Cybersecurity 2026

AUSTRALIA Trends and Developments Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

actions could be at the expense of societal innovation, legitimate business, and, most concerningly, criminal law principles, including its focus on criminal intent. Practical Advice The firm’s experience aligns with the above data, with both individuals and businesses coming to Nyman Gibson Miralis for compliance and security advice, but also in the aftermath of money loss, information exposure, or both. Some general advice to proactively combat common cyber-risks include the following. • For individuals, always verify the phone number of any service provider and call them to confirm bank payment details. This includes law firms, real estate agents for property rentals, or conveyancing. • For businesses, the above advice is echoed, along with a recommendation for key personnel (if not all staff) to undertake regular Cybersecurity Tabletop Exercises throughout the year to practice cyber - security protocol and build muscle memory. While there are paid options, a good starting point would be the ASD’s Exercise in a Box, which offers 15 scenarios lasting 15 to 30 minutes each. In the aftermath of a cybersecurity event, it is criti - cal that individuals and businesses engage a law firm as soon as possible. For individuals, this is to ensure they know their rights in terms of law enforcement, banks, and other protections. While for businesses, the legal and risk landscape is even more complex and includes reporting obligations, internal investiga - tions, listing announcements, corporate duties, and more. Hiring legal experts is therefore key. Legislative and Regulatory Reform Cyber Security Act In 2024, the Australian government passed an Aus - tralian first: the Cyber Security Act 2024, a statute specifically aimed at cybersecurity. This Act included: • two new roles: (a) the National Cyber Security Co-ordinator (NCS Co-ordinator) responsible for co-ordinating whole-of-government action in response to sig -

nificant cybersecurity incidents, policies, and capabilities; and (b) the Cyber Incident Review Board (CIRB), an independent advisory body that will undertake reviews of certain cybersecurity incidents on a no-fault basis; and • mandatory ransomware payment reporting obliga - tions. New roles The full impact of the two new roles is still to be seen. The first NCS Co-ordinator, Lieutenant General Michelle McGuinness CSC, has operated mainly in the background, with the only publicised event being the cybersecurity incident against MediSecure. Meanwhile, the Minister of Home Affairs has still to appoint members to the CIRB or the Expert Panel that is to advise the Board. Accordingly, the continued absence of this independent advisory body means that Australia still lacks the no-fault, post-incident reviews of significant cybersecurity incidents in Aus - tralia. In turn, this leads to an increase in regulators undertaking educational and co-operative regulatory approaches, despite their outward pivots to monitor - ing and enforcement approaches. Mandatory ransomware reporting obligations On 30 May 2025, the mandatory ransomware report - ing obligations under Part 3 of the Cyber Security Act 2024 (Cth) commenced with the release of the outstanding details under the Cyber Security (Ran - somware Payment Reporting) Rules 2025. Per these new rules, businesses with annual turnovers of AUD3 million or more and entities responsible for critical infrastructure must report a cybersecurity incident within 72 hours of making the payment (or becoming aware of a ransomware being made). How this new information is used to inform key regulators and their approaches in this space remains to be seen. The broader framework remains the same. The Act implements “limited use” obligations on the bodies who receive the information (primarily or secondarily). In doing so, the Act excludes the use of the informa - tion for investigations or enforcement action, unless it is a contravention of the reporting obligations them -

28 CHAMBERS.COM

Powered by