Skip to content
Legislation
Skip to legislation

Cyber Security Act 2024 · Version 2024-11-29

Part 5—Cyber Incident Review Board

Register source version C2024A00098 · Source observation:

Reading presentation · Verification limits and dated status · No live currency check

Part 5—Cyber Incident Review Board

Read this container only

Division 1—Preliminary

Read this container only

45 Simplified outline of this Part

:::box The Cyber Incident Review Board is established by this Part.

The Board must cause reviews to be conducted in relation to certain cyber security incidents. The purpose of a review is to make recommendations to government and industry about actions that could be taken to prevent, detect, respond to or minimise the impact of, cyber security incidents of a similar nature in the future.

A review panel will be established for each review in accordance with the terms of reference for the review.

The Board consists of the Chair and up to 6 other standing members. The standing members are appointed by the Minister.

The Board may establish an Expert Panel. One or more members of the Expert Panel may be appointed to assist in relation to a review conducted under this Part.

This Part also deals with the appointment of the Chair, standing members and Expert Panel members, and the procedures of the Board. :::

Division 2—Reviews

Read this container only

46 Board must cause reviews to be conducted

  • (1) The Cyber Incident Review Board may cause a review to be conducted under this section in relation to a cyber security incident, or a series of related cyber security incidents, on written referral by:
  • (a) the Minister; or
  • (b) the National Cyber Security Coordinator; or
  • (c) an entity impacted by the incident or an incident in the series of incidents; or
  • (d) a member of the Board.

Note: Each review is conducted by a particular review panel established for that review in accordance with the terms of reference for the review.

  • (2) A review may only be conducted under this section:
  • (a) if the Board is satisfied that the incident or series of incidents meets the criteria mentioned in subsection (3); and
  • (b) after the incident or series of incidents, and the immediate response, has ended; and
  • (c) if the Minister has approved the terms of reference for the review.
  • (3) For the purposes of paragraph (2)(a), the criteria are:
  • (a) the incident or series of incidents have seriously prejudiced, or could reasonably be expected to seriously prejudice:
    • (i) the social or economic stability of Australia or its people; or
    • (ii) the defence of Australia; or
    • (iii) national security; or
  • (b) the incident or series of incidents involved novel or complex methods or technologies, an understanding of which will significantly improve Australia’s preparedness, resilience, or response to cyber security incidents of a similar nature; or
  • (c) the incident or series of incidents are, or could reasonably be expected to be, of serious concern to the Australian people.
  • (4) Each review is to be conducted by a review panel that consists of:
  • (a) the Chair; and
  • (b) the standing members of the Board that are specified in the terms of reference for the review; and
  • (c) the members of the Expert Panel appointed to assist in the review under section 70.

The terms of reference for the review must specify one or more standing members for the review.

  • (5) The rules may make provision for or in relation to reviews under this Part, including for or in relation to the following:
  • (a) dealing with written referrals made to the Board;
  • (b) prioritisation of referrals for review and reviews conducted;
  • (c) terms of reference for reviews, including their variation;
  • (d) notification of reviews;
  • (e) the timing of when reviews may be conducted;
  • (f) when reviews may be discontinued;
  • (g) how information or submissions may be provided for reviews.

47 Board may discontinue a review

  • (1) The Board may discontinue a review at any time.
  • (2) The Board must, within 28 days of discontinuing a review, publish in any way the Board considers appropriate notice of the review being discontinued.

48 Chair may request information or documents

If the Board reasonably believes that:

  • (a) an entity; or
  • (b) a Commonwealth body or a State body; or
  • (c) an officer or employee of a Commonwealth body or a State body;

has information or documents relevant to a review being conducted under section 46 by a review panel, the Chair may request, by notice in writing, the entity, body, officer or employee to give the Board such information or documents as are specified in the request.

Note 1: There is no requirement to comply with the request.

Note 2: The Chair may require certain entities to give documents under section 49.

49 Chair may require certain entities to produce documents

  • (1) This section applies if:
  • (a) the Board reasonably believes that an entity involved in a cyber security incident that relates to a review being conducted under section 46 by a review panel has a document that is relevant to the review; and
  • (b) the Chair of the Board has requested that the entity provide the document under section 48; and
  • (c) the entity is not:
    • (i) a Commonwealth body or a State body; or
    • (ii) an officer or employee of a Commonwealth body or a State body.
  • (2) The Chair of the Board may, by notice in writing given to the entity, require the entity to:
  • (a) produce any such documents; or
  • (b) make copies of any such documents and to produce those copies;

to the Board within the period (which must not be less than 14 days), and in the manner, specified in the notice.

  • (3) The notice must set out the effect of the following provisions:
  • (a) section 50;
  • (b) Part 6 of this Act (Regulatory powers);
  • (c) sections 137.1 and 137.2 of the Criminal Code (false or misleading information or documents).

Compensation

  • (4) An entity is entitled to be paid by the Commonwealth reasonable compensation for complying with a requirement covered by paragraph (2)(b).

50 Civil penalty—failing to comply with a notice to produce documents

  • (1) An entity is liable to a civil penalty if:
  • (a) the entity is given a notice under subsection 49(2); and
  • (b) the entity fails to comply with the notice.

Civil penalty: 60 penalty units.

  • (2) Subsection (1) does not apply in relation to the production of a document or a copy of a document if the production would, or could reasonably be expected to, prejudice one or more of the following:
  • (a) the security, defence or international relations of the Commonwealth;
  • (b) the capabilities of an intelligence agency;
  • (c) the prevention, detection or investigation of, or the conduct of proceedings relating to, an offence or a contravention of a civil penalty provision;
  • (d) the administration of justice.
  • (3) Subsection 93(2) of the Regulatory Powers Act does not apply in relation to a contravention of subsection (1) of this section.
  • (4) Despite section 96 of the Regulatory Powers Act, in proceedings for a civil penalty order against an entity for a contravention of subsection (1), the entity does not bear an evidential burden in relation to the matters in subsection (2).

Note: This Act does not make the Crown (other than an authority of the Crown) liable to a civil penalty.

51 Draft review reports

  • (1) The Board must prepare a draft report (a draft review report) on a review being conducted under section 46 by a review panel.
  • (2) The draft review report must set out:
  • (a) the preliminary findings of the review; and
  • (b) a summary of the information and material on which those preliminary findings are based; and
  • (c) any recommendations the Board proposes to make; and
  • (d) if the Board proposes to make recommendations—the reasons for those proposed recommendations; and
  • (e) if the terms of reference for the review require particular information to be included in the draft review report—that information; and
  • (f) information (if any) that is prescribed by the rules; and
  • (g) such other information that the Board thinks fit to include in the draft review report.
  • (3) The Board must give the draft review report to the Minister.
  • (4) The Board may give the draft review report, or an extract of the draft review report, to any other Commonwealth body or a State body or entity:
  • (a) if the Board considers it appropriate to give the body or entity an opportunity to make submissions on the draft review report or the extract; or
  • (b) for the purposes of determining whether information proposed to be included in the final review report is sensitive review information.

Note 1: The disclosure of sensitive review information may be prohibited under another Act (for example, the Privacy Act 1988). This section does not authorise disclosure if prohibited under that Act: see subsection (7) of this section.

Note 2: Sensitive review information must be redacted from a final review report that is to be published by the Board: see section 53.

  • (5) If the Board gives a draft review report to the Minister under subsection (3), or a Commonwealth body, State body or entity under subsection (4), the Board must specify a reasonable period within which submissions may be made to the Board on the draft review report.
  • (6) Submissions must be given in the manner and form (if any) prescribed by the rules.
  • (7) However, this section does not authorise the Board to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988 or any other Act.

52 Final review reports

  • (1) After a review is completed under section 46 by the review panel, the Board must prepare a report (a final review report) on the review.

Note 1: The Board must redact sensitive review information from a final review report: see section 53.

Note 2: If information is redacted from a final review report, the Board must also prepare a protected review report: see section 54.

  • (2) In preparing the final review report, the Board must consider any submissions received under section 51 in relation to the draft review report.
  • (3) Subject to section 53, the final review report must set out:
  • (a) the findings of the review; and
  • (b) a summary of the information and material on which those findings are based; and
  • (c) any recommendations made by the Board; and
  • (d) if recommendations are made—the reasons for those recommendations; and
  • (e) if the terms of reference for the review require particular information to be included in the review report—that information; and
  • (f) information (if any) that is prescribed by the rules; and
  • (g) such other information that the Board thinks fit to include in the report.
  • (4) The Board must not in the final review report:
  • (a) apportion blame in relation to a cyber security incident that was the subject of the review; or
  • (b) provide the means to determine the liability of any entity in relation to such a cyber security incident; or
  • (c) identify an individual (unless the individual has consented); or
  • (d) allow any adverse inference to be drawn from the fact that an entity is the subject of the review.

However, even though blame or liability may be inferred, or an adverse inference may be made, by a person other than the Board, this does not prevent the Board from including information in the final review report.

  • (5) This section does not otherwise limit what may be included in the final review report.
  • (6) The Board must publish the final review report (excluding any information required to be redacted under section 53). The report may be published in any way the Board considers appropriate.

53 Certain information must be redacted from final review reports

  • (1) Information must be redacted from a final review report if the Chair is satisfied that the information is sensitive review information.

Note: If information is redacted from a final review report, the Board must prepare a protected review report that includes the information, see section 54.

  • (2) Sensitive review information is information the disclosure of which:
  • (a) could prejudice the security, defence or international relations of Australia; or
  • (b) would prejudice relations between the Commonwealth government and the government of a State or Territory; or
  • (c) could reveal, or enable a person to ascertain, the existence or identity of a confidential source of information in relation to the enforcement of the criminal law; or
  • (d) could endanger a person’s life or physical safety; or
  • (e) would prejudice the fair trial of any person or the impartial adjudication of a matter; or
  • (f) would involve disclosing information whose disclosure is prohibited or restricted by or under this Act, another Act or an instrument made under an Act; or
  • (g) would involve unreasonably disclosing information that is confidential or commercially sensitive; or
  • (h) would involve the disclosure of personal information about an individual without their consent.

54 Protected review reports

  • (1) If information must be redacted from a final review report under section 53, the Board must prepare another report (a protected review report) that includes:
  • (a) the redacted information; and
  • (b) the reasons for redacting the information from the final review report.
  • (2) If a protected review report is prepared under this section, the Board must give the Minister, and the Prime Minister, a copy of:
  • (a) the final review report prepared under section 52; and
  • (b) a copy of the protected review report.
  • (3) The Minister may give a copy of the protected review report, or an extract of the protected review report, to any other Commonwealth body, a State body or an entity but only for the purposes of one or more of the following:
  • (a) the performance of the functions of a Commonwealth body relating to responding to, mitigating or resolving a cyber security incident;
  • (b) the performance of the functions of a State body relating to responding to, mitigating or resolving a cyber security incident;
  • (c) informing and advising the Minister, and other Ministers of the Commonwealth, about a cyber security incident;
  • (d) the performance of the functions of an intelligence agency.

Division 3—Protection of information relating to reviews

Read this container only

55 Limitations on use and disclosure by the Board

Permitted use and disclosure

  • (1) The Board may make a record of, use or disclose information provided by an entity, Commonwealth body or State body under section 48, 49 or 51 but only:
  • (a) for the purposes of one or more of the following:
    • (i) performing functions or exercising powers under this Part or Part 6 as it applies to this Part;
    • (ii) proceedings under, or arising out of, section 137.1 or 137.2 of the Criminal Code (false and misleading information and documents) that relate to this Act;
    • (iii) proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
    • (iv) the performance of the functions of a Commonwealth body relating to responding to, mitigating or resolving a cyber security incident;
    • (v) the performance of the functions of a State body relating to responding to, mitigating or resolving a cyber security incident;
    • (vi) informing and advising the Minister, and other Ministers of the Commonwealth, about a cyber security incident;
    • (vii) the performance of the functions of an intelligence agency; or
  • (b) as otherwise authorised by a provision of this Part.

Note: Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.

Restriction on use and disclosure for civil or regulatory action

  • (2) However, the Board must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention by the entity or body of a Commonwealth, State or Territory law other than:
  • (a) a contravention by the entity or body of this Part; or
  • (b) a contravention by the entity or body of a law that imposes a penalty or sanction for a criminal offence.

Note: See also section 58 in relation to admissibility of the information in proceedings.

Interaction with the Privacy Act 1988

  • (3) Subsection (1) does not authorise the Board to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.

Information not covered by the prohibitions in this section

  • (4) Subsection (1) does not prohibit the recording, use or disclosure of information that has already been lawfully made available to the public.

56 Limitations on secondary use and disclosure

  • (1) This section applies to information that:
  • (a) has been provided to the Board under section 48, 49 or 51; and
  • (b) has been obtained under section 54 or 55, or this section, by an entity, a Commonwealth body or a State body; and
  • (c) is held by the entity, Commonwealth body or State body.

Note: This section does not apply to the information to the extent that it has been otherwise obtained by the entity, Commonwealth body or State body.

Permitted use and disclosure

  • (2) The entity, Commonwealth body or State body may make a record of, use or disclose the information but only:
  • (a) for the purposes of one or more of the following:
    • (i) performing functions or exercising powers, or assisting in the performance of functions or the exercise of powers, under this Part or Part 6 as it applies to this Part;
    • (ii) proceedings under, or arising out of, section 137.1 or 137.2 of the Criminal Code (false and misleading information and documents) that relate to this Act;
    • (iii) proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
    • (iv) the performance of the functions of a Commonwealth body relating to responding to, mitigating or resolving a cyber security incident;
    • (v) the performance of the functions of a State body relating to responding to, mitigating or resolving a cyber security incident;
    • (vi) informing and advising the Minister, and other Ministers of the Commonwealth, about a cyber security incident;
    • (vii) the performance of the functions of an intelligence agency; or
  • (b) as otherwise authorised by a provision of this Part.

Restriction on use and disclosure for civil or regulatory action

  • (3) However, the entity, Commonwealth body or State body must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention, by the entity or body that originally provided the information under section 48, 49 or 51, of a Commonwealth, State or Territory law other than:
  • (a) a contravention by the entity or body of this Part; or
  • (b) a contravention by the entity or body of a law that imposes a penalty or sanction for a criminal offence.

Note: See also section 58 in relation to admissibility of the information in proceedings.

Interaction with the Privacy Act 1988

  • (4) Subsection (2) does not authorise the entity, Commonwealth body or State body to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.

Information not covered by the prohibitions in this section

  • (5) Subsection (2) does not prohibit:
  • (a) recording, use or disclosure of information that has already been lawfully made available to the public (for example, in the publication of the final review report); or
  • (b) if the entity is an individual—recording, use or disclosure of personal information about the individual; or
  • (c) if the entity or body is the entity or body that originally provided the information under section 48, 49 or 51—the entity’s or body’s own information; or
  • (d) recording, use or disclosure of that entity’s or body’s own information, with the consent of that entity or body, by another entity, a Commonwealth body or a State body; or
  • (e) recording, use or disclosure of information for the purposes of carrying out a State’s constitutional functions, powers or duties.

Civil penalty for contravention of this section

  • (6) An entity is liable to a civil penalty if:
  • (a) the entity contravenes subsection (2); and
  • (b) the entity is not a Commonwealth officer; and
  • (c) any of the following applies:
    • (i) the information is sensitive information about an individual and the individual has not consented to the record, use or disclosure of the information;
    • (ii) the information is confidential or commercially sensitive;
    • (iii) the record, use or disclosure of the information would, or could reasonably be expected to, cause damage to the security, defence or international relations of the Commonwealth.

Note 1: See the Criminal Code for offences for Commonwealth officers.

Note 2: This Act does not make the Crown (other than an authority of the Crown) liable to a civil penalty.

Civil penalty: 60 penalty units.

58 Admissibility of information given by an entity that has been requested or required by the Board

  • (1) This section applies to information that:
  • (a) has been provided by an entity to the Board under section 48, 49 or 51; and
  • (b) has been obtained under section 48, 49, 51, 54, 55 or 56 by a Commonwealth body or a State body; and
  • (c) is held by the Commonwealth body or State body.

Note: This section does not apply to information held by the Commonwealth body or State body to the extent that it has been otherwise obtained.

  • (2) The information is not admissible in evidence against the entity in any of the following proceedings:
  • (a) criminal proceedings for an offence under a Commonwealth law, other than:
    • (i) proceedings for an offence against section 137.1 or 137.2 of the Criminal Code (which deal with false or misleading information or documents) that relates to this Act; or
    • (ii) proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
  • (b) civil proceedings for a contravention of a civil penalty provision of a Commonwealth law, other than a civil penalty provision of this Part;
  • (c) proceedings for a breach of any other Commonwealth, State or Territory law (including the common law);
  • (d) proceedings before a tribunal of the Commonwealth, a State or a Territory.
  • (4) This section does not apply to the following:
  • (a) the proceedings of a coronial inquiry or a Royal Commission in Australia;
  • (b) proceedings in a federal court exercising original jurisdiction in which a writ of mandamus or prohibition or an injunction is sought against an officer or officers of the Commonwealth.

Note: For federal court, see section 2B of the Acts Interpretation Act 1901.

  • (5) This section does not limit or affect any right, privilege or immunity that the entity has, apart from this section, as a defendant in any proceedings.

59 Disclosure of draft review reports prohibited

  • (1) An entity is liable to a civil penalty if:
  • (a) the entity receives a draft review report under section 51; and
  • (b) the entity makes a record of, discloses or otherwise uses any information in the draft review report.

Civil penalty: 60 penalty units.

  • (2) Subsection (1) does not apply if the making of the record, disclosure or use is:
  • (a) for the purpose of preparing a submission to the Board in accordance with section 51; or
  • (b) if the entity is the entity that originally provided the information under section 48 or 49—of the entity’s own information; or
  • (c) with the consent of the Chair of the Board; or
  • (d) after the information has already been lawfully made available to the public (for example, in the publication of the final review report);
  • (e) for the purposes of carrying out a State’s constitutional functions, powers or duties.
  • (3) Despite section 96 of the Regulatory Powers Act, in proceedings for a civil penalty order against an entity for a contravention of subsection (1), the entity does not bear an evidential burden in relation to the matters in subsection (2).

Note: This Act does not make the Crown (other than an authority of the Crown) liable to a civil penalty.

Division 4—Establishment, functions and powers of the Board

Read this container only

60 Cyber Incident Review Board

  • (1) The Cyber Incident Review Board is established by this section.
  • (2) For the purposes of paragraph (a) of the definition of Department of State in section 8 of the Public Governance, Performance and Accountability Act 2013, the Cyber Incident Review Board is prescribed in relation to the Department.

Note: Subject to subsection (2), this means that the chair and members of the Board are officials of the Department for the purposes of the Public Governance, Performance and Accountability Act 2013.

61 Constitution of the Board

The Board consists of the following members:

  • (a) a Chair;
  • (b) at least 2, and not more than 6, other standing members.

62 Functions of the Board

  • (1) The functions of the Board are:
  • (a) to cause reviews to be conducted by review panels in relation to cyber security incidents, or series of related cyber security incidents, to:
    • (i) identify factors that contributed to the incident or series of incidents; and
    • (ii) make recommendations to government and industry about actions that could be taken to prevent, detect, respond to or minimise the impact of, incidents of a similar nature in the future; and
    • (iii) report publicly on the review; and
  • (b) any other functions conferred on the Board by this Act or the rules.

Note: See section 46 in relation to the circumstances in which a cyber security incident may be reviewed.

  • (2) It is not a function of the Board to:
  • (a) apportion blame in relation to a cyber security incident; or
  • (b) provide the means to determine the liability of any entity in relation to a cyber security incident; or
  • (c) allow any adverse inference to be drawn from the fact that an entity is the subject of a review.

However, even though blame or liability may be inferred, or an adverse inference may be made, by a person other than the Board, this does not prevent the Board from carrying out its functions.

  • (3) The Board has power to do all things necessary or convenient to be done for or in connection with the performance of the Board’s functions.
  • (4) The Board must not perform a function or exercise a power under this Part at a particular time if the performance of the function or the exercise of the power at that time would prejudice the investigation of, or the conduct of proceedings relating to, an offence or a contravention of a civil penalty provision under a law of the Commonwealth or of a State or Territory.
  • (5) The rules may prescribe the circumstances in which cyber security incidents are a series of related incidents for the purposes of this section.

Note: For example, the rules may prescribe that cyber security incidents are a series of related incidents if the incidents involve a common type of impacted system or a common attack method.

63 Independence

Subject to this Act and to other laws of the Commonwealth, the Cyber Incident Review Board:

  • (a) has complete discretion in the performance of the Board’s functions and the exercise of the Board’s powers; and
  • (b) is not subject to direction by any person in relation to the performance or exercise of those functions or powers.

Note: The Minister must approve the terms of reference for a review to be undertaken by the Board: see subsection 46(2).

Division 5—Terms and conditions of appointment of the Chair and members of the Board

Read this container only

64 Appointment of Chair

  • (1) The Chair of the Board is to be appointed by the Minister by written instrument.

Note: The Chair may be reappointed: see section 33AA of the Acts Interpretation Act 1901.

  • (2) The Chair may be appointed on a full‑time or part‑time basis.
  • (3) The Chair holds office for the period specified in the instrument of appointment. The period must not exceed 4 years.
  • (4) The rules may make provision for or in relation to the appointment of the Chair, including in relation to eligibility for appointment.

65 Remuneration of the Chair

  • (1) The Chair of the Board is to be paid the remuneration that is determined by the Remuneration Tribunal. If no determination of that remuneration by the Tribunal is in operation, the Chair is to be paid the remuneration that is prescribed by the rules.
  • (2) The Chair is to be paid the allowances that are prescribed by the rules.
  • (3) This section has effect subject to the Remuneration Tribunal Act 1973.

66 Appointment of standing members of the Board

  • (1) A standing member of the Board is to be appointed by the Minister by written instrument.

Note: A member may be reappointed: see section 33AA of the Acts Interpretation Act 1901.

  • (2) A standing member of the Board may be appointed on a full‑time or part‑time basis.
  • (3) A standing member of the Board holds office for the period specified in the instrument of appointment. The period must not exceed 4 years.
  • (4) The rules may make provision for or in relation to the appointment of standing members of the Board, including in relation to eligibility for appointment.

67 Remuneration of standing members of the Board

  • (1) A standing member of the Board is to be paid the remuneration that is determined by the Remuneration Tribunal. If no determination of that remuneration by the Tribunal is in operation, a standing member of the Board is to be paid the remuneration that is prescribed by the rules.
  • (2) A standing member of the Board is to be paid the allowances that are prescribed by the rules.
  • (3) This section has effect subject to the Remuneration Tribunal Act 1973.

68 Acting Chair

The Minister may, by written instrument, appoint a standing member of the Board to act as the Chair:

  • (a) during a vacancy in the office of Chair (whether or not an appointment has previously been made to the office); or
  • (b) during any period, or during all periods, when the Chair:
    • (i) is absent from duty or from Australia; or
    • (ii) is, for any reason, unable to perform the duties of the office.

Note: For rules that apply to acting appointments, see section 33A of the Acts Interpretation Act 1901.

69 Terms and conditions etc. for standing members

  • (1) The rules may make provision for or in relation to the Board, including for or in relation to the following:
  • (a) membership of the Board (subject to section 61);
  • (b) terms of appointment of the Chair and standing members;
  • (c) acting appointments;
  • (d) resignation of the Chair and standing members;
  • (e) disclosure of interests by the Chair and standing members;
  • (f) termination of appointment of the Chair and standing members;
  • (g) leave of absence of the Chair and standing members.
  • (2) The Chair and a standing member of the Board holds office on the terms and conditions (if any) that are determined by the Minister in relation to matters not covered by this Act or the rules.

Division 6—Expert Panel, staff assisting and consultants

Read this container only

70 Expert Panel

  • (1) The Board may, in writing, establish an Expert Panel.
  • (2) The Expert Panel consists of such members as the Board from time to time appoints by written instrument.

Note: A member of the Expert Panel may be reappointed: see section 33AA of the Acts Interpretation Act 1901.

  • (3) One or more members of the Expert Panel are to be appointed by the Board, in writing and in accordance with the terms of reference for a review under section 46, to the review panel for the review to assist in the review.
  • (4) The office of member of the Expert Panel, and the office of member of the Expert Panel assisting in relation to a review, are not public offices within the meaning of the Remuneration Tribunal Act 1973.
  • (5) The rules may make provision for or in relation to the Expert Panel, including for or in relation to the following:
  • (a) membership of the Expert Panel;
  • (b) appointment of members to the Expert Panel;
  • (c) appointments of its members to a review panel for a review;
  • (d) terms of appointment of members;
  • (e) remuneration of members;
  • (f) resignation of members;
  • (g) disclosure of interests by members;
  • (h) termination of appointment of members;
    • (i) leave of absence of members.

71 Arrangements relating to staff of the Department

  • (1) The staff assisting the Cyber Incident Review Board are to be APS employees, or officers or employees of a Commonwealth body, whose services are made available to the Board in connection with the performance of any of the Board’s functions or the exercise of any of the Board’s powers.
  • (2) When performing services for the Board, the staff are subject to the directions of the Board.

72 Consultants

The Secretary of the Department may, on behalf of the Commonwealth, engage consultants to assist in the performance of any of the Cyber Incident Review Board’s functions or the exercise of any of the Board’s powers.

Division 7—Other matters relating to the Board

Read this container only

73 Board procedures

  • (1) Subject to this Act and the rules, the Board may:
  • (a) operate in the way it determines; and
  • (b) regulate proceedings at its meetings as it considers appropriate.
  • (2) The rules may make provision for or in relation to the operation and procedures of the Board.

74 Liability

Responding to notices to produce

  • (1) An entity is not liable to an action or other proceeding for damages for or in relation to an act done or omitted in good faith in compliance with section 49 (Chair may obtain documents from certain entities).
  • (2) An officer, employee or agent of an entity is not liable to an action for damages for or in relation to an act done or omitted in good faith in connection with an act done or omitted by the entity as mentioned in subsection (1).

The Board etc.

  • (3) A person who is or has been:
  • (a) the Chair; or
  • (b) a standing member of the Board; or
  • (c) a member of the Expert Panel; or
  • (d) a member of the staff assisting the Board (as mentioned in section 71); or
  • (e) a consultant assisting the Board (as mentioned in section 72); or
  • (f) a witness appearing in a review;

is not liable to an action or other proceeding for damages for or in relation to an act done or omitted in good faith in the performance or purported performance of a function or duty conferred by this Part, or the exercise or purported exercise of a power conferred by this Part.

Evidential burden

  • (4) An entity or person who wishes to rely on subsection (1), (2) or (3) in relation to an action or other proceeding bears an evidential burden (within the meaning of the Regulatory Powers Act) in relation to that matter.

75 Certification of involvement in review

  • (1) The Chair may issue a certificate stating that a specified person who is, or has been:
  • (a) a standing member of the Board; or
  • (b) a member of the Expert Panel; or
  • (c) a member of the staff assisting the Board (as mentioned in section 71); or
  • (d) a consultant assisting the Board (as mentioned in section 72); or
  • (e) a witness appearing in a review;

is involved, or has been involved, in a review under this Part into a specified matter.

  • (2) The Secretary may issue a certificate stating that a specified person who is, or has been, the Chair is involved, or has been involved, in a review under this Part into a specified matter.
  • (3) If, under subsection (1) or (2), a certificate is issued in relation to a person and a specified matter, the person:
  • (a) is not obliged to comply with a subpoena or similar direction of a federal court or a court of a State or Territory to attend and answer questions relating to the matter; and
  • (b) is not compellable to give an expert opinion in any civil or criminal proceedings in a federal court or a court of a State or Territory in relation to the matter.
  • (4) This section does not apply to a coronial inquiry.

76 Annual report

The annual report prepared by the Secretary and given to the Minister under section 46 of the Public Governance, Performance and Accountability Act 2013 for a reporting period must also include the following:

  • (a) the number of each of the following during the period:
    • (i) reviews commenced;
    • (ii) reviews completed;
    • (iii) reviews discontinued;
  • (b) a brief description of each of those reviews;
  • (c) the status of any reviews not yet completed at the end of the period;
  • (d) the reasons for discontinuing any reviews during the period;
  • (e) the number of times the Minister refused to approve the terms of reference for a review during the period;
  • (f) the number of members of the Expert Panel during the period;
  • (g) the number of Expert Panel members appointed to a review panel during the period;
  • (h) the number of times appointment of a member of the Board was terminated during the period.

77 Rules may prescribe reporting requirements etc.

The rules may prescribe requirements with which the Board must comply relating to:

  • (a) the communication of information to the public; and
  • (b) reporting to the Minister;

about the work of the Board.