Skip to content
World Watch/Australia/Cybersecurity

Cybersecurity ยท Australia

Cybersecurity law & regulation in Australia (2026)

Comprehensive lawCountry index 84 ยท A

Australia shaded by its cybersecurity status

Cybersecurity in Australia: comprehensive law.

FrameworkCyber Security Act 2024 (Cth) (Australia's first standalone cyber law), supported by the Security of Critical Infrastructure Act 2018 (SOCI Act), the Privacy Act 1988 Notifiable Data Breaches (NDB) scheme, and sectoral rules such as APRA Prudential Standard CPS 234; administered by the Department of Home Affairs, the Australian Signals Directorate (ASD/ACSC), OAIC and APRA.

Australia now operates a comprehensive, multi-layered cybersecurity regime anchored by the Cyber Security Act 2024, its first dedicated cyber statute, which introduced mandatory ransomware-payment reporting (commenced 30 May 2025), enforceable smart-device security standards (commenced 4 March 2026), a Cyber Incident Review Board, and limited-use protections for voluntary information sharing. It is layered over the SOCI Act's cyber and risk-management obligations for 11 critical infrastructure sectors (with 12-hour/72-hour incident reporting), the Privacy Act's NDB scheme for personal-data breaches to the OAIC, and APRA CPS 234 for regulated financial entities. A first statutory review of the SOCI Act was delivered on 31 January 2026 and further reforms opened for consultation in March 2026.

Key points

Cyber Security Act 2024 โ€” standalone national law

Australia's first standalone cyber security statute establishes four pillars: mandatory security standards for smart devices, mandatory ransomware/extortion payment reporting, limited-use protections for information voluntarily shared with the National Cyber Security Coordinator, and a Cyber Incident Review Board (CIRB) to conduct no-fault post-incident reviews.

Mandatory ransomware-payment reporting

From 30 May 2025, entities carrying on business in Australia with annual turnover above A$3 million, and all responsible entities for critical infrastructure assets regardless of turnover, must report any ransomware or cyber-extortion payment to the Australian Signals Directorate (ASD) within 72 hours of making or becoming aware of the payment.

SOCI Act โ€” critical infrastructure duties

The Security of Critical Infrastructure Act 2018 imposes an all-hazards regime on 11 sectors (including energy, telecommunications, data storage/processing and finance): asset registration, a Critical Infrastructure Risk Management Program (CIRMP), and mandatory cyber-incident notification to ASD within 12 hours for critical incidents and 72 hours for other reportable incidents; further amendments were opened for consultation on 25 March 2026 following the first Independent Review delivered 31 January 2026.

Smart-device security standards in force

The Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced on 4 March 2026 and apply to internet- and network-connectable consumer products manufactured or supplied on or after that date, requiring unique/user-set passwords, a public vulnerability disclosure process, and transparency about security-update support periods; the regime has extraterritorial reach to overseas manufacturers selling into Australia.

Privacy Act โ€” Notifiable Data Breaches (NDB) scheme

APP entities (Commonwealth agencies, businesses with turnover over A$3 million, health service providers, credit reporting bodies, TFN recipients and CDR/Digital ID accredited entities) must notify the OAIC and affected individuals of any 'eligible data breach' likely to result in serious harm; entities generally have 30 days to assess whether a breach is notifiable.

Financial-sector rule: APRA CPS 234

Prudential Standard CPS 234 requires all APRA-regulated entities (banks, insurers, superannuation funds) to maintain an information-security capability commensurate with the threat, ensure third-party providers meet equivalent controls, and notify APRA of any material information-security incident as soon as possible and no later than 72 hours after becoming aware; board-level accountability is mandatory.

Timeline - major decisions & events

Aug 8, 2025enforcementofficial
OAIC sues Optus in Federal Court over 2022 breach

The Australian Information Commissioner commenced civil penalty proceedings alleging Optus failed to take reasonable steps to protect 9.5 million customers' data, with potential penalties of up to A$2.22 million per contravention. It is the first major test of the Privacy Act's serious-interference provisions against a large breach.

OAIC โ†—
May 30, 2025lawofficial
Mandatory ransomware payment reporting commences

Part 3 of the Cyber Security Act 2024 took effect, requiring entities with turnover above A$3 million or operating critical infrastructure to report ransom/extortion payments to cyber.gov.au within 72 hours. It establishes Australia's first mandatory ransomware-payment reporting regime.

Department of Home Affairs โ†—
Dec 10, 2024lawofficial
Privacy and Other Legislation Amendment Act 2024 receives Royal Assent

The Act progressed 23 reforms from the Privacy Act Review, including a new statutory tort for serious invasions of privacy (effective by 10 June 2025) and stronger enforcement powers. It marks the most significant overhaul of Australian privacy law since the Privacy Act 1988.

OAIC โ†—
Nov 21, 2023guidanceofficial
2023-2030 Australian Cyber Security Strategy released

The government published its roadmap to make Australia a 'world leader in cyber security by 2030', built on six cyber 'shields' and delivered across three horizons, backed by A$586.9 million in new funding. It set the policy direction for the Cyber Security Act and SOCI/Privacy reforms that followed.

Department of Home Affairs โ†—
Oct 13, 2022incidentofficial
Medibank ransomware breach disclosed

Health insurer Medibank disclosed a breach in which attackers exfiltrated ~520GB of data on 9.7 million current and former members; after Medibank refused a ~US$10 million ransom, data was published on the dark web. The incident, alongside Optus, catalysed Australia's cyber and privacy law overhaul.

OAIC โ†—
Sep 22, 2022incidentofficial
Optus data breach exposes 9.5 million customers

Optus disclosed a breach exposing personal data, including driver licence, passport and Medicare numbers, of around 9.5 million Australians, accessed via an unprotected API. The breach prompted emergency government data-sharing regulations and a national rethink of cyber obligations.

Queensland Government โ†—
Apr 2, 2022lawofficial
SLACIP Act 2022 strengthens critical infrastructure protection

The Security Legislation Amendment (Critical Infrastructure Protection) Act received Royal Assent, requiring responsible entities to adopt and maintain a Critical Infrastructure Risk Management Program and introducing enhanced cyber-security obligations for systems of national significance. It completed the two-part SOCI reform package.

Department of Home Affairs โ†—
Dec 2, 2021lawofficial
SLACI Act 2021 expands SOCI Act with mandatory incident reporting

The Security Legislation Amendment (Critical Infrastructure) Act commenced, extending the SOCI Act to 11 critical sectors and mandating reporting of significant cyber incidents to the ACSC (within 12 hours for critical impacts) plus government 'last resort' intervention powers. It transformed SOCI into a broad cyber-resilience regime.

Cyber and Infrastructure Security Centre โ†—
Jul 1, 2019guidanceofficial
APRA CPS 234 Information Security standard takes effect

The mandatory prudential standard required APRA-regulated banks, insurers and superannuation funds to maintain information-security capability, clarify board accountability, and notify APRA of material security incidents within 72 hours. It established baseline cyber obligations for the financial sector.

APRA โ†—
Jul 11, 2018lawofficial
Security of Critical Infrastructure Act 2018 enacted

The original SOCI Act created a register of critical infrastructure assets and information-gathering and ministerial directions powers across electricity, gas, water and ports. It laid the foundation for Australia's later critical-infrastructure cyber-security obligations.

Cyber and Infrastructure Security Centre โ†—
Feb 22, 2018lawofficial
Notifiable Data Breaches scheme commences

Amendments to the Privacy Act 1988 made breach notification mandatory, requiring covered entities to notify affected individuals and the OAIC of eligible data breaches likely to cause serious harm. It introduced Australia's first economy-wide mandatory breach-reporting obligation.

OAIC โ†—
Oct 1, 2001lawofficial
Cybercrime Act 2001 establishes core computer offences

The Act inserted modern computer-related offences (unauthorised access, modification and impairment of data) into the Criminal Code, aligning Australia with the Council of Europe Convention on Cybercrime. It remains the foundational criminal-law basis for prosecuting cyber intrusions.

Federal Register of Legislation โ†—

Australia - other topics

Cybersecurity in other countries

Last verified 7/25/2026 ยท Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite ยท State of Technology Regulation 2026 ยท Explore the full world map โ†’