Australia’s Cyber Security Act 2024 receives Royal Assent today, the country’s first standalone cyber security legislation and a central part of its 2023–2030 Cyber Security Strategy.
Key points
- Businesses above a turnover threshold must report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours.
- Mandatory security standards will apply to consumer smart devices supplied in Australia.
- Information shared with the National Cyber Security Coordinator gets limited-use protections.
- A Cyber Incident Review Board will conduct no-fault reviews of significant incidents.
UK organisations with Australian operations need processes to capture and report extortion payments. Manufacturers of connected devices will face requirements similar to the UK’s Product Security and Telecommunications Infrastructure regime.
Source: Cyber Security Act 2024 (Federal Register of Legislation)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.