Cybersecurity 2026

AUSTRALIA Trends and Developments Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

These latest sanctions make it a criminal offence to provide assets to ZServers or the five sanctioned indi - viduals, or to use or deal with their assets, with pen - alties of up to ten years’ imprisonment and/or heavy fines. These sanctions also ban the individuals from entering Australia. State-sponsored attacks Regulators continue to be concerned about state- sponsored attacks, with the ASD releasing joint cyber - security advisories concerning: • on 22 May 2025, a Russian state-sponsored cyber - campaign from the Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (85th GTsSS), military unit 26165 (and tracked under other names) targeting Western logistics entities and technology companies; and • on 28 August 2025, a People’s Republic of China state-sponsored cyberthreat actors, referred to by Australian authorities as a more generic name: “Advanced Persistent Threat (APT) actors”. These advisories were co-sealed by a variety of authorities and countries, illustrating the co-ordinated and multijurisdictional approach being taken by law enforcement authorities. In an effort to proactively build priority capabilities to defend against state- sponsored cyber-actors targeting Australia’s critical infrastructure, the ASD’s ACSC has released “CI For - tify” – a new series of guidance for critical infrastruc - ture providers. State-sponsored cyber-operations are set only to increase with growing geopolitical tensions. Addi - tionally, as sanctions expand globally, the sanctioned states will likely continue to turn towards co-opting actors and engage in state-sponsored hacking to sup - plement revenue streams. On the Horizon As Australia enters Horizon 2, the Australian govern - ment has taken significant leaps in 2023 to 2025, with its eyes glued on becoming the “frontier” in cyberse - curity. However, as in 2024, it continues to play catch up with technology, other countries, and now, its own strategy.

Some key dates to keep an eye on include the fol - lowing. • From 4 March 2026, the Cyber Security (Security Standards for Smart Device) Rules 2025 (Cth) will commence, following a 12-month transition period by which entities should adopt the mandatory cybersecurity standards for most smart devices acquired in Australia by a consumer. These stand - ards prohibit universal default passwords and require manufactures to publish both a means to report security issues and information about how long the device will be supported for. • From 10 December 2026, there are additional obli - gations under the Privacy Act relating to automated decision making, and regulated entities must ensure their privacy policies are properly up to date to reflect this change. Importantly, businesses should keep an eye on the regulators as they move into a more adversarial, enforcement approach, particularly the Privacy Com - missioner and ASIC. This action will shed light on how the legislative and regulatory frameworks are to be practically implemented, and the costs for not doing so. As 2026 begins, several components of the 2024 reforms are still to be implemented and their impact is yet to be assessed. Similarly, the implications of “Horizon 2” for Australian agencies and the wider community remains unclear. Until such steps are clari - fied, whether 2026 will be a year of consolidating what Australia already has or a year of further developments and change, will remain uncertain.

31 CHAMBERS.COM

Powered by