Cybersecurity 2026

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

ing sharing) of CDR. The CDR was rolled out to the banking and energy sectors in 2020 and 2022 respec - tively. In 2023, the government paused the roll-out the superannuation, insurance, and telecommunications sectors (and then non-bank lenders and Buy Now Pay Later products) and remains in hiatus since an August 2024 report found compliance costs exceeded initial estimates. Enforcement continues with the Common - wealth Bank of Australia (CBA) receiving four infringe - ment notices totalling AUD792,000 from the ACCC under the CDR scheme. CBA had failed to enable data sharing on accounts with a Trading Entity Business Name (TEBN) customer profile. However, the Consumer Affairs Ministers across Aus - tralia recently renewed their commitment to a strong national consumer protection framework, including progressing nation-wide reforms to protect consum - ers from unfair trading practices. To many, including the Consumer Policy Research Centre, this suggests addressing questionable transfer and use of consum - er data through subscriptions, digital design tactics or “dark patterns”, and other deceptive practices. What impact this has on data transfers remains to be seen. Prohibitions Certain information is prohibited from being held or taken outside Australia, such as records held for the purposes of the My Health Record system. Breaching this prohibition could result in a maximum criminal penalty of five years imprisonment and AUD99,000; or a civil penalty of AUD495,000. Cybercrime For completeness, it should also be noted that unau - thorised access to computer systems (hacking, force - able transfers, etc) is criminalised by both State and Federal legislation. For example, persons suspected of unauthorised access to computer systems are charged pursuant to Section 478.1 of the Criminal Code, which provides for the offence of “Unauthorised access to, or modification of, restricted data”. These offences have extraterritorial application, mean - ing that conduct undertaken outside Australia can still be charged and prosecuted under Australian law if:

• the crime involves conduct both inside and outside Australia; • the crime results in harm within Australia; • the offender is an Australian citizen, or a corpora - tion incorporated in Australia; or • the crime is related to another crime that occurred in Australia. Digital ID The Digital ID Act and the Digital ID (Transitional and Consequential Provisions) Act 2024 (Cth) restrict an accredited entity on the collection, use, and disclo - sure of biometrics and other personal information. Although the Digital ID Rules can address the stor - ing and transfer of information outside Australia and were expected to take the form of blanket prohibi - tions (with minimal exemptions), no such rules have yet been introduced. 3.6 Threat-Led Penetration Testing Threat-led penetration testing (TLPT) is the testing of systems by replicating the methods used by actual threat actors against. Generally speaking, TLPT is not a requirement in Australia. Currently, only those critical infrastructure assets des - ignated as a SoNS may be required to undertake: • a “cyber security exercise”, the purpose of which is to test the entity’s ability to respond appropriate - ness, preparedness to respond appropriately, and ability to mitigate the relevant impacts, and there - after prepare an internal report which can in turn be audited; and • a vulnerability assessment, the purpose of which is to test system vulnerabilities to the relevant cyber - security incident and thereafter prepare a vulner - ability assessment report. TLPT is also a component of regulatory guidance (eg, ASD’s best practices for deploying secure and resil - ient AI systems). On the flipside, unsolicited/unauthorised penetration testing activity could be captured by Section 478.1 of the Criminal Code, which provides for the offence of “[un]authorised access to, or modification of, restrict - ed data”.

21 CHAMBERS.COM

Powered by