AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis
where a cybersecurity incident relates to a declared national emergency, or elsewhere there is a material risk that a cybersecurity incident has, is, or will likely seriously prejudice the Australia’s social or economic stability, defence, or national security. These include the heavily circumscribed Ministerial power to request an authorised agency to intervene in relation to com - puter-related activities where an entity is unwilling or unable to respond to an incident. Additionally, the Cyber Incident Review Board (CIRB) has been established as an independent statutory advisory body responsible for conducting no-fault, post-incident reviews of significant cybersecurity inci - dents in Australia. The CIRB post review report will contain recommendations to government and indus - try about actions to prevent, detect, respond to, or minimise the impact of future cybersecurity incidents of a similar nature. In pursuit of national cohesion, the state authorities adopt the following approaches. • The ACSC facilitates information and collabora - tion across private, public, and NGO sectors to develop collective cyber-resilience and to respond to cyber-incidents. In this regard, the ACSC has commenced: a partnership programme, involving private, public, and NGO sectors to enable infor - mation sharing and network hardening; and an alert service which provides information on recent cyberthreats as well as prevention and mitigation advice. • The Joint Cyber Security Centres (JCSC) are state- based agencies which collaborate with organisa - tions across the private, public, and NGO sectors on cybersecurity and cybercrime threats and response options. 3. Operational Resilience in the Financial Sector 3.1 Scope of Financial Sector Operational Resilience Regulation Even for the financial sector, there is a patchwork of legislation covering the financial sector’s operational resilience, leading to variations in scope. This legisla -
tion includes the SOCI Act, the Corporations Act, the Banking Ac 1959 (Cth), and the Insurance Act 1973 (Cth). Corporations Act As a starting point, the Corporations Act imposes a duty to exercise “care and diligence” on all direc - tors and officers of corporations (Section 180), which inherently involves considerations relating to cyber - security resilience. But more specifically, the Corpo - rations Act requires corporations holding financial licences to have adequate risk management systems (Section 912A). CPS 234 On top of this, APRA’s CPS 234 regulates informa - tion security standards for APRA-regulated financial, insurance, and superannuation entities. Other Legislation (SOCI Act and Cyber Security Act) Additionally, other legislation and regulation applica - ble to sectors beyond the financial is equally relevant here. These include the SOCI Act, since the financial services and markets sector does fall within its scope, so as to include certain banking assets, superannua - tion assets, insurance assets, and financial market infrastructure assets (see 2. Critical Infrastructure Cybersecurity Regulation ). Each of these are, in turn, defined and cover a range of assets owned or oper - ated by entities with certain Australian market licen - sees, CS facility licensees, benchmark administrators, and more, but most with the underlying condition that the asset is “critical to the security and reliability of the financial services and markets sector”. Those that fall outside the scope of the SOCI Act may fall within the scope of the Cyber Security Act, which imposes reporting obligations on “reporting business entities”. See 2. Critical Infrastructure Cybersecurity Regulation . 3.2 ICT Service Provider Contractual Requirements Information and communications technology (ICT) service providers are not expressly defined in Austral - ia. However, legislation does address “data process - ing or storage” assets and providers. Such an asset
18 CHAMBERS.COM
Powered by FlippingBook