given by subsection 13(4).
manufacturer has the same meaning as in the Australian Consumer Law.
National Cyber Security Coordinator means:
- (a) the officer of the Department known as the National Cyber Security Coordinator; and
- (b) the APS employees, and officers or employees of Commonwealth bodies, whose services are made available to the officer in connection with the performance of any of the officer’s functions or the exercise of any of the officer’s powers under this Act.
network‑connectable product has the meaning given by subsection 13(5).
permitted cyber security purpose for a cyber security incident has the meaning given by section 10.
personal information has the same meaning as in the Privacy Act 1988.
protected review report has the meaning given by subsection 54(1).
ransomware payment has the meaning given by subsection 26(1).
ransomware payment report means a report given by an entity under subsection 27(1).
Regulatory Powers Act means the Regulatory Powers (Standard Provisions) Act 2014.
relevant connectable product has the meaning given by subsection 13(2).
reporting business entity has the meaning given by subsection 26(2).
responsible entity, for an asset, has the same meaning as in the Security of Critical Infrastructure Act 2018.
Secretary means the Secretary of the Department.
sensitive information has the same meaning as in the Privacy Act 1988.
sensitive review information has the meaning given by subsection 53(2).
significant cyber security incident has the meaning given by section 34.
State body means:
- (a) a Minister of a State or Territory; or
- (b) a Department of State of a State or Territory or a Department of the Public Service of a State or Territory; or
- (c) a body (whether incorporated or not) that:
- (i) is established, or continued in existence, for a public purpose by or under a law of a State or Territory; and
- (ii) is not an authority of the Crown.
supply has the same meaning as in the Australian Consumer Law and supplied and supplier have corresponding meanings.
9 Meaning of cyber security incident
- (1) A cyber security incident is one or more acts, events or circumstances:
- (a) of a kind covered by the meaning of cyber security incident in the Security of Critical Infrastructure Act 2018; or
- (b) involving unauthorised impairment of electronic communication to or from a computer, within the meaning of that phrase in that Act, but as if that phrase did not exclude the mere interception of any such communication.
- (2) However, an incident is only a cyber security incident for the purposes of this Act if:
- (a) the incident involves a critical infrastructure asset; or
- (b) the incident involves the activities of an entity that is a corporation to which paragraph 51(xx) of the Constitution applies; or
- (c) the incident is or was effected by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
- (d) the incident is impeding or impairing, or has impeded or impaired, the ability of a computer to connect to such a service; or
- (e) the incident has seriously prejudiced or is seriously prejudicing:
- (i) the social or economic stability of Australia or its people; or
- (ii) the defence of Australia; or
- (iii) national security.
10 Meaning of permitted cyber security purpose
Each of the following is a permitted cyber security purpose for a cyber security incident:
- (a) the performance of the functions of a Commonwealth body (to the extent that it is not a Commonwealth enforcement body) relating to responding to, mitigating or resolving the cyber security incident;
- (b) the performance of the functions of a State body relating to responding to, mitigating or resolving the cyber security incident;
- (c) the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to the cyber security incident;
- (d) informing and advising the Minister, and other Ministers of the Commonwealth, about the cyber security incident;
- (e) preventing or mitigating material risks that the cyber security incident has seriously prejudiced, is seriously prejudicing, or could reasonably be expected to prejudice:
- (i) the social or economic stability of Australia or its people; or
- (ii) the defence of Australia; or
- (iii) national security;
- (f) preventing or mitigating material risks to a critical infrastructure asset;
- (g) the performance of the functions of an intelligence agency;
- (h) the performance of the functions of a Commonwealth enforcement body.
Note 1: There are some limitations in relation to civil or regulatory functions against entities that have provided information in relation to the incident: see subsections 38(2) and 39(3).
Note 2: Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.
11 Disclosure to State body
- (1) Despite any other provision of this Act, information that may be disclosed to a State body under Part 3, 4 or 5 must not be disclosed to the State body under that Part unless:
- (a) a Minister of the State or Territory has informed the Minister administering this Act, in writing, that the State or Territory gives consent to the provisions of that Part applying to the State body; and
- (b) a Minister of the State or Territory has not informed the Minister administering this Act, in writing, that the State or Territory withdraws that consent.
- (2) For the purposes of paragraph (1)(a), a Minister of a State or Territory may give consent in relation to all State bodies, a class of State bodies, or particular State bodies, of that State or Territory.