Cybersecurity 2026

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Act to investigate and resolve complaints and enforce compliance. In dealing with non-compliance, ACMA is empowered to issue warnings, infringement notices, enforceable undertakings, and remedial directions. ACMA is fur - ther able to cancel or impose conditions on licences and accreditations. ACMA also has the ability to com - mence civil proceedings or refer matters for criminal prosecution. Additionally, the Office of the eSafety Commissioner (the “eSafety Commissioner”) has powers to promote and regulate online safety with respect to telecommu - nications, broadcasting, and other online industries. However, the eSafety Commissioner cannot inves - tigate matters of cybercrime. Penalties range from takedown notices and blocking directions to infringe - ment notices and injunction proceedings. Corporations, Consumers and Financial Services Cybersecurity ASIC is Australia’s corporate, market, and financial services regulator. It regulates publicly-listed corpora - tions under the Corporations Act and is empowered to investigate and take action against corporations, directors, and officers for non-compliance with the Corporations Act, including cybersecurity issues. APRA regulates certain finance, banking, insurance, and superannuation entities and issues regulatory guidance (eg, information security standards CPS 234). APRA has powers to supervise, monitor, and intervene in matters of cybersecurity for regulated entities and has a range of enforcement powers to deal with breaches of its standards. Such powers involve APRA issuing infringement notices, provid - ing directions or enforceable undertakings, imposing licensing conditions, disqualifying senior officials, and commencing court-based action. The ACCC is Australia’s competition regulator and consumer protector, and may, where appropriate, undertake enforcement action against breaches of the Consumer Act, including breaches involving cyberse - curity, cybercrime, and cyberscam issues. The ACCC additionally:

• administers the Consumer Data Right (CDR) regime; • co-regulates (with OAIC) the Digital ID Act; and • hosts the Scamwatch website, which provides public information, alerts, and access to com - plaints mechanisms on a wide range of consumer scams, including scams perpetrated online. Also relevant for the financial sector is that OAIC regu - lates the aspects of the Privacy Act which deal with credit reporting obligations and the credit reporting code, which imposes certain conditions on entities that hold credit-related personal information. Cybercrime Cybercrime at the federal level is investigated and enforced by the AFP and prosecuted by the CDPP. The AFP have a dedicated Cybercrime Operations team comprising investigators, technical specialists, and intelligence analysts who operate across multiple jurisdictions to conduct cyber-assessments and to tri - age, investigate, and disrupt cybercrime. More specifically: • ACIC is Australia’s national criminal intelligence agency; it has broad investigative and coercive powers and shares information between all levels of law enforcement; • AUSTRAC is the domestic watchdog for Australia’s anti-money laundering and counter-terrorism measures; it supports law enforcement operations involving cybercrime financing; and • ASIO investigates cyber-activity involving espio - nage, sabotage, and terrorism related activities; ASIO also contributes to the investigation of com - puter network operations directed against Aus - tralia’s systems. State and territory-based police and prosecution agencies investigate, enforce and prosecute state and territory cybercrimes.

14 CHAMBERS.COM

Powered by