Cybersecurity 2026

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

may be considered itself a critical infrastructure asset, separate to other critical infrastructure, and therefore fall within the scope of the SOCI Act. Specifically, an entity that owns or operates a “data storage or processing asset” will be considered a responsible entity under the SOCI Act and their asset “critical” if: • the entity wholly or primarily provides data stor - age or processing services that relate to “business critical data”, being “personal information” (per the Privacy Act – see 6.1 Cybersecurity and Data Pro- tection ) relating to at least 20,000 individuals, or otherwise information relating to any research and development, needed to operate, systems needed to operate, or risk management and business con - tinuity in relation to a critical infrastructure asset; • these services are provided to certain end‑users, primarily either: (a) the Commonwealth, a State, a Territory, or a body corporate established under such a Com - monwealth, State, or Territory law; or (b) the responsible entity for a critical infrastruc - ture asset; • the entity knows that the asset is used by the above end-user; and • the asset does not constitute another critical infra - structure asset. Further, the 2024 SOCI Amendment Act clarified the SOCI Act so that it included secondary assets who hold business critical data relating to the primary asset. Notably, the intent behind these amendments is not to capture all non-operational systems holding business critical data; rather only those where vulnerabilities could significantly impact critical infrastructure assets. Examples of relevant operational data included network blueprints, encryption keys, algorithms, operational system code, and tactics, techniques and procedures. The regulations may specifically exclude other such assets. See 2. Critical Infrastructure Cybersecurity Regulation for their obligations and responsibilities. 3.3 Key Operational Resilience Obligations There is no specific legislation for “digital operational resilience” for the financial sector as seen in the Euro -

pean jurisdictions; however, the objectives of enabling the financial sector to be or remain resilient in the face of serious operational disruption and prevent/mitigate cyberthreats are reflected in the patchwork of legisla - tion. The SOCI Act Specifically looking at the obligations under the SOCI Act for the financial sector, although financial busi - ness using or constituting critical infrastructure assets have the same incident reporting obligations already covered (see 2.3 Incident Response and Notification Obligations ), such services do not have the obliga - tions to register as critical assets and to have a CIRMP under the SOCI Act (except where they are “payment services”). As an aside, a financial service can be clas - sified as a SoNS under the SOCI Act, attracting the enhanced cybersecurity obligations. The Corporations Act Notwithstanding the position under the SOCI Act, financial services are likely already required to be reg - istered with APRA and/or obtain a form of financial service licensing; and in doing the latter, must, inter alia, provide their services “efficiently and fairly” and have an adequate risk management program. Aus - tralian courts have already confirmed that such a risk management plan must ensure adequate cyberse - curity and cyber-resilience measures are adequately implemented across its business. CPS 234 APRA’s CPS 234 requires APRA-regulated financial, insurance, and superannuation entities to comply with legally binding minimum standards of informa - tion security, including by: • specifying information security roles and responsi - bilities for the entities’ board, senior management, governing bodies, and individuals; • implementing and maintaining appropriate informa - tion security capabilities; • maintaining tools to detect and respond to infor - mation security incidents in a timely way; and • notifying APRA of any material information security incidents.

19 CHAMBERS.COM

Powered by