KWM TOPICS >

Cybersecurity and critical infrastructure

|
Current site :      |  

It's not just cyber security, it's cyber resilience and cyber regulation

As many have realised, it’s not a question of ‘if’ but ‘when’ a cyber security breach happens. The scale, speed and impact of cyber security breaches means that you need to be prepared to act on the assumption that a cyber security breach will occur, and to ensure that your organisation is resilient enough to recover from the breach. This requires planning and testing your business continuity and cyber breach plans to make sure that your organisation can continue to operate effectively even if there is a very significant incident that incapacitates your IT systems. ASIC has put Boards on notice that it expects them to ensure that their organisations pay sufficient attention and devote adequate resources to cyber security and cyber resilience.

And, if its not enough dealing with the impact of a cyber breach from a resilience perspective, you also have to deal with the regulatory implications of a cyber security incident. These range from ASX notifications under continuous disclosure obligations for listed entities, to notifications of regulators (the OAIC, the CISC and APRA) under a range of statutory notification obligations.

Our team has been advising clients involved in two of the most significant breaches in recent times on navigating through this maze of issues, as well as on the regulatory investigations, representative claims and class actions that have resulted from those breaches.

Our Cyber Security Insights

SOCI update: Exposure draft enhancements to CIRMP Rules and consultation on proposed amendments to Ministerial Directions Powers

As foreshadowed in our earlier insight here, the Department of Home Affairs (Department) has now released an exposure draft of proposed enhancements to the Security of Critical Infrastructure (Critical Infrastructure Risk Management Program) Rules 2023 (CIRMP Rules), and a separate consultation paper on proposed amendments to the Ministerial Directions Powers in Part 3 of the Security of Critical Infrastructure Act 2018 (SOCI Act).

09 April 2026

SOCI update: proposed enhancements to CIRMP Rules

At the end of 2025, the Department of Home Affairs (the Department) released a consultation paper for proposed enhancements to the Security of Critical Infrastructure (Critical Infrastructure Risk Management Program) Rules 2023 (CIRMP Rules) for certain asset classes (Consultation Paper).

30 January 2026

Updates to the Annual CIRMP Report webform

Responsible entities who are submitting their 2025 Critical Infrastructure Risk Management Program (CIRMP) report should be aware that the form was updated by the Critical Infrastructure Security Centre (CISC) in April this year.

24 July 2025

Consumer energy resources: Cyber security

Cybersecurity considerations are increasingly critical in the management of consumer energy resources.

09 July 2025

SOCI Act update: Key Cyber Security and Critical Infrastructure Rules have been registered

Following a period of consultation on rules to support the Government’s Omnibus Cyber Security and Critical Infrastructure package discussed here, 4 of the 6 proposed rules have now been registered.

13 March 2025

Cyber security - if you share an incident report with the government, can it come back to bite you?

Cyber security legislation enacted by the Australian Parliament in late 2024 sought to encourage full and frank disclosure to the government of information by organisations impacted by serious cyber security incidents.

07 February 2025

CISC is consulting on rules to be made under Omnibus Cyber Security and Critical Infrastructure Package

The Cyber and Infrastructure Security Centre (CISC) is consulting on proposed new rules to support the implementation of the Government’s recently assented Omnibus Cyber Security and Critical Infrastructure Package. Consultation closes on 14 February 2025.

24 January 2025

An omnibus cyber security and critical infrastructure package

The Government’s legislative package that implements a range of initiatives aimed at improving Australia’s cyber security consistent with its 2023-2030 Cyber Security Strategy has now been passed and is awaiting Royal Assent.

27 November 2024

An Omnibus Cyber Security and Infrastructure Package

The Government has released a legislative package that implements a range of initiatives aimed at improving Australia’s cyber security consistent with its 2023-2030 Cyber Security Strategy.

14 October 2024

When innovation meets regulation: The KWM Digital Future Summit 2024

Trust, safety, security and the regulators’ rise were central to messages shared across the 11 sessions at the KWM Digital Future Summit 2024, which culminated in a focus on the technology and innovation that is at the heart of our energy transition.

03 September 2024

First CIRMP annual reports under the SOCI Act - due soon

Responsible entities who are subject to the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules) are required to submit their first annual report within 90 days of the end of the financial year (by 28 September 2024). Responsible entities should now be taking steps to prepare the annual report to ensure it is ready to submit by the deadline.

10 July 2024

ASX guidance on disclosure in a cyber breach: Sensible guidance but there’s more to think about

ASX updated Guidance Note 8 to include a new example addressing a cyber incident.

27 June 2024

ASX provides welcome cyber breach disclosure guidance – update to Guidance Note 8

Following recent high profile cyber breaches, ASX has included a new data breach worked example in its updated Guidance Note 8 (effective 27 May 2024).

20 May 2024

SOCI roadmap – where are we at now, and what’s coming up next?

Responsible entities of critical infrastructure assets who are subject to the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (Rules) must comply with a designated cyber security framework (or an equivalent framework) by 18 August 2024.

15 March 2024

Strengthening Australia’s critical infrastructure against cyber risks: Consultation on legislative reforms close 1 March 2024

The Security of Critical Infrastructure Act (SOCI Act) is again being expanded, this time as part of the Australian Government’s 2023-2030 Cyber Security Strategy.

21 February 2024

Securing Australia’s digital future: unpacking the 2023-30 Cyber Security Strategy

The Government’s 2023-2030 Cyber Security Strategy aims to make Australia the most cyber secure nation and a global leader in cyber security by 2030

05 December 2023

Lessons for organisations and boards in the wake of ASIC’s November 2023 cyber pulse survey

Regulated organisations have been warned to address significant gaps in their cyber security and resilience following ASIC’s latest cyber pulse survey.

29 November 2023

Lessons from where you don’t want to be: Analysing the OAIC’s latest report on notifiable data breaches

The OAIC’s latest report on the Privacy Act’s notifiable data breach scheme reveals a declining number of notifications.

06 September 2023

APRA has finalised CPS 230: The clock is ticking for regulated entities to comply with new requirements

On 17 July 2023, the Australian Prudential Regulation Authority (APRA) released the long awaited final Prudential Standard CPS 230 Operational Risk Management (CPS 230) following extensive industry consultation. CPS 230 will replace the current APRA Prudential Standards for Outsourcing (CPS 231 / SPS 231 / HPS 231) and Business Continuity Planning (CPS 232 / SPS 232) so that CPS 230 will become the core standard for APRA-regulated entities when outsourcing services and managing other operational risk (including business continuity).

03 August 2023

UK Supreme Court weighs in on APP scams

The UK Supreme Court in a landmark judgment (Philipp v Barclays Bank UK Plc [2023] UKSC 25) has unanimously held that a bank does not have a common law duty to customers to refrain from acting on their instructions where the bank believes the customer is the victim of an authorised push payment scam.

14 July 2023

APRA finds gaps in compliance with CPS 234

The Australian Prudential Regulation Authority (APRA)’s initial round of tripartite cyber assessments of regulated entities against prudential standard CPS 234 (CPS 234) has revealed significant control gaps in relation to their compliance with the requirements of CPS 234.

12 July 2023

Australian Government releases new Data and Digital Government Strategy

The Minister for Finance, Senator the Hon Katy Gallagher, recently launched for consultation a draft Data and Digital Government Strategy: The data and digital vision for a world-leading APS to 2030 (Draft Strategy). You’re invited to make comments on the Draft Strategy by 25 July 2023.

07 July 2023

Hong Kong’s new financial crime tool

Fraud is one of the thorniest problems for banks and their customers globally, with billions of dollars of leakage to opportunists, criminal syndicates and thieves. The Hong Kong Monetary Authority (HKMA) has recently announced Hong Kong’s newest institutional financial crime tool – FINEST. The initiative was launched in collaboration with the Hong Kong Police Force (HKPF) and The Hong Kong Association of Banks (HKAB). King & Wood Mallesons was delighted to serve as legal advisor on the project. This alert summarises the key points to know.

30 June 2023

Lifting our gaze: an update on the Australian space industry and satellite cyber security

The Australian space industry has cause for excitement after a joint statement issued by the Prime Minister of Australia and the President of the United States on 20 May 2023.

26 May 2023

KWM privacy bytes – Privacy Act Review Report individual rights

Released in February this year, the Government’s long-awaited Privacy Act Review Report (Report) contains 116 proposals for privacy reform. In this, our second article in the Privacy Bytes series, we take a closer look at the new individual rights the Report proposes to include or expand in the Privacy Act.

09 May 2023

International comparison of Cyber Security regulatory settings: KWM report commissioned by AICD

The increasing regularity of high-profile cyber incidents is a constant and costly reminder that effective cyber resilience is fundamental to realising the promised benefits of digitisation. Australia is among many countries seeking to reboot its cyber defences.

08 May 2023

The risk management program rules under the SOCI Act have now come into force

The Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 (CIRMP Rules) have now been made and came into force with effect from 17 February 2023.

20 February 2023

ACSC Annual Threat Report

The Australian Cyber Security Centre (ACSC) has just released its Annual Cyber Threat Report covering the period July 2021 to July 2022 (Report). It will probably surprise nobody that along with the international security environment more broadly, the cyber threat landscape has deteriorated markedly over the review period.

08 November 2022

Privacy Act enforcement powers to be boosted

The Government has introduced legislation that will significantly increase maximum penalties under the Privacy Act.

26 October 2022

Data separation in M&A transactions

Data is increasingly being treated as a core business asset in M&A transactions. In this context, management of data is about deriving and preserving its value, and limiting reputational, regulatory and contractual risk.

24 October 2022

Consultation commences on critical infrastructure reforms

The Minister for Home Affairs has commenced consultation on the proposed risk management program (RMP) under the amended Security of Critical Infrastructure Act 2018 (SOCI Act). Consultation is open for 45 days from Wednesday 5 October 2022 until Friday 18 November 2022.

07 October 2022

Lloyd’s of London announces cyber-attack insurance exclusions for “state backed cyber-attack”

Lloyd’s of London has directed that commencing in March 2023, underwriters are to exclude losses arising from any “state backed cyber-attack” from all standalone cyber-attack policies.

05 October 2022

Privacy Annual Update 2022

With the ever-quickening pace of technological change, it is as vital a time as ever to look at the current state of privacy law and prepare for its next evolution.

04 October 2022

Beware - your computer crime policy may not give you the cyber coverage you may expect

The insured could not recover the costs of investigating and preventing a ransomware attack, replacement hardware costs or the costs or retrieving or reconstituting affected data because the cyber policy excluded ‘indirect and consequential loss’ and limited loss or damage to electronic data, media or information to the costs of replacement media and labour costs for transcription and copying.

30 August 2022

AUSTRAC and APRA crypto updates – sculpting the Australian regulatory landscape

Global crypto markets are no stranger to volatility. We have been here before. At the same time, with Australia’s first crypto ETFs launch, we are also seeing a significant uptick in Australian market entry for major international crypto players, as well as the continued expansion of home-grown service providers and developers. Banks are also entering the fray.

26 May 2022

Themes emerging from recent crypto attacks

We are barely finished with the first quarter of the calendar year and already we have seen multiple “hacks” in the crypto space that have resulted in the losses of over US$1 billion.

16 May 2022

An Australian first: Federal Court decision heralds new era of cybersecurity regulatory action

In a landmark judgment, the Federal Court has found that an Australian financial services licence (AFSL) holder contravened its general AFSL obligations under Corporations Act 2001 (Cth) (Act) by failing to have and to implement documentation and controls in respect of cybersecurity and cyber resilience that were adequate to manage risk.

12 May 2022

Government opens discussion on collective responsibility for data security

The Australian Government has released a discussion paper on data security for public comment, as part of the ongoing development of Australia’s National Data Security Action Plan (Action Plan).

22 April 2022

Cybersecurity notification and Registration obligations under the SOCI Act have now been switched on

The asset register reporting requirements and the cyber security incident notification obligations under the Security of Critical Infrastructure Act 2018 (Cth) have now been enlivened.

13 April 2022

The second package of reforms to the Security of Critical Infrastructure Legislation has been passed

The Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 (SLACIP Act) has been passed by the Senate and the House of Representatives.

01 April 2022

Parliament considers Ransomware plan legislation

New, stronger criminal offences applicable to cybercriminals proposed with extraterritorial application. Modernised powers to investigate and seize digital assets, including cryptocurrency, introduced.

25 February 2022

Of charlatans and poor choices: how restrictions on crypto assets are growing worldwide

Yet the ancient origin of the word goes to the essence of today’s regulatory tension: ‘crypto’ has its origin in the Greek word ‘kruptos’, meaning ‘hidden’. Governments and regulators around the world are working to bring crypto assets into view.

22 February 2022

Reform of Australia’s electronic surveillance framework

Written by Sean Field.

01 February 2022

International comparison of Cyber Security regulatory settings - Summary

The increasing regularity of high-profile cyber incidents is a constant and costly reminder that effective cyber resilience is fundamental to realising the promised benefits of digitisation. Australia is among many countries seeking to reboot its cyber defences.

Show More Show Less

Our Privacy Insights

OAIC consults on new Children’s Online Privacy Code

The OAIC has released a draft Children’s Online Privacy Code for public consultation.

09 April 2026

Proceed with caution! Privacy lessons from Bunnings & Privacy Commissioner

Bunnings’ use of facial recognition technology (FRT) to identify and deal with unlawful activity by repeat offenders was permitted under the Privacy Act 1998 (Cth) (Privacy Act) according to the Administrative Review Tribunal (Tribunal).

16 February 2026

Privacy Law Annual Update

Welcome to the 2025 edition of KWM’s annual privacy law update.

25 November 2025

Under the Hood – Connected Vehicles & Australia’s Privacy Commissioner

Australians have long embraced technological innovation, and nowhere is this more apparent than on our roads. Vehicles that once operated in splendid isolation are now sophisticated, data-generating computers on wheels

13 May 2025

Report of the Statutory Review of the Online Safety Act 2021 released

The Government has tabled a report on the review of the Online Safety Act 2021 (Online Safety Act or OSA).

10 February 2025

Privacy Annual Update 2024

Each year, we write this publication to recap the key developments in Australian privacy law over the past year.

11 December 2024

Social Media Minimum Age Bill Introduced

The Government has introduced the Online Safety Amendment (Social Media Minimum Age) Bill 2024 (Bill) into Parliament.

22 November 2024

Data Wars Part IV: Enforcement reforms in the Privacy Amendment Bill

The Australian Government is seeking to implement reforms to the Privacy Act 1988 (Cth) (Privacy Act).

21 November 2024

Data Wars Part III: Statutory tort, incoming!

With a substantially pared back Privacy and Other Legislation Amendment Bill 2024 (the Bill) before Parliament, only the statutory tort remains.

15 October 2024

Whose phone is it anyway? Navigating employee privacy and employer data in the age of BYOD

An ever-increasing proportion of business is conducted outside of the physical office and contracted hours – most commonly, on an employee’s mobile device, whether it is their personal device or employer-provided.

11 October 2024

Breaking down the Privacy Amendment Bill

The Government has (at last) introduced the first tranche of long-anticipated privacy reforms.

18 September 2024

Privacy Act Reforms – A Long Running Saga, Yet Still to be Continued …

A privacy reform Bill has been introduced to parliament. If enacted, the Bill will implement significant changes to the Privacy Act, including introducing broader enforcement powers for the Australian Information Commissioner, a statutory tort for serious invasions of privacy, greater transparency for individuals regarding use of personal information for automated decision-making, and additional protections for children’s privacy.

12 September 2024

Australia’s privacy reforms are about to arrive! Five significant things to keep an eye out for

With draft legislation for implementation of reforms to Australian privacy laws likely to be introduced this month, we’ve taken a look at some of the more impactful changes likely to be flagged and what that might mean for your organisation.

05 September 2024

When innovation meets regulation: The KWM Digital Future Summit 2024

Trust, safety, security and the regulators’ rise were central to messages shared across the 11 sessions at the KWM Digital Future Summit 2024, which culminated in a focus on the technology and innovation that is at the heart of our energy transition.

03 September 2024

Data Wars Part II: A direct right of action

In our previous Insight, we explored the proposed statutory tort for serious invasions of privacy detailed in the Attorney-General’s Department’s Privacy Act Review Report (Report) in February 2023. Draft legislation is expected in coming months.

29 August 2024

Risk of GenAI - Probing the privacy pitfalls

The Australian public is nervous about AI and has low trust that companies using AI will protect their personal data.

01 August 2024

Data Wars - Part I: Tortious invasions of privacy

The Australian Government has confirmed its commitment to introduce a new direct right of action for breaches of the Privacy Act 1988 (Cth) (the Act) or the Australian Privacy Principles (APPs), and a statutory tort for serious invasions of privacy.

12 July 2024

Consumer Energy Resources: data and privacy

Welcome back to our 5-part series exploring the emerging opportunities and challenges associated with the uptake of CER in Australia from a tech law perspective, with a focus on privacy and data, AI and automation, cyber security and contracting to enable the transition to CER.

20 June 2024

Representative complaints under the Australian Privacy Act – recent developments

Data breach litigation in Australia is a relatively new occurrence. The courts have recently decided that a multiplicity of court cases and administrative investigations into the same incident may run in parallel.

20 March 2024

Australian privacy regulator sues in data breach case

On 3 November 2023, the Australian Information Commissioner filed proceedings in the Federal Court of Australia against Australian Clinical Labs Limited seeking a civil penalty (fine) in connection with the company’s response to a data breach that occurred in February 2022.

13 November 2023

Inching forwards: Government responds to Privacy Act Review Report

TL;DR The Government has today released its long-awaited response to the proposals made in the Attorney General’s Privacy Act Review Report.

28 September 2023

Have your say on the regulation of Artificial Intelligence in Australia: Recent Developments

Artificial Intelligence (AI) is increasingly becoming a focal point for lawmakers and regulators around the world. Like many nascent technologies, AI has the potential for both harmful as well as positive outcomes, with algorithmic biases and the generation of misleading or erroneous outputs of particular concern. Consequently, safety and the effective management of AI risk has been at the forefront of the minds of Australian regulators. While some overseas jurisdictions are already further down the path towards AI regulation, there have been three recent significant developments in

26 June 2023

Europe’s AI regulation gets real : what to know (and do) about the EU AI Act as it nears finalisation

More than two years ago, the European Union (EU) released the first draft of the Artificial Intelligence Act (AI Act). This was the first significant attempt at regulating AI on a large scale. In June, it passed a major milestone bringing it closer to finalisation. There is some way to go, but the signs are clear. Our experts share what the AI Act means for companies worldwide – and why now is the time to start thinking about risk mitigation steps.

26 June 2023

KWM privacy bytes – Privacy Act Review Report individual rights

Released in February this year, the Government’s long-awaited Privacy Act Review Report (Report) contains 116 proposals for privacy reform. In this, our second article in the Privacy Bytes series, we take a closer look at the new individual rights the Report proposes to include or expand in the Privacy Act.

09 May 2023

Developments in the regulation of Artificial Intelligence

Artificial intelligence (AI) has captured the attention of the world over the last 12 months. From AI chatbots to AI-generated art and inventions, AI has the potential to radically transform our economy, our society, and humanity.

19 April 2023

KWM Privacy Bytes - Privacy Act Review Report: Collecting and using of personal information

The Government’s long-awaited Privacy Act Review Report contains 116 proposals for reform. While not fundamentally changing the current principles based approach, these proposals will require a step change in how Australian companies collect and use personal information.

30 March 2023

Privacy Act Review Report (Finally) Released

The Government has released a long-awaited report setting out its privacy reform agenda. This landmark report proposes many significant changes.

17 February 2023

Privacy Act enforcement powers to be boosted

The Government has introduced legislation that will significantly increase maximum penalties under the Privacy Act.

26 October 2022

Data separation in M&A transactions

Data is increasingly being treated as a core business asset in M&A transactions. In this context, management of data is about deriving and preserving its value, and limiting reputational, regulatory and contractual risk.

24 October 2022

Privacy Annual Update 2022

With the ever-quickening pace of technological change, it is as vital a time as ever to look at the current state of privacy law and prepare for its next evolution.

04 October 2022

Data Availability and Transparency Act passes Parliament, paving the way for greater sharing and use of public sector data

First introduced in December 2020, these Acts will significantly change the way that public sector data can be collected, shared and used.

05 April 2022

Reform of Australia’s electronic surveillance framework

Written by Sean Field.

01 February 2022

Show More Show Less