It's not just cyber security, it's cyber resilience and cyber regulation
As many have realised, it’s not a question of ‘if’ but ‘when’ a cyber security breach happens. The scale, speed and impact of cyber security breaches means that you need to be prepared to act on the assumption that a cyber security breach will occur, and to ensure that your organisation is resilient enough to recover from the breach. This requires planning and testing your business continuity and cyber breach plans to make sure that your organisation can continue to operate effectively even if there is a very significant incident that incapacitates your IT systems. ASIC has put Boards on notice that it expects them to ensure that their organisations pay sufficient attention and devote adequate resources to cyber security and cyber resilience.
And, if its not enough dealing with the impact of a cyber breach from a resilience perspective, you also have to deal with the regulatory implications of a cyber security incident. These range from ASX notifications under continuous disclosure obligations for listed entities, to notifications of regulators (the OAIC, the CISC and APRA) under a range of statutory notification obligations.
Our team has been advising clients involved in two of the most significant breaches in recent times on navigating through this maze of issues, as well as on the regulatory investigations, representative claims and class actions that have resulted from those breaches.
Our Cyber Security Insights
SOCI Act update: Proposal to significantly extend and enhance the enforcement of the SOCI Act
The Department of Home Affairs (Department) has released the Streamlining and Modernising the Security of Critical Infrastructure Act 2018 Consultation Paper (Consultation Paper) here, proposing a second tranche of reforms to the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act).
15 July 2026
SOCI update: Exposure draft enhancements to CIRMP Rules and consultation on proposed amendments to Ministerial Directions Powers
As foreshadowed in our earlier insight here, the Department of Home Affairs (Department) has now released an exposure draft of proposed enhancements to the Security of Critical Infrastructure (Critical Infrastructure Risk Management Program) Rules 2023 (CIRMP Rules), and a separate consultation paper on proposed amendments to the Ministerial Directions Powers in Part 3 of the Security of Critical Infrastructure Act 2018 (SOCI Act).
09 April 2026
SOCI update: proposed enhancements to CIRMP Rules
At the end of 2025, the Department of Home Affairs (the Department) released a consultation paper for proposed enhancements to the Security of Critical Infrastructure (Critical Infrastructure Risk Management Program) Rules 2023 (CIRMP Rules) for certain asset classes (Consultation Paper).
30 January 2026
The Protective Security Policy Framework has been updated: what’s new?
The Department of Home Affairs published the 2025 Annual Release of the Protective Security Policy Framework on 24 July 2025 (PSPF 2025).
10 September 2025
Technology is shaping productivity: Lessons from the 2025 KWM Digital Future Summit
How is technology changing what productivity means? And how can it secure our digital future across the region?
03 September 2025
SFC issues further guidance on custody of virtual assets for exchanges
The Securities and Futures Commission (SFC) has issued a circular detailing its expected standards and good practices for the custody of client virtual assets by licensed virtual asset trading platform operators (Platform Operators) (Circular). These are exchanges regulated under the Anti-Money Laundering and Counter-Terrorist Financing Ordinance (Cap. 615) and/or the Securities and Futures Ordinance (Cap. 571), also known as “VATPs”.
20 August 2025
Digital Future Summit 2025
In 8 sessions across 4 days, our lawyers and leading experts across Australia's digital and regulatory landscape looked at what the digital future holds.
13 August 2025
Updates to the Annual CIRMP Report webform
Responsible entities who are submitting their 2025 Critical Infrastructure Risk Management Program (CIRMP) report should be aware that the form was updated by the Critical Infrastructure Security Centre (CISC) in April this year.
24 July 2025
Consumer energy resources: Cyber security
Cybersecurity considerations are increasingly critical in the management of consumer energy resources.
09 July 2025
SOCI Act update: Key Cyber Security and Critical Infrastructure Rules have been registered
Following a period of consultation on rules to support the Government’s Omnibus Cyber Security and Critical Infrastructure package discussed here, 4 of the 6 proposed rules have now been registered.
13 March 2025
Cyber security - if you share an incident report with the government, can it come back to bite you?
Cyber security legislation enacted by the Australian Parliament in late 2024 sought to encourage full and frank disclosure to the government of information by organisations impacted by serious cyber security incidents.
07 February 2025
CISC is consulting on rules to be made under Omnibus Cyber Security and Critical Infrastructure Package
The Cyber and Infrastructure Security Centre (CISC) is consulting on proposed new rules to support the implementation of the Government’s recently assented Omnibus Cyber Security and Critical Infrastructure Package. Consultation closes on 14 February 2025.
24 January 2025
An omnibus cyber security and critical infrastructure package
The Government’s legislative package that implements a range of initiatives aimed at improving Australia’s cyber security consistent with its 2023-2030 Cyber Security Strategy has now been passed and is awaiting Royal Assent.
27 November 2024
An Omnibus Cyber Security and Infrastructure Package
The Government has released a legislative package that implements a range of initiatives aimed at improving Australia’s cyber security consistent with its 2023-2030 Cyber Security Strategy.
14 October 2024
When innovation meets regulation: The KWM Digital Future Summit 2024
Trust, safety, security and the regulators’ rise were central to messages shared across the 11 sessions at the KWM Digital Future Summit 2024, which culminated in a focus on the technology and innovation that is at the heart of our energy transition.
03 September 2024
First CIRMP annual reports under the SOCI Act - due soon
Responsible entities who are subject to the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules) are required to submit their first annual report within 90 days of the end of the financial year (by 28 September 2024). Responsible entities should now be taking steps to prepare the annual report to ensure it is ready to submit by the deadline.
10 July 2024
ASX guidance on disclosure in a cyber breach: Sensible guidance but there’s more to think about
ASX updated Guidance Note 8 to include a new example addressing a cyber incident.
27 June 2024
ASX provides welcome cyber breach disclosure guidance – update to Guidance Note 8
Following recent high profile cyber breaches, ASX has included a new data breach worked example in its updated Guidance Note 8 (effective 27 May 2024).
20 May 2024
SOCI roadmap – where are we at now, and what’s coming up next?
Responsible entities of critical infrastructure assets who are subject to the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (Rules) must comply with a designated cyber security framework (or an equivalent framework) by 18 August 2024.
15 March 2024
Strengthening Australia’s critical infrastructure against cyber risks: Consultation on legislative reforms close 1 March 2024
The Security of Critical Infrastructure Act (SOCI Act) is again being expanded, this time as part of the Australian Government’s 2023-2030 Cyber Security Strategy.
21 February 2024
Securing Australia’s digital future: unpacking the 2023-30 Cyber Security Strategy
The Government’s 2023-2030 Cyber Security Strategy aims to make Australia the most cyber secure nation and a global leader in cyber security by 2030
05 December 2023
Lessons for organisations and boards in the wake of ASIC’s November 2023 cyber pulse survey
Regulated organisations have been warned to address significant gaps in their cyber security and resilience following ASIC’s latest cyber pulse survey.
29 November 2023
Lessons from where you don’t want to be: Analysing the OAIC’s latest report on notifiable data breaches
The OAIC’s latest report on the Privacy Act’s notifiable data breach scheme reveals a declining number of notifications.
06 September 2023
APRA has finalised CPS 230: The clock is ticking for regulated entities to comply with new requirements
On 17 July 2023, the Australian Prudential Regulation Authority (APRA) released the long awaited final Prudential Standard CPS 230 Operational Risk Management (CPS 230) following extensive industry consultation. CPS 230 will replace the current APRA Prudential Standards for Outsourcing (CPS 231 / SPS 231 / HPS 231) and Business Continuity Planning (CPS 232 / SPS 232) so that CPS 230 will become the core standard for APRA-regulated entities when outsourcing services and managing other operational risk (including business continuity).
03 August 2023
UK Supreme Court weighs in on APP scams
The UK Supreme Court in a landmark judgment (Philipp v Barclays Bank UK Plc [2023] UKSC 25) has unanimously held that a bank does not have a common law duty to customers to refrain from acting on their instructions where the bank believes the customer is the victim of an authorised push payment scam.
14 July 2023
APRA finds gaps in compliance with CPS 234
The Australian Prudential Regulation Authority (APRA)’s initial round of tripartite cyber assessments of regulated entities against prudential standard CPS 234 (CPS 234) has revealed significant control gaps in relation to their compliance with the requirements of CPS 234.
12 July 2023
Australian Government releases new Data and Digital Government Strategy
The Minister for Finance, Senator the Hon Katy Gallagher, recently launched for consultation a draft Data and Digital Government Strategy: The data and digital vision for a world-leading APS to 2030 (Draft Strategy). You’re invited to make comments on the Draft Strategy by 25 July 2023.
07 July 2023
Hong Kong’s new financial crime tool
Fraud is one of the thorniest problems for banks and their customers globally, with billions of dollars of leakage to opportunists, criminal syndicates and thieves. The Hong Kong Monetary Authority (HKMA) has recently announced Hong Kong’s newest institutional financial crime tool – FINEST. The initiative was launched in collaboration with the Hong Kong Police Force (HKPF) and The Hong Kong Association of Banks (HKAB). King & Wood Mallesons was delighted to serve as legal advisor on the project. This alert summarises the key points to know.
30 June 2023
Lifting our gaze: an update on the Australian space industry and satellite cyber security
The Australian space industry has cause for excitement after a joint statement issued by the Prime Minister of Australia and the President of the United States on 20 May 2023.
26 May 2023
KWM privacy bytes – Privacy Act Review Report individual rights
Released in February this year, the Government’s long-awaited Privacy Act Review Report (Report) contains 116 proposals for privacy reform. In this, our second article in the Privacy Bytes series, we take a closer look at the new individual rights the Report proposes to include or expand in the Privacy Act.
09 May 2023
International comparison of Cyber Security regulatory settings: KWM report commissioned by AICD
The increasing regularity of high-profile cyber incidents is a constant and costly reminder that effective cyber resilience is fundamental to realising the promised benefits of digitisation. Australia is among many countries seeking to reboot its cyber defences.
08 May 2023
International comparison of Cyber Security regulatory settings - Summary
The increasing regularity of high-profile cyber incidents is a constant and costly reminder that effective cyber resilience is fundamental to realising the promised benefits of digitisation. Australia is among many countries seeking to reboot its cyber defences.
08 May 2023
Walking a tightrope: Continuous disclosure, data breaches and cyber security
Consider this. You’re a director of a publicly listed company, rushing to join your fellow board-members for a swiftly convened in-person meeting. Online wasn’t an option as the company has been hacked.
30 March 2023
The risk management program rules under the SOCI Act have now come into force
The Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules) have now been made and came into force with effect from 17 February 2023.
20 February 2023









