AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation Australia’s critical infrastructure and assets are regu - lated through Commonwealth, state, and territory legislation, with a particular emphasis on the SOCI Act. That said, there is broader legislation, such as the Privacy Act and Cyber Security Act, and more sector- specific legislation, such as the Telecommunications Act, that cannot be ignored. The SOCI Act currently regulates certain assets across eleven sectors: communications, data stor - age and processing, financial services, energy, food and grocery, health and medical, higher education and research, space technology, transport, water and sewerage, and the defence industry. In Novem - ber 2025, telecommunications security obligations (which were previously under the Telecommunication Sector Security Reforms (TSSR)) were moved into the SOCI, a change implemented by the Security of Criti - cal Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (Cth) (the “2024 SOCI Amendment Act”). Notwithstanding recent reforms which clarified the SOCI Act, the exact parameters of the legislation are broad and complex, and extend to various partici - pants in a supply chain including “responsible enti - ties”, “reporting entities”, “direct interest holders”, “managed service providers”, and “operators”. Some of these definitions are asset-specific, but for our purposes, it is important to note that a “responsible entity” is generally the entity that owns, is licensed, or otherwise responsible for operating the asset. Further, despite the imminent shift of the TSSR and its obligations to the SOCI Act, these obligations still remain in force and apply to the relevant infrastructure as is. The TSSR are applicable to carriers, carriage service providers, and carriage service intermediaries. Cyber Security Act Additionally, there are cybersecurity obligations imposed on critical infrastructure under the Cyber
Security Act where they constitute “a reporting busi - ness entity”. A “reporting business entity” is an entity that: • is carrying on a business in Australia with an annual turnover for the previous financial year that exceeds the “turnover threshold for that year” (to be determined) but is not a Commonwealth body, State body, or responsible entity for a critical infra - structure asset; or • a responsible entity for a critical infrastructure asset “to which Part 2B of the Security of Criti - cal Infrastructure Act 2018 applies” – specifically, these entities are listed in Security of Critical Infra - structure (Application) Rules (LIN 22/026) 2022 and include most infrastructure assets. 2.2 Critical Infrastructure Cybersecurity Requirements The SOCI Act imposes requirements on owners and operators of assets across various fields. The exact requirements vary depending on the particular asset/ industry; however, it may include a requirement to: • register with the Register of Critical Infrastructure Assets; • provide ownership and operational information; • notify the government of certain cyber-incidents; • implement and comply with a critical infrastructure risk management programme (CIRMP); and • if they have “business critical data” processed or stored by a third party on a commercial basis, they must take reasonable steps to notify that third party. Further still, the SOCI Act and associated rules impose enhanced cybersecurity obligations on assets desig - nated as “systems of national significance” (SoNS). These must be assets that are already considered a “critical infrastructure asset”, but also that they are of “national significance”. These designations are private and confidential so as to avoid publicising their signifi - cance to malicious actors. Reports indicate that over 200 systems have been designated to date. A responsible entity for a SoNS may be required to:
15 CHAMBERS.COM
Powered by FlippingBook