Loading…
Loading…
The Cyber Security Act 2024 (Cth) is the flagship of a three-bill cybersecurity legislative package passed together by the Australian Parliament in late November 2024 — the others being the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 and the Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024. Together they implement the legislative reforms identified in the 2023-2030 Australian Cyber Security Strategy.
Four distinct regulatory regimes are stood up by the Act:
1. Security standards for smart / connected products — the Minister for Cyber Security may, by rules, prescribe mandatory minimum cyber-security standards for "relevant connectable products" supplied in Australia (consumer IoT and adjacent categories). Suppliers must provide statements of compliance and are subject to civil-penalty enforcement and product-recall powers vested in Home Affairs.
2. Mandatory ransomware / cyber-extortion payment reporting — "reporting business entities" (Australian-carrying-on-business entities with annual turnover above AUD 3 million, plus responsible entities for critical infrastructure assets under the SOCI Act) must report ransomware and cyber-extortion payments to the Australian Signals Directorate via cyber.gov.au within 72 hours of payment (or awareness that a payment was made on their behalf). Reportable details include the payment amount, payment method, attacker identifiers, and the underlying cyber- incident context. Non-compliance attracts a civil penalty of 60 penalty units (~AUD 19,800 per offence for corporations). The ransomware-reporting regime commenced 30 May 2025 (i.e., six months after Royal Assent, the proclamation-or-six-months trigger).
3. Cyber Incident Review Board (CIRB) — an independent statutory body conducting no-blame post-incident reviews of significant cyber-security incidents, modelled loosely on the US Cyber Safety Review Board and Australia's own Air Transport Safety Bureau. The CIRB reports publicly on systemic findings, without attributing blame to specific entities.
4. "Limited use" protection — information voluntarily disclosed to the National Cyber Security Coordinator (within Home Affairs) in the context of a significant cyber-security incident is subject to statutory use restrictions: it may not be used as evidence against the disclosing entity in most civil and regulatory proceedings. This is intended to remove the chilling effect that the prospect of enforcement creates around voluntary information-sharing during live incident response.
The Act passed both chambers on 25 November 2024 (House of Representatives) and 25-26 November 2024 (Senate), and received Royal Assent on 29 November 2024 as Act No. 98 of 2024.
the first AUKUS / Five Eyes member outside the US/UK to adopt a standalone cyber-security framework statute; the structure (mandatory IoT standards + ransomware-payment reporting + CIRB + limited-use protection) is likely to influence New Zealand, Singapore, and Japan rule-making, and the Active Cyber Defense law architecture in Japan (filed separately).
GCP, Cloudflare, Akamai, plus consumer-IoT brands (Apple HomeKit, Google Nest, Amazon Ring, Samsung SmartThings, Xiaomi, Tuya-powered white-label devices) all face new IoT-security-standards exposure for the Australian market. Material capex for product-recertification workflows, but not market-exit-grade friction.
reporting clock combined with ASD's coordination role with the AFP and ACSC raises the operational cost of paying ransoms in Australia. Likely to depress aggregate AU ransom payments and shift attacker targeting toward less-regulated APAC jurisdictions.
(Chubb, AIG, Marsh, QBE, IAG) will need to align policy wordings with statutory reporting duties; ransom-coverage clauses may tighten or be repriced.
amended SOCI Act, broadening the universe of cyber-incident reporting duties for critical-infrastructure responsible entities (energy, water, telco, transport, finance, healthcare, food, defence, higher-ed, data-storage).
rules — Home Affairs has not yet finalised the security-standards rule list as of filing date.
practice with stat-decl-style self-reporting or with deeper technical-evidence requirements (forensic logs, attacker communications).
Legislation Amendment Act 2024, passed in parallel) — overlap between mandatory data-breach notification (OAIC) and ransomware- payment notification (ASD) channels.
shared with the ACSC and CIRB or remain narrowly construed to the National Cyber Security Coordinator.