Cybersecurity 2026

Definitive global law guides offering comparative analysis from top-ranked lawyers

CHAMBERS GLOBAL PRACTICE GUIDES

Cybersecurity 2026 Definitive global law guides offering comparative analysis from top-ranked lawyers

Contributing Editor Christian Schröder Orrick

Global Practice Guides

Cybersecurity Contributing Editor Christian Schröder Orrick, Herrington & Sutcliffe LLP

2026

Chambers Global Practice Guides For more than 20 years, Chambers Global Guides have ranked lawyers and law firms across the world. Chambers now offer clients a new series of Global Practice Guides, which contain practical guidance on doing legal business in key jurisdictions. We use our knowledge of the world’s best lawyers to select leading law firms in each jurisdiction to write the ‘Law & Practice’ sections. In addition, the ‘Trends & Developments’ sections analyse trends and developments in local legal markets. Disclaimer: The information in this guide is provided for general reference only, not as specific legal advice. Views expressed by the authors are not necessarily the views of the law firms in which they practise. For specific legal advice, a lawyer should be consulted. Content Management Director Claire Oxborrow Content Manager Jonathan Mendelowitz Senior Content Reviewers Sally McGonigal, Ethne Withers, Deborah Sinclair, Stephen Dinkeldein, Vivienne Button and Sean Marshall Content Reviewers Lawrence Garrett, Marianne Page, Heather Palomino, Alison Moore, Adrian Ciechacki and Michael Irvine Content Coordination Manager Nancy Tsang Senior Content Coordinators Carla Cagnina and Delicia Tasinda Content Coordinator Joanna Chivers Head of Production Jasper John Production Coordinator Genevieve Sibayan

Published by Chambers and Partners 165 Fleet Street London EC4A 2AE Tel +44 20 7606 8844 Fax +44 20 7831 5662 Web www.chambers.com

Copyright © 2026 Chambers and Partners

Contents

INTRODUCTION Contributed by Christian Schröder, Orrick, Herrington & Sutcliffe LLP p.5

INDIA Law and Practice p.189

Contributed by ANA Law Group Trends and Developments p.206 Contributed by Ankura Consulting Group, LLC

AUSTRALIA Law and Practice p.8 Contributed by Nyman Gibson Miralis Trends and Developments p.25 Contributed by Nyman Gibson Miralis

ITALY Law and Practice p.212

Contributed by ICT Legal Consulting Trends and Developments p.222 Contributed by ICT Legal Consulting

BELGIUM Law and Practice p.32

Contributed by Alston & Bird LLP Trends and Developments p.51 Contributed by Loyens & Loeff CHILE Law and Practice p.56 Contributed by Magliona Abogados

JAPAN Law and Practice p.228 Contributed by Mori Hamada Trends and Developments p.238 Contributed by Nagashima Ohno & Tsunematsu

MEXICO Law and Practice p.245 Contributed by Nader Hayaux & Goebel

CHINA Law and Practice p.73

Contributed by Fangda Partners Trends and Developments p.89 Contributed by Fangda Partners

PORTUGAL Law and Practice p.256

Contributed by Abreu Advogados Trends and Developments p.273 Contributed by Abreu Advogados

FINLAND Law and Practice p.95

Contributed by Lieke Attorneys Ltd Trends and Developments p.111 Contributed by Lieke Attorneys Ltd

SINGAPORE Law and Practice p.280

Contributed by Drew & Napier LLC Trends and Developments p.297 Contributed by CMS SOUTH KOREA Law and Practice p.303 Contributed by Lee & Ko Trends and Developments p.319 Contributed by Lee & Ko SPAIN Law and Practice p.325 Contributed by Deloitte Legal Trends and Developments p.344 Contributed by Deloitte Legal

FRANCE Law and Practice p.119 Contributed by Freshfields

GERMANY Law and Practice p.139 Contributed by Annerton Trends and Developments p.157 Contributed by Annerton

GREECE Law and Practice p.164 Contributed by ALG Manousakis Law Firm Trends and Developments p.183 Contributed by ALG Manousakis Law Firm

3 CHAMBERS.COM

Contents

SWEDEN Law and Practice p.352 Contributed by Mannheimer Swartling Advokatbyrå AB Trends and Developments p.368 Contributed by Mannheimer Swartling Advokatbyrå

UAE Trends and Developments p.433 Contributed by Ankura Consulting Group LLC

UK Law and Practice p.440

Contributed by Sidley Austin LLP Trends and Developments p.456 Contributed by Sidley Austin LLP USA Law and Practice p.461 Contributed by Freshfields Trends and Developments p.473 Contributed by Freshfields

SWITZERLAND Law and Practice p.374

Contributed by Walder Wyss Ltd Trends and Developments p.385 Contributed by Walder Wyss Ltd

TAIWAN Law and Practice p.390 Contributed by Lee and Li Attorneys-at-Law Trends and Developments p.406 Contributed by Lee and Li Attorneys-at-Law

TÜRKIYE Law and Practice p.414 Contributed by YAZICIOGLU Legal

4 CHAMBERS.COM

INTRODUCTION

Contributed by: Christian Schröder, Orrick, Herrington & Sutcliffe LLP

Orrick, Herrington & Sutcliffe LLP is a global law firm dedicated to serving the technology and innova - tion, energy and infrastructure, finance, and life sci - ences and healthtech sectors. With more than 1,150 lawyers across 26+ markets worldwide, Orrick pro - vides forward-looking, pragmatic advice on transac - tions, litigation and compliance matters. As one of the world’s leading tech law firms, cybersecurity and privacy are central to Orrick's practice. The firm has 20 cybersecurity and privacy-focused partners and more than 60 specialised lawyers, making it one of

the strongest data protection practices in the market, recognised by Chambers Global, US and Europe. Or - rick helps clients navigate the complex cybersecurity and privacy legal landscape, managing global com - pliance matters, cyber incidents, litigation and regu - latory investigations. The team maximises data value, addresses global privacy requirements and reduces security risks. Whether clients are managing com - pliance challenges, licensing data or acquiring new companies, Orrick offers forward-thinking solutions to address data challenges.

Contributing Editor

Christian Schröder is a partner in Orrick's Düsseldorf office and leads the firm’s cyber, privacy and data innovation group in Europe. He specialises in data-focused laws, including cybersecurity, privacy

compliance, incident response, data licensing, AI and regulatory investigations. Christian advises on internal and external data transfers, product launches and privacy requirements for connected cars. He maintains strong relationships with German and EU data protection authorities, effectively defending clients in investigations. Recognised by Chambers as a top practitioner, he is a noted thought leader in privacy law.

Orrick, Herrington & Sutcliffe LLP Heinrich-Heine-Allee 12 40213 Düsseldorf Germany Tel: +49 211 3678 7269 Email: cschroeder@orrick.com Web: www.orrick.com

5 CHAMBERS.COM

INTRODUCTION  Contributed by: Christian Schröder, Orrick, Herrington & Sutcliffe LLP

Introduction to the Cybersecurity Guide Cybersecurity has shifted from a niche technical con - cern to a management board priority and, increas - ingly, to an enforcement reality. Lawmakers and regu - lators in many jurisdictions are moving from principles to practice, demanding that organisations not only implement robust controls but also adhere to certifi - cation schemes or otherwise prove their compliance. The result is a maturing patchwork of cybersecurity rules that pose new challenges to many organisations. In the European Union (EU), the NIS2 Directive, the Digital Operational Resilience Act (DORA), the Cyber Resilience Act (CRA), the Cyber Solidarity Act, and a pending revision of the Cybersecurity Act are con - verging into a more integrated regime that reaches products, services, operations and supply chains. The US, Middle East and Asia-Pacific are simultaneously tightening rules, creating a patchwork of laws that management boards, legal departments and counsel must navigate cautiously. The recent wave of cybersecurity regulations reflects a global recognition of the critical importance of safe - guarding digital assets. These regulations underscore the necessity for comprehensive risk management strategies, accountability at the highest levels of man - agement, and the implementation of rigorous secu - rity measures across all sectors. One of the primary implications of these regulations is the heightened accountability placed on organisational leadership. This shift in responsibility requires a cultural change within organisations, where cybersecurity is integrated into the core business strategy rather than treated as a peripheral IT issue. Furthermore, the emphasis on incident reporting and transparency has profound implications for how organisations handle data breaches and cyber inci - dents. Timely reporting to regulatory authorities and affected parties is not only a legal obligation but also a critical component of maintaining trust and credibility. Cybersecurity laws around the world The rapid pace of technological advances and the growing significance of cyber-related systems for critical infrastructure are prompting lawmakers world - wide to introduce new legislation to address emerging

cybersecurity challenges. One of the key challenges for international businesses in implementing cyberse - curity regulations is the harmonisation of standards across jurisdictions. Differences in legal systems, regulatory approaches and levels of technological development can hinder efforts to establish common standards. For international businesses, it is crucial to react promptly to legislative amendments and imple - ment the relevant cybersecurity obligations within their internal structure. Consequently, it is essential to consistently monitor legislative processes and gen - eral trends. The EU continues to set the tone. Even as the transpo - sition of NIS2 remains uneven across member states, management bodies already face explicit governance duties and potential liability, and supervisory expecta - tions are sharpening. The CRA has been in force since December 2024 and pushes secure‑by‑design devel - opment, vulnerability handling and incident reporting across products with digital elements, including soft - ware‑only offerings. Its reporting obligations begin in September 2026, with many core duties taking effect in December 2027. In early 2025, a targeted update to the EU Cybersecurity Act strengthened the certifi - cation framework and empowered ENISA to develop new schemes, reinforcing trust in cloud and informa - tion security products and services. DORA has applied to financial entities since 17 Janu - ary 2025, with regulatory technical standards already in place for incident classification, reporting content and timelines, and the critical third-party provider (CTPP) oversight regime. The European Supervisory Authorities have already designated the CTPPs and launched oversight engagement. Financial entities should expect assertive supervision of ICT risk man - agement, testing, third-party chains and reporting. The United States is also consolidating incident reporting and governance obligations. The Cyber - security and Infrastructure Agency’s rule under the Cyber Incident Reporting and Critical Infrastruc - ture Act is planned for 2026. For the use of artificial intelligence, the National Institute of Standards and Technology is planning a Cybersecurity Framework, with the focus on securing AI system components, conducting AI-enabled cyber defence, and thwart -

6 CHAMBERS.COM

INTRODUCTION  Contributed by: Christian Schröder, Orrick, Herrington & Sutcliffe LLP

ing AI-enabled cyber-attacks. In addition, a range of state-level cybersecurity laws are already in place, with further legislation anticipated. Beyond the EU and the US, cybersecurity momentum is also recognisable. • On 12 November 2025, the UK introduced the Cyber Security and Resilience (Network and Infor - mation Systems) Bill to modernise its NIS regime, tighten reporting and transparency, and raise sanc - tions, largely aligning with the EU’s NIS2 Directive and easing cross‑channel co-ordination for multi - nationals. • In China, the first major overhaul of the Cyberse - curity Law since 2017 took effect on 1 January 2026, increasing penalties, strengthening adminis - trative enforcement, and extending extraterritorial reach. It also introduces a new article addressing artificial intelligence, signalling that AI governance and cybersecurity will increasingly be treated as integrated policy concerns. • Across the MENA region, Saudi Arabia’s National Cybersecurity Authority has entrenched mandatory baselines through Essential Cybersecurity Controls and sectoral extensions (including cloud), backed since 2024 by inspection and enforcement powers. • The UAE and Qatar are likewise elevating baseline controls and clarifying notification expectations. Challenges Rising geopolitical tensions are one reason for stricter cybersecurity regulations worldwide. State-backed and state-aligned activity has grown more sophisti - cated, and sectors intertwined with public mandates (such as defence, infrastructure and water) face heightened exposure. Consequently, cybersecurity standards for the public sector have increased sig - nificantly worldwide. The regulatory challenge now is less about intent and more about coherence of cybersecurity regulation. While the EU has made strides in creating a unified cybersecurity framework, achieving global consensus remains a complex task. Differences in legal systems,

regulatory approaches and levels of technological development can hinder efforts to establish common standards. However, international co-operation and dialogue are essential to overcoming these barriers and creating a cohesive global cybersecurity strategy. Another challenge lies in the integration of emerging technologies, such as artificial intelligence (AI) and the Internet of Things (IoT), into existing cybersecu - rity frameworks. These technologies offer tremendous potential for innovation but also introduce new vulner - abilities that must be addressed. The EU’s AI Act, for example, sets standards for the design and operation of AI systems to ensure they are resilient to errors and secure against unauthorised alterations. As technol - ogy continues to evolve, legal frameworks must be adaptable to accommodate new developments and address emerging threats. In addition, the cost of non-compliance with cyber - security laws is rising. Non-compliance can trigger substantial penalties under the EU’s NIS2 Directive of up to EUR10 million or 2% of worldwide turnover, alongside civil litigation and reputational harm. In the EU, a key driver is the personal liability of manage - ment introduced by NIS2. Conclusion: integrated legal approaches are needed Cybersecurity law can no longer be thought of as something separate and isolated but should be treat - ed as an integral part of a larger, interconnected land - scape, where a broad range of stakeholders must be integrated and where different laws are relevant, such as data protection law, consumer protection law and corporate governance. Technical aspects are also deeply connected with legal matters. For legal professionals, navigating the complexities of cybersecurity law requires a deep understanding of both the regulatory landscape and the technical aspects of cybersecurity. The path forward involves balancing innovation with regulation, ensuring that legal frameworks are both comprehensive and adapt - able to emerging threats.

7 CHAMBERS.COM

AUSTRALIA

Australia

Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas Nyman Gibson Miralis

Sydney

Tasmania

Contents 1. General Overview of Laws and Regulators p.10 1.1 Cybersecurity Regulation Strategy p.10 1.2 Cybersecurity Laws p.10 1.3 Cybersecurity Regulators p.12 2. Critical Infrastructure Cybersecurity Regulation p.15 2.1 Scope of Critical Infrastructure Cybersecurity Regulation p.15 2.2 Critical Infrastructure Cybersecurity Requirements p.15 2.3 Incident Response and Notification Obligations p.16 2.4 State Responsibilities and Obligations p.17 3. Operational Resilience in the Financial Sector p.18 3.1 Scope of Financial Sector Operational Resilience Regulation p.18 3.2 ICT Service Provider Contractual Requirements p.18

3.3 Key Operational Resilience Obligations p.19 3.4 Operational Resilience Enforcement p.20

3.5 International Data Transfers p.20 3.6 Threat-Led Penetration Testing p.21 4. Cyber-Resilience p.22 4.1 Cyber-Resilience Legislation p.22 4.2 Key Obligations Under Legislation p.22 5. Security Certification for ICT Products, Services and Processes p.22

5.1 Key Cybersecurity Certification Legislation p.22 6. Cybersecurity in Other Regulations p.23 6.1 Cybersecurity and Data Protection p.23 6.2 Cybersecurity and AI p.24 6.3 Cybersecurity in the Healthcare Sector p.24

8 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Nyman Gibson Miralis is an international, award- winning criminal defence law firm based in Sydney, Australia. For over 50 years it has been leading the market in all aspects of general, complex and interna - tional crime, and is widely recognised for its involve - ment in some of Australia’s most significant criminal cases. Its international law practice focuses on white- collar and corporate crime, transnational financial crime, bribery and corruption, international money laundering, cybercrime, international asset freezing or forfeiture, extradition and mutual assistance law.

Nyman Gibson Miralis strategically advises and ap - pears in matters where transnational cross-border investigations and prosecutions are being conducted in parallel jurisdictions, involving some of the largest law enforcement agencies and financial regulators worldwide. Working with international partners, it has advised and acted in investigations involving the Brit - ish Virgin Islands, Cambodia, Canada, China, the EU, Hong Kong, Macau, Mexico, New Zealand, Russia, Singapore, South Africa, South Korea, Taiwan, the UK, the USA and Vietnam.

Authors

Dennis Miralis is a leading Australian defence lawyer who specialises in international criminal law, with a focus

Henry Yu is an international criminal lawyer and part of the white-collar investigations team at Nyman Gibson Miralis. He assists the partners in various international criminal law matters, focusing on white-collar

on complex multijurisdictional regulatory investigations and prosecutions. His areas of expertise include cybercrime, global investigations, proceeds of crime, bribery and corruption, anti-money laundering, worldwide freezing orders, national security law, Interpol Red Notices, extradition and mutual legal assistance law. Dennis advises individuals and companies under investigation for economic crimes both locally and internationally. He has extensive experience in dealing with all major Australian and international investigative agencies.

crime, anti-bribery and corruption, anti-money laundering, tax fraud and evasion, and cybercrime. With extensive experience in financial crime, foreign bribery, high-value taxation investigations and disputes, tax fraud and evasion, money laundering, and unexplained wealth matters, Henry brings a comprehensive understanding to complex legal challenges.

Phillip Salakas is a defence lawyer who assists the partners with complex criminal matters and investigations involving corporate and financial crime as part of Nyman Gibson Miralis’ white-collar crime

Jack Dennis is a senior criminal defence lawyer who practises in international and domestic criminal, corporate and tax law at Nyman Gibson Miralis. His international criminal work includes transnational

team. Phillip has completed a Bachelor of Laws degree at the University of Technology Sydney and has previously worked in the area of general crime.

criminal and regulatory investigations, liaising with foreign legal and regulatory bodies, as well as advising clients on matters concerning international public law. Domestically, Jack has advised on a range of criminal issues and investigations, including white-collar crime, fraud, sanctions, INTERPOL, extraditions and national security. He also has significant international, corporate and tax experience, having advised on cross-border transactions and disputes involving foreign and domestic corporations and individuals, across the software, financial services, and crypto-industries.

9 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Nyman Gibson Miralis Level 9, 299 Elizabeth Street Sydney NSW 2000 Australia

Tel: +61 292 648 884 Email: dm@ngm.com Web: www.ngm.com.au

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy On 22 November 2023 the Australian government released the 2023–2030 Australian Cyber Security Strategy (the “Strategy”), with the aim of strengthen - ing Australia’s cyberdefences and supporting people and businesses to be resilient to and recover quickly from cyber-attacks. Alongside the Strategy was the 2023–2030 Austral - ian Cyber Security Strategy: Action Plan (the “Action Plan”) setting out three “Horizons”, which culminate in Horizon 3 with Australia as a leader of the global frontier in developing cybertechnologies and adapting to risk and opportunities. Last year marked the end of Horizon 1 (“Strengthen our foundations”), which aimed to address critical gaps, build protections, and support an initial uplift in cybermaturity. Between July and August 2025, the government conducted a public consultation concerning Horizon 2 (“Expand our search”). The government has moved into industry co-design on specific actions and initiatives; however, no substan - tive announcements have yet been made. Originally, Horizon 2 was intended to involve scaling Australia’s “maturity across the whole economy” through invest - ments in the broader cyber-ecosystem and workforce. The government has grounded its vision in six “shields” or “layers of defence” comprising the businesses and citizens, safe technology, world-class threat sharing and blocking, protected critical infrastructure, sover - eign capabilities, and resilient region and global lead -

ership. It has set out in its Action Plan different actions and objectives for each shield. While the co-design process of Horizon 2 and any amendments to the Strategy and the Action Plan are still being contemplated, it is expected that changes to Australia’s overall strategy will be announced in the next 12 months. 1.2 Cybersecurity Laws Australia has a broad system of federal, state, and territory-based laws which govern data protection, cybersecurity, and cybercrime. Data Protection Entities dealing with personal information in Australia should also be aware of their obligations with respect to: • the Privacy Act 1988 (Cth) (the “Privacy Act”), which regulates the handling of personal informa - tion by “APPs entities” pursuant to the Australian Privacy Principles (APPs). • the Digital ID Act 2024 (Cth) (the “Digital ID Act”), which is intended to embed safeguards for digital ID services and data in addition to the Privacy Act; • privacy legislation enacted at the state and territory level; • the My Health Records Act 2012 (Cth) (the “My Health Records Act”), which imposes specific obli - gations for health information collected and stored in Australia’s national online health database (in addition to the Privacy Act); • state and territory health records legislation enact - ed in New South Wales, Victoria, and the Australian Capital Territory; and

10 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

• federal, state, and territory surveillance legisla - tion, which regulates video surveillance, computer and data monitoring, GPS tracking, and the use of listening devices on individuals. Further definitions and details on the Privacy Act are set out in 6.1 Cybersecurity and Data Protection . Cybersecurity Cybersecurity laws in Australia are primarily governed under sector-specific federal laws, and include the fol - lowing. • Critical infrastructure: this sector is regulated under the Security of Critical Infrastructure Act 2018 (Cth) (the “SOCI Act”), which imposes registration, reporting, and notification obligations on owners and operators of critical infrastructure and empow - ers the Australian government to gather informa - tion and issue directions where there is a risk to security. More details are contained in 2. Critical Infrastructure Cybersecurity Regulation . • Telecommunications: this sector is regulated by dual legislation, namely: (a) the Telecommunications Act 1997 (Cth) (the “Telecommunications Act”), which imposes security and notification obligations on Aus - tralian telecommunications providers and empowers the Australian government to gather information and issue directions; and (b) the Telecommunications (Interception and Access) Act 1979 (Cth) (the “TIA Act”), which prohibits the interception of communication and access to stored communication data, ex - cept for certain law enforcement and national security purposes. • Corporate: corporations generally are regulated under the Corporations Act 2001 (Cth) (the “Corpo - rations Act”), which is highly relevant to the cyber - security space. For example, the director’s duty to exercise “care and diligence” (Section 180) is equally relevant to the management of foreseeable cyber and information security risks. • Financial services: certain financial, insurance, and superannuation entities are regulated through standards, including the Prudential Standard CPS 234 on Information Security (CPS 234), issued by the Australian Prudential Regulation Authority

(APRA). Additionally, entities in the financial servic - es have specific obligations under the Corporations Act, such as adequate risk management systems to hold a financial licence (section 912A). There are additional laws that are highly relevant to the cybersecurity space that are less sector-specific, such as consumer law, specifically the Competition and Consumer Act 2010 (Cth) (the “Consumer Act”) which addresses consumer affairs, including consum - er data protection and cyberscams. Cybercrime Overlaying the above are various cybercrime offences in Australia at the federal, state, and territory levels. These offences broadly encompass two categories: • offences that are directed at computers or other devices and involve hacking-related activities; and • cyber-enabled offences where such devices are used as a key component of the offence, includ - ing online fraud, online child abuse offences, and cyberstalking. Federally, cybercrime is criminalised under Parts 10.6 and 10.7 of the Schedule to the Criminal Code Act 1995 (Cth) (the “Criminal Code”), which sets out a vari - ety of offences with maximum penalties ranging from fine-only through to life imprisonment. Organisations should note that in addition to the Crim - inal Code: • the TIA Act also makes it a federal offence for an individual to (without authorisation) intercept or access private telecommunications without the knowledge of those involved; and • state and territory laws criminalise computer offences similar to those criminalised under the Criminal Code (eg, Part 6 of the Crimes Act 1900 (NSW) provides for multiple computer offences regarding unauthorised access, modification, or impairment of restricted data and electronic com - munications). Australian states and territories also have their own criminal laws which govern cybercrime offences.

11 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Other Laws Areas that are also related to cybersecurity include: • the Broadcasting Services Act 1992 (Cth) (the “Broadcasting Act”) regulates broadcasting ser - vices through internet and other means in Australia and enables the creation of industry codes of prac - tice regulating the content of such services; • the Online Safety Act 2021 (Cth) (OSA) establishes complaint systems for cyberbullying of children, non-consensual sharing of intimate images, cyber- abuse of adults, and the online/social media avail - ability of content that would be subject to broad - casting classifications (restricted or age 18 years or older); • the Spam Act 2003 (Cth) (the “Spam Act”) prohib - its the use of electronic communications for the purpose of sending unsolicited marketing materials to individuals; and • the Do Not Call Register Act 2006 (Cth) (the “DNCR Act”) prohibits unsolicited telemarketing calls being made to phone numbers registered on a Do Not Call Register. 1.3 Cybersecurity Regulators Australia has a range of federal, state, and territory regulators and agencies which deal with cybersecu - rity. The overarching government agencies are: • Department of Home Affairs (DoHA); and • Australian Signals Directorate (ASD). While the key regulators and enforcement bodies include: • Office of the Information Commissioner (OAIC); • Critical Infrastructure Centre (CIC); • Australian Communications and Media Authority (ACMA); • Australian Securities and Investments Commission (ASIC); • Australian Prudential Regulation Authority (APRA); and • Australian Competition and Consumer Commission (ACCC).

Specifically in relation to criminal enforcement, the fol - lowing regulators are key: • Australian Federal Police (AFP); • Commonwealth Director of Public Prosecutions (CDPP); • Australian Security Intelligence Organisation (ASIO); • Australian Transaction Reports and Analysis Centre (AUSTRAC); and • Australian Criminal Intelligence Commission (ACIC). Each of the above are addressed below. Overarching Government Agencies DoHA The DoHA is the lead government department for cyberpolicy. The DoHA develops cybersecurity and cybercrime law and policy, implements Australia’s national cybersecurity strategy, and responds to international and domestic cybersecurity threats and opportunities, including in the areas of critical infra - structure and emerging technologies. The DoHA also has responsibility for cybersecurity and cybercrime operational agencies including the AFP, ACIC, AUS - TRAC, and ASIO. ASD, ACSC and CERT The ASD is Australia’s operational lead on cyberse - curity and plays both a signals intelligence and infor - mation security role. The ASD undertakes cyberthreat monitoring and conducts defensive, disruption, and offensive cyber-operations offshore to support mili - tary operations and to counter terrorism, cyber-espio - nage, and serious cyber-enabled crime. The ASD also advises and co-ordinates operational responses to cyber-intrusions on government, critical infrastructure, information networks and other systems of national significance. Within the ASD sits the Australian Cyber Security Centre (ACSC). The ACSC drives cyber-resilience across the whole Australian economy including with respect to critical infrastructure, government, large organisations and small to medium businesses, aca - demia, NGOs, and the broader Australian community. The ACSC provides general information, advice, and

12 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

assistance to Australian organisations and the pub - lic on cyberthreats and it collaborates with business, government, and the community to increase cyber- resilience across Australia. The ACSC also runs the Computer Emergency Response Team (CERT), which provides advice and support to industry on cybersecurity issues affecting Australia’s critical infrastructure and other systems of national significance. Other key government bodies At this juncture, the following bodies should also be noted: • the Attorney-General’s Department (AGD) advises government on cybersecurity policies and law, including in relation to human rights, privacy, pro - tective security, international law, administration of criminal justice, and oversight of intelligence, security, and law enforcement agencies; • the Department of Defence (DoD) contributes to Australia’s whole-of-government cybersecurity pol - icy and operations and houses ASD; it also houses the Information Warfare Division, which develops information warfare capabilities for the Australian Defence Force (ADF); and • the Department of Foreign Affairs and Trade (DFAT) advances Australia’s international cyber-affairs agenda, which includes digital trade, cybersecurity, cybercrime, international security, internet govern - ance and co-operation, human rights and democ - racy online, and technology for development. Data Protection and Privacy The OAIC is the federal privacy and information regu - lator with a range of functions and powers to investi - gate and resolve privacy complaints, enforce privacy compliance, make determinations, and provide rem - edies for breaches under the notifiable data breach (NDB) scheme. The OAIC operates by reference to the Privacy Act, the My Health Records Act, the Tel - ecommunications Act, the TIA Act, and recently the Digital ID Act. The remedies range from enforceable undertakings to civil penalties of 2,000 penalty units (approximate - ly AUD660,000); but may also involve imprisonment.

Since December 2022, serious and repeated interfer - ences with privacy may attract a penalty of up to: • for entities, not body corporates – AUD2.5 million; or • for body corporates – the greater of AUD50 million, three times the value of the benefit attributable to the conduct, or 30% of the adjusted turnover for the relevant period. There are also state and territory privacy commission - ers which administer state and territory-based privacy and health information laws. These include: • the NSW Information and Privacy Commission, who administers, inter alia, the Privacy and Per - sonal Information Protection Act 1998 (NSW) and Health Records and Information Privacy Act 2002 (NSW); and • the Office of the Victorian Information Commis - sioner, who administers the Privacy and Data Protection Act 2014 (Vic) and the Victorian Health Complaints Commissioner, who handles breaches The CIC is part of the DoHA and is the federal regu - lator of the SOCI Act and certain provisions of the Telecommunications Act with powers to investigate, audit, and enforce on compliance matters. The CIC also has the ability to make recommendations to DoHA and the Home Affairs Minister on whether their information-gathering powers and directions powers should be exercised. The CIC additionally has enforcement powers which allows it to issue penal - ties for non-compliance that range from performance injunctions, enforceable undertakings, civil penalties of up to 120 penalty units (AUD39,600), or seek two years’ imprisonment. Telecommunications, Broadcasting and Marketing Cybersecurity The ACMA is Australia’s regulator for broadcasting, telecommunication, and certain online content and provides licensing to industry providers. ACMA has specific regulatory powers under the Telecommunica - tions Act, the TIA Act, the Spam Act, and the DNCR of the Health Records Act 2001 (Vic). Critical Infrastructure Cybersecurity

13 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

Act to investigate and resolve complaints and enforce compliance. In dealing with non-compliance, ACMA is empowered to issue warnings, infringement notices, enforceable undertakings, and remedial directions. ACMA is fur - ther able to cancel or impose conditions on licences and accreditations. ACMA also has the ability to com - mence civil proceedings or refer matters for criminal prosecution. Additionally, the Office of the eSafety Commissioner (the “eSafety Commissioner”) has powers to promote and regulate online safety with respect to telecommu - nications, broadcasting, and other online industries. However, the eSafety Commissioner cannot inves - tigate matters of cybercrime. Penalties range from takedown notices and blocking directions to infringe - ment notices and injunction proceedings. Corporations, Consumers and Financial Services Cybersecurity ASIC is Australia’s corporate, market, and financial services regulator. It regulates publicly-listed corpora - tions under the Corporations Act and is empowered to investigate and take action against corporations, directors, and officers for non-compliance with the Corporations Act, including cybersecurity issues. APRA regulates certain finance, banking, insurance, and superannuation entities and issues regulatory guidance (eg, information security standards CPS 234). APRA has powers to supervise, monitor, and intervene in matters of cybersecurity for regulated entities and has a range of enforcement powers to deal with breaches of its standards. Such powers involve APRA issuing infringement notices, provid - ing directions or enforceable undertakings, imposing licensing conditions, disqualifying senior officials, and commencing court-based action. The ACCC is Australia’s competition regulator and consumer protector, and may, where appropriate, undertake enforcement action against breaches of the Consumer Act, including breaches involving cyberse - curity, cybercrime, and cyberscam issues. The ACCC additionally:

• administers the Consumer Data Right (CDR) regime; • co-regulates (with OAIC) the Digital ID Act; and • hosts the Scamwatch website, which provides public information, alerts, and access to com - plaints mechanisms on a wide range of consumer scams, including scams perpetrated online. Also relevant for the financial sector is that OAIC regu - lates the aspects of the Privacy Act which deal with credit reporting obligations and the credit reporting code, which imposes certain conditions on entities that hold credit-related personal information. Cybercrime Cybercrime at the federal level is investigated and enforced by the AFP and prosecuted by the CDPP. The AFP have a dedicated Cybercrime Operations team comprising investigators, technical specialists, and intelligence analysts who operate across multiple jurisdictions to conduct cyber-assessments and to tri - age, investigate, and disrupt cybercrime. More specifically: • ACIC is Australia’s national criminal intelligence agency; it has broad investigative and coercive powers and shares information between all levels of law enforcement; • AUSTRAC is the domestic watchdog for Australia’s anti-money laundering and counter-terrorism measures; it supports law enforcement operations involving cybercrime financing; and • ASIO investigates cyber-activity involving espio - nage, sabotage, and terrorism related activities; ASIO also contributes to the investigation of com - puter network operations directed against Aus - tralia’s systems. State and territory-based police and prosecution agencies investigate, enforce and prosecute state and territory cybercrimes.

14 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

2. Critical Infrastructure Cybersecurity Regulation 2.1 Scope of Critical Infrastructure Cybersecurity Regulation Australia’s critical infrastructure and assets are regu - lated through Commonwealth, state, and territory legislation, with a particular emphasis on the SOCI Act. That said, there is broader legislation, such as the Privacy Act and Cyber Security Act, and more sector- specific legislation, such as the Telecommunications Act, that cannot be ignored. The SOCI Act currently regulates certain assets across eleven sectors: communications, data stor - age and processing, financial services, energy, food and grocery, health and medical, higher education and research, space technology, transport, water and sewerage, and the defence industry. In Novem - ber 2025, telecommunications security obligations (which were previously under the Telecommunication Sector Security Reforms (TSSR)) were moved into the SOCI, a change implemented by the Security of Criti - cal Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (Cth) (the “2024 SOCI Amendment Act”). Notwithstanding recent reforms which clarified the SOCI Act, the exact parameters of the legislation are broad and complex, and extend to various partici - pants in a supply chain including “responsible enti - ties”, “reporting entities”, “direct interest holders”, “managed service providers”, and “operators”. Some of these definitions are asset-specific, but for our purposes, it is important to note that a “responsible entity” is generally the entity that owns, is licensed, or otherwise responsible for operating the asset. Further, despite the imminent shift of the TSSR and its obligations to the SOCI Act, these obligations still remain in force and apply to the relevant infrastructure as is. The TSSR are applicable to carriers, carriage service providers, and carriage service intermediaries. Cyber Security Act Additionally, there are cybersecurity obligations imposed on critical infrastructure under the Cyber

Security Act where they constitute “a reporting busi - ness entity”. A “reporting business entity” is an entity that: • is carrying on a business in Australia with an annual turnover for the previous financial year that exceeds the “turnover threshold for that year” (to be determined) but is not a Commonwealth body, State body, or responsible entity for a critical infra - structure asset; or • a responsible entity for a critical infrastructure asset “to which Part 2B of the Security of Criti - cal Infrastructure Act 2018 applies” – specifically, these entities are listed in Security of Critical Infra - structure (Application) Rules (LIN 22/026) 2022 and include most infrastructure assets. 2.2 Critical Infrastructure Cybersecurity Requirements The SOCI Act imposes requirements on owners and operators of assets across various fields. The exact requirements vary depending on the particular asset/ industry; however, it may include a requirement to: • register with the Register of Critical Infrastructure Assets; • provide ownership and operational information; • notify the government of certain cyber-incidents; • implement and comply with a critical infrastructure risk management programme (CIRMP); and • if they have “business critical data” processed or stored by a third party on a commercial basis, they must take reasonable steps to notify that third party. Further still, the SOCI Act and associated rules impose enhanced cybersecurity obligations on assets desig - nated as “systems of national significance” (SoNS). These must be assets that are already considered a “critical infrastructure asset”, but also that they are of “national significance”. These designations are private and confidential so as to avoid publicising their signifi - cance to malicious actors. Reports indicate that over 200 systems have been designated to date. A responsible entity for a SoNS may be required to:

15 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

• fulfil statutory response planning obligations; • undertake a cybersecurity exercise (see 3.6 Threat- Led Penetration Testing ); • undertake a vulnerability assessment (see 3.6 Threat-Led Penetration Testing ); and • where the system is a computer or needs a com - puter to operate the system, undertake periodic reports, provide event-based reports or install soft - ware that transmits system information to the ASD. It is also worth noting that the SOCI Act also includes: • an information gathering power for the Secretary of the DoHA to monitor compliance; and • a directions power for the Home Affairs Minister to direct regulated entities to do or not do a specified thing that is reasonably necessary to protect criti - cal infrastructure from national security risks. 2.3 Incident Response and Notification The SOCI Act imposes mandatory incident reporting obligations for responsible entities of critical infra - structure assets with regards to cybersecurity inci - dents. Responsible entities must report cybersecurity inci - dents that have a significant or relevant impact on their asset. In other words, a “responsible entity” must make a report when it becomes aware of the follow - ing. Obligations The SOCI Act • Under Section 30BC a “cyber security incident” that “has had, or is having, a significant impact (whether direct or indirect) on the availability of the asset” – such a “significant impact” is defined as being where “the incident has materially disrupted the availability of [the] essential goods or service” in connection with which the asset is used to pro - vide. The report must be made “as soon as prac - ticable, and in any event within 12 hours, after the entity becomes aware”. If the initial report is oral, then a written report must be made within 84 hours after the oral report is given; and • Under Section 30BD a “cyber security incident” that “has had, or is having, or is likely to have, a relevant impact on the asset” – such a “relevant

impact” is defined (for critical infrastructure assets) as a (direct or indirect) impact on the availability, integrity, reliability of the asset, or on the confiden - tiality of information about the asset, information stored on the asset or computer data constituting the asset. The report must be made “as soon as practicable, and in any event within 72 hours, after the entity becomes aware. If the initial report is oral, then a written report must be filed within 48 hours of the oral report. A “cyber security incident”, as defined under Section 12M, is the: • unauthorised access to or modification of com - puter data or computer program; • unauthorised impairment of electronic communica - tions to or from a computer (but does not include “a mere interception of any such communication”); or • unauthorised impairment of the availability, reli - ability, security or operation of computer data, a computer program or a computer. Either of these reports must be given to the ASD (unless another relevant Commonwealth body is specified in the rules). Failure to make a report at all or in writing, or in the approved form, is punishable by 50 penalty units (AUD16,500 fine). The Cyber Security Act Irrespective of whether the cybersecurity incident meets the above significance or relevance thresholds, most critical infrastructure assets (being “a reporting business entity”) have additional reporting obligations under the Cyber Security Act. In summary, there is an obligation to report to the ASD (or another designated Commonwealth agency) where: • there is a cybersecurity incident that has had, is having, or could reasonably be expected to have a (direct or indirect) impact on a reporting business entity; • an entity (the extorting entity) demands a benefit; and

16 CHAMBERS.COM

AUSTRALIA Law and Practice Contributed by: Dennis Miralis, Jack Dennis, Henry Yu and Phillip Salakas, Nyman Gibson Miralis

• the reporting entity (or a third party on their behalf) makes the ransomware payment. Such a report must be given with 72 hours of the reporting business entity becoming aware of the pay - ment and must contain certain information. A “cyber security incident” for these purposes is broader than under the SOCI Act. Under the Cyber Security Act, a “cyber security incident” is an act, event or circumstance covered by the SOCI Act but can also be an act, event, or circumstance if it involves “unauthorised impairment of electronic communica - tion to or from a computer” (even mere interception). However, in the case of the latter, the incident must involve a critical infrastructure asset; involve an Aus - tralian corporation (attracting paragraph 51 (xx) of the Constitution); (actually or is reasonably expected to be) effected by means of “telegraphic, telephonic or other like service”; (actually, probably, or it is reason - able to expect it) impeded or impaired “the ability of a computer to connect to such a service”; or (probably or is reasonably expected to have) prejudiced Aus - tralia’s social/economic stability, defence or national security. Voluntary Incident Reporting Obligations The ACSC has a cyber-incident reporting portal through which critical asset owners are encouraged to voluntarily report cybersecurity incidents. Any impacted entity carrying or a business in Aus - tralia or otherwise a responsible entity for critical infra - structure is now being statutorily encouraged to make voluntary reports to the NCS Coordinator under the Cyber Security Act, even where it is unclear if an inci - dent is a cybersecurity incident. Other Mandatory Reporting Obligations Other reporting obligations under the SOCI Act for critical infrastructure assets include: • taking reasonable steps to notify a third-party entity if that third party is processing or storing “business critical data” on a commercial basis; • an ongoing obligation on a “reporting entity” to report a “notifiable event” in relation to an asset

usually within 30 days after the event occurs, which relates to changes in the operational infor - mation and interest/control information in relation to “director interest holders”, or the status of an entity as a reporting entity; and • reporting if a hazard had significant relevant impacts on a critical infrastructure asset. See additionally relevant obligations in 6.1 Cyberse- curity and Data Protection . Criminal Offences Related to infrastructure, Part 10.6 of the Criminal Code places obligations on providers of content or hosting services to notify the AFP as to the existence of material displaying “abhorrent violent conduct” (if occurring in Australia) and, in any event, to expedi - tiously remove or cease to host such material. Relevantly, this reporting obligation is supplemented by the OSA, which empowers the eSafety Commis - sioner to issue removal notices requiring hosting ser - vice providers to remove cyberbullying, cyber-abuse, and other harmful material within strict statutory time - frames. 2.4 State Responsibilities and Obligations The Australian government considers “the respon - sibility for ensuring the continuity of operations and the provision of essential services to the Australian economy and community” as being shared “between owners and operators of critical infrastructure, state and territory governments and the Australian govern - ment”. Generally speaking, government bodies may also be captured within the scope of legislative regimes such as the Privacy Act and therefore have the same (or similar) obligations as their private-sphere coun - terparts. However, the SOCI Act does not apply to the Commonwealth or a body corporate established under Commonwealth law unless so declared or pre - scribed. The Australian government is responsible for the “final defence” of Australian infrastructure and cybersecu - rity. To this end, the SOCI Act grants the Minister last resort “government assistance measures” and powers

17 CHAMBERS.COM

Page i Page 1 Page 2 Page 3 Page 4 Page 5 Page 6 Page 7 Page 8 Page 9 Page 10 Page 11 Page 12 Page 13 Page 14 Page 15 Page 16 Page 17 Page 18 Page 19 Page 20 Page 21 Page 22 Page 23 Page 24 Page 25 Page 26 Page 27 Page 28 Page 29 Page 30 Page 31 Page 32 Page 33 Page 34 Page 35 Page 36 Page 37 Page 38 Page 39 Page 40 Page 41 Page 42 Page 43 Page 44 Page 45 Page 46 Page 47 Page 48 Page 49 Page 50 Page 51 Page 52 Page 53 Page 54 Page 55 Page 56 Page 57 Page 58 Page 59 Page 60 Page 61 Page 62 Page 63 Page 64 Page 65 Page 66 Page 67 Page 68 Page 69 Page 70 Page 71 Page 72 Page 73 Page 74 Page 75 Page 76 Page 77 Page 78 Page 79 Page 80 Page 81 Page 82 Page 83 Page 84 Page 85 Page 86 Page 87 Page 88 Page 89 Page 90 Page 91 Page 92 Page 93 Page 94 Page 95 Page 96 Page 97 Page 98 Page 99 Page 100 Page 101 Page 102 Page 103 Page 104 Page 105 Page 106 Page 107 Page 108 Page 109 Page 110 Page 111 Page 112 Page 113 Page 114 Page 115 Page 116 Page 117 Page 118 Page 119 Page 120 Page 121 Page 122 Page 123 Page 124 Page 125 Page 126 Page 127 Page 128 Page 129 Page 130 Page 131 Page 132 Page 133 Page 134 Page 135 Page 136 Page 137 Page 138 Page 139 Page 140 Page 141 Page 142 Page 143 Page 144 Page 145 Page 146 Page 147 Page 148 Page 149 Page 150 Page 151 Page 152 Page 153 Page 154 Page 155 Page 156 Page 157 Page 158 Page 159 Page 160 Page 161 Page 162 Page 163 Page 164 Page 165 Page 166 Page 167 Page 168 Page 169 Page 170 Page 171 Page 172 Page 173 Page 174 Page 175 Page 176 Page 177 Page 178 Page 179 Page 180 Page 181 Page 182 Page 183 Page 184 Page 185 Page 186 Page 187 Page 188 Page 189 Page 190 Page 191 Page 192 Page 193 Page 194 Page 195 Page 196 Page 197 Page 198 Page 199

Powered by