Cybersecurity ยท Australia
Cybersecurity law & regulation in Australia (2026)
Australia shaded by its cybersecurity status
Cybersecurity in Australia: comprehensive law.
FrameworkCyber Security Act 2024 (Cth) (Australia's first standalone cyber law), supported by the Security of Critical Infrastructure Act 2018 (SOCI Act), the Privacy Act 1988 Notifiable Data Breaches (NDB) scheme, and sectoral rules such as APRA Prudential Standard CPS 234; administered by the Department of Home Affairs, the Australian Signals Directorate (ASD/ACSC), OAIC and APRA.
Australia now operates a comprehensive, multi-layered cybersecurity regime anchored by the Cyber Security Act 2024, its first dedicated cyber statute, which introduced mandatory ransomware-payment reporting (commenced 30 May 2025), enforceable smart-device security standards (commenced 4 March 2026), a Cyber Incident Review Board, and limited-use protections for voluntary information sharing. It is layered over the SOCI Act's cyber and risk-management obligations for 11 critical infrastructure sectors (with 12-hour/72-hour incident reporting), the Privacy Act's NDB scheme for personal-data breaches to the OAIC, and APRA CPS 234 for regulated financial entities. A first statutory review of the SOCI Act was delivered on 31 January 2026 and further reforms opened for consultation in March 2026.
Key points
Australia's first standalone cyber security statute establishes four pillars: mandatory security standards for smart devices, mandatory ransomware/extortion payment reporting, limited-use protections for information voluntarily shared with the National Cyber Security Coordinator, and a Cyber Incident Review Board (CIRB) to conduct no-fault post-incident reviews.
From 30 May 2025, entities carrying on business in Australia with annual turnover above A$3 million, and all responsible entities for critical infrastructure assets regardless of turnover, must report any ransomware or cyber-extortion payment to the Australian Signals Directorate (ASD) within 72 hours of making or becoming aware of the payment.
The Security of Critical Infrastructure Act 2018 imposes an all-hazards regime on 11 sectors (including energy, telecommunications, data storage/processing and finance): asset registration, a Critical Infrastructure Risk Management Program (CIRMP), and mandatory cyber-incident notification to ASD within 12 hours for critical incidents and 72 hours for other reportable incidents; further amendments were opened for consultation on 25 March 2026 following the first Independent Review delivered 31 January 2026.
The Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced on 4 March 2026 and apply to internet- and network-connectable consumer products manufactured or supplied on or after that date, requiring unique/user-set passwords, a public vulnerability disclosure process, and transparency about security-update support periods; the regime has extraterritorial reach to overseas manufacturers selling into Australia.
APP entities (Commonwealth agencies, businesses with turnover over A$3 million, health service providers, credit reporting bodies, TFN recipients and CDR/Digital ID accredited entities) must notify the OAIC and affected individuals of any 'eligible data breach' likely to result in serious harm; entities generally have 30 days to assess whether a breach is notifiable.
Prudential Standard CPS 234 requires all APRA-regulated entities (banks, insurers, superannuation funds) to maintain an information-security capability commensurate with the threat, ensure third-party providers meet equivalent controls, and notify APRA of any material information-security incident as soon as possible and no later than 72 hours after becoming aware; board-level accountability is mandatory.
Timeline - major decisions & events
The Australian Information Commissioner commenced civil penalty proceedings alleging Optus failed to take reasonable steps to protect 9.5 million customers' data, with potential penalties of up to A$2.22 million per contravention. It is the first major test of the Privacy Act's serious-interference provisions against a large breach.
OAIC โPart 3 of the Cyber Security Act 2024 took effect, requiring entities with turnover above A$3 million or operating critical infrastructure to report ransom/extortion payments to cyber.gov.au within 72 hours. It establishes Australia's first mandatory ransomware-payment reporting regime.
Department of Home Affairs โThe Act progressed 23 reforms from the Privacy Act Review, including a new statutory tort for serious invasions of privacy (effective by 10 June 2025) and stronger enforcement powers. It marks the most significant overhaul of Australian privacy law since the Privacy Act 1988.
OAIC โThe government published its roadmap to make Australia a 'world leader in cyber security by 2030', built on six cyber 'shields' and delivered across three horizons, backed by A$586.9 million in new funding. It set the policy direction for the Cyber Security Act and SOCI/Privacy reforms that followed.
Department of Home Affairs โHealth insurer Medibank disclosed a breach in which attackers exfiltrated ~520GB of data on 9.7 million current and former members; after Medibank refused a ~US$10 million ransom, data was published on the dark web. The incident, alongside Optus, catalysed Australia's cyber and privacy law overhaul.
OAIC โOptus disclosed a breach exposing personal data, including driver licence, passport and Medicare numbers, of around 9.5 million Australians, accessed via an unprotected API. The breach prompted emergency government data-sharing regulations and a national rethink of cyber obligations.
Queensland Government โThe Security Legislation Amendment (Critical Infrastructure Protection) Act received Royal Assent, requiring responsible entities to adopt and maintain a Critical Infrastructure Risk Management Program and introducing enhanced cyber-security obligations for systems of national significance. It completed the two-part SOCI reform package.
Department of Home Affairs โThe Security Legislation Amendment (Critical Infrastructure) Act commenced, extending the SOCI Act to 11 critical sectors and mandating reporting of significant cyber incidents to the ACSC (within 12 hours for critical impacts) plus government 'last resort' intervention powers. It transformed SOCI into a broad cyber-resilience regime.
Cyber and Infrastructure Security Centre โThe mandatory prudential standard required APRA-regulated banks, insurers and superannuation funds to maintain information-security capability, clarify board accountability, and notify APRA of material security incidents within 72 hours. It established baseline cyber obligations for the financial sector.
APRA โThe original SOCI Act created a register of critical infrastructure assets and information-gathering and ministerial directions powers across electricity, gas, water and ports. It laid the foundation for Australia's later critical-infrastructure cyber-security obligations.
Cyber and Infrastructure Security Centre โAmendments to the Privacy Act 1988 made breach notification mandatory, requiring covered entities to notify affected individuals and the OAIC of eligible data breaches likely to cause serious harm. It introduced Australia's first economy-wide mandatory breach-reporting obligation.
OAIC โThe Act inserted modern computer-related offences (unauthorised access, modification and impairment of data) into the Criminal Code, aligning Australia with the Council of Europe Convention on Cybercrime. It remains the foundational criminal-law basis for prosecuting cyber intrusions.
Federal Register of Legislation โAustralia - other topics
Cybersecurity in other countries
Last verified 7/25/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ