The Commonwealth Government's 2023 Cyber Security Strategy outlines six 'cyber shields' to make Australia a cybersecurity leader by 2030. Read more at 2023-2030 Australian Cyber Security Strategy.
The 'cyber shields' include strong businesses and citizens, safe technology, threat sharing, protected critical infrastructure, sovereign capabilities, and global leadership. The strategy supports small businesses in handling cyber incidents and promotes safer technology to protect assets and ensure trust. It emphasises Australia’s role in international cyber law and regional support.
The Government proposed amending the Security of Critical Infrastructure Act 2018 (Cth) ("SOCI Act") to address gaps from recent cyber incidents. See Security of Critical Infrastructure. Amendments include clarifying data protection obligations, introducing a last-resort power for the Minister, simplifying information sharing, and consolidating telecommunications security under the SOCI Act.
In 2022-23, the MCIR regime reported 188 significant cyber incidents. The Government committed to minimal regulatory burdens while supporting industry, aligning with the Privacy Act 1988 (Cth) (for more information, see Privacy Law page).
2023-2030 Australian Cyber Security Strategy: Legislative Reforms Consultation Paper
The Consultation Paper covered new cyber security laws and SOCI Act amendments. It did not address “co-design” initiatives or the Privacy Act Review.
The Government considered SOCI Act reforms due to gaps from recent cyber incidents. Amendments included clarifying data protection obligations, introducing a last-resort power for the Minister, simplifying information sharing, allowing the Secretary to direct entities to fix deficiencies, and consolidating telecommunications security under the SOCI Act.
Proposed changes to the SOCI Act included expanding the definition of "asset" to include 'business-critical data', updating rules to classify risks, allowing directions to prevent incident consequences, and authorizing information sharing (see page 45 of the consultation paper).
Importance of Protecting Critical Infrastructure
Critical infrastructure is vital for daily life and national security. Cyber threats, like the 2022 Optus and Medibank incidents, highlighted the impact of breaches.