Don’t do SECURITY. Do business SECURELY.

Australia expands critical infrastructure security law

Amendments to Australia’s SOCI Act extend coverage to 11 sectors and introduce mandatory cyber incident reporting.

The Security Legislation Amendment (Critical Infrastructure) Act 2021 receives Royal Assent today, significantly expanding Australia’s Security of Critical Infrastructure Act 2018 (SOCI).

Key points

  • Coverage grows to 11 sectors, including data storage and processing, financial services, communications, energy, health and transport.
  • Mandatory cyber incident reporting: 12 hours for significant impact and 72 hours for other impacts.
  • Government assistance and intervention powers to respond to serious cyber attacks.
  • Asset registration obligations extend to more critical asset classes.
  • A second bill will add risk management programmes and enhanced obligations for systems of national significance.

UK organisations operating or supplying critical assets in Australia, including cloud and data centre providers, may now fall within scope. Similar direction of travel is visible in the UK’s Cyber Security and Resilience Bill.

Source: Security Legislation Amendment (Critical Infrastructure) Act 2021 (Federal Register of Legislation)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights