Cybersecurity 2026

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Nyman Gibson Miralis Level 9, 299 Elizabeth Street Sydney NSW 2000 Australia

Tel: +61 292 648 884 Email: dm@ngm.com Web: www.ngm.com.au

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy On 22 November 2023 the Australian government released the 2023–2030 Australian Cyber Security Strategy (the “Strategy”), with the aim of strengthen - ing Australia’s cyberdefences and supporting people and businesses to be resilient to and recover quickly from cyber-attacks. Alongside the Strategy was the 2023–2030 Austral - ian Cyber Security Strategy: Action Plan (the “Action Plan”) setting out three “Horizons”, which culminate in Horizon 3 with Australia as a leader of the global frontier in developing cybertechnologies and adapting to risk and opportunities. Last year marked the end of Horizon 1 (“Strengthen our foundations”), which aimed to address critical gaps, build protections, and support an initial uplift in cybermaturity. Between July and August 2025, the government conducted a public consultation concerning Horizon 2 (“Expand our search”). The government has moved into industry co-design on specific actions and initiatives; however, no substan - tive announcements have yet been made. Originally, Horizon 2 was intended to involve scaling Australia’s “maturity across the whole economy” through invest - ments in the broader cyber-ecosystem and workforce. The government has grounded its vision in six “shields” or “layers of defence” comprising the businesses and citizens, safe technology, world-class threat sharing and blocking, protected critical infrastructure, sover - eign capabilities, and resilient region and global lead -

ership. It has set out in its Action Plan different actions and objectives for each shield. While the co-design process of Horizon 2 and any amendments to the Strategy and the Action Plan are still being contemplated, it is expected that changes to Australia’s overall strategy will be announced in the next 12 months. 1.2 Cybersecurity Laws Australia has a broad system of federal, state, and territory-based laws which govern data protection, cybersecurity, and cybercrime. Data Protection Entities dealing with personal information in Australia should also be aware of their obligations with respect to: • the Privacy Act 1988 (Cth) (the “Privacy Act”), which regulates the handling of personal informa - tion by “APPs entities” pursuant to the Australian Privacy Principles (APPs). • the Digital ID Act 2024 (Cth) (the “Digital ID Act”), which is intended to embed safeguards for digital ID services and data in addition to the Privacy Act; • privacy legislation enacted at the state and territory level; • the My Health Records Act 2012 (Cth) (the “My Health Records Act”), which imposes specific obli - gations for health information collected and stored in Australia’s national online health database (in addition to the Privacy Act); • state and territory health records legislation enact - ed in New South Wales, Victoria, and the Australian Capital Territory; and

10 CHAMBERS.COM

Powered by