(1) A cyber security incident is one or more acts, events or circumstances:
(a) of a kind covered by the meaning of cyber security incident in the Security of Critical Infrastructure Act 2018; or
(b) involving unauthorised impairment of electronic communication to or from a computer, within the meaning of that phrase in that Act, but as if that phrase did not exclude the mere interception of any such communication.
(2) However, an incident is only a cyber security incident for the purposes of this Act if:
(a) the incident involves a critical infrastructure asset; or
(b) the incident involves the activities of an entity that is a corporation to which paragraph 51(xx) of the Constitution applies; or
(c) the incident is or was effected by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
(d) the incident is impeding or impairing, or has impeded or impaired, the ability of a computer to connect to such a service; or
(e) the incident has seriously prejudiced or is seriously prejudicing:
(i) the social or economic stability of Australia or its people; or