Cyber Security Act 2024: Legislative Updates and What You Need to Know
Summary
This blog post, "Cyber Security Act 2024: Legislative Updates and What You Need to Know", is a blueAPACHE article from 2025 covering security. Australia has traditionally been lagging the rest of the world when it comes to cyber security legislation. It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.
Key facts
| Label | Value |
|---|---|
| Publication year | 2025 |
| Topic | Cyber Security Act 2024: Legislative Updates and What You Need to Know |
| Services referenced | emPOWER Security, Managed Detection and Response, Governance, Risk and Compliance |
| Named products or vendors | None named beyond blueAPACHE |
| Cited statistic | Mandatory Ransomware Payment Reporting: Reporting requirements are enforced where a ransom has been paid to a threat actor for entities carrying on a business in Australia with a revenue over $3M. |
Article
Australia has traditionally been lagging the rest of the world when it comes to cyber security legislation. There continues to be the Notifiable Data Breaches scheme, which has been in place since February 2018, where data breaches of individuals personal information needs to be reported to the Office of the Australian Information Commissioner (OAIC) but only just recently we now have new legislation for Cyber. In November 2023 the Cyber Security Legislative Package was formed. The 2023-2030 Australian Cyber Security Strategy is the roadmap to realise the Australian Governments vision of becoming world leader in cyber security by 2030. As part of this strategy, on the 29 November 2024, the Cyber Security Act 2024 received Royal Assent and became Law.
What You Need to Know
- Ensure Cyber Security Standards For Smart Devices Are Set: Manufacturers and suppliers of smart devices in Australia must ensure that the devices meet specified security standards relevant for that product. This will involve a statement of compliance to be provided to the regulator.
The regulator may then conduct testing to verify the statement of compliance and if there is a failure to comply the regulator may publish a notice in the public domain which could cause reputational damage.
- Mandatory Ransomware Payment Reporting: Reporting requirements are enforced where a ransom has been paid to a threat actor for entities carrying on a business in Australia with a revenue over $3M.
The report must be made within 72 hours of the ransomware payment being made, the entity making the payment is liable irrespective of how the attack occurred, even via a third-party organisation.
- Limited Use for the National Cyber Security Coordinator: This component of the Cyber Security Act establishes a limited use obligation on the National Cyber Security Coordinator to provide confidence that the information shared by affected businesses without fear of the information being provided to regulators or law enforcement for use in regulatory or law enforcement proceedings, unless the affected businesses have committed a criminal offense.
- Cyber Incident Review Board: The establishment of an Independent Statutory Advisory Body that will conduct no-fault, post-incident reviews of significant cyber security incidents in Australia to make recommendations to the government on actions to prevent, detect, respond to or minimise the impact of similar cyber security incidents in the future.
How to Protect Your Organisation
- Regular Cyber Risk Assessments: Identify vulnerabilities through comprehensive assessments to stay ahead of potential threats and ensure mitigation strategies are up to date.
- Strong Incident Response Plans: A clear, tested incident response strategy can turn a potential crisis into a manageable situation, reducing both impact and cost.
- Keep Software and Systems Updated: Regularly update all software and systems to protect against known vulnerabilities. This includes applying patches and updates as soon as they are available.
- Threat Intelligence: Ensure the collection, analysis, and application of information about potential and existing cyber threats. This helps organisations anticipate, detect, and respond to cyber threats more effectively.
- **Understand your 3 rd party – and Supply Chain Risks: **Third-party relationships may provide threat actors with an easier pathway into an organisation’s systems and networks. Vetting those supply chain partner’s cyber security resiliency and capability, including through their assurance of identity and access management, governance and risk management, and information asset management, will help understand any partner / supplier weaknesses and potential risk vectors.
What Happens If You Don’t Act
Failing to meet legislated expectations can expose your organisation to regulatory and legal risks, with potential fines and severe reputational damage. Customers and stakeholders expect robust data protection, and any failure in this area can significantly tarnish your brand’s credibility. It is important to recognise that any information contained in this document, or the links shared are general in nature and does not constitute legal advice. Readers are encouraged to obtain legal advice that applies to their particular circumstances.
How blueAPACHE Can Support You
At blueAPACHE, we support our clients by helping to build a robust risk management framework which adequately addresses its security risk, and ensures controls are implemented to protect our client’s key assets, thereby enhancing their cyber resilience. blueAPACHE helps our clients with scenario-based simulations to assess response processes and recovery with gaps identified for improvement and remediation. Complimenting this our ISO27001-certified practices across our entire emPOWER portfolio, ensures that our infrastructure meets the highest standards of information security. This certification demonstrates our commitment to maintaining rigorous cybersecurity measures and helps you align with compliance requirements. Our vCISO (Virtual Chief Information Security Officer) capability provides a cost-effective, strategic oversight tailored to your organisation’s needs. This service ensures you remain compliant, resilient, and prepared to navigate today’s complex regulatory landscape. For further assistance or to discuss your cybersecurity needs, please reach out to us here.
Related
- emPOWER Security
- emPOWER Security (pillar hub)
- Managed Detection and Response
- Governance, Risk and Compliance
- blueAPACHE Security (case study)
Frequently asked questions
When did the Cyber Security Act 2024 receive Royal Assent?
29 November 2024, as part of the Cyber Security Legislative Package formed in November 2023 under the 2023-2030 Australian Cyber Security Strategy.
What is the revenue threshold that triggers mandatory ransomware payment reporting?
The article states reporting requirements are enforced where a ransom has been paid to a threat actor for entities carrying on a business in Australia with a revenue over $3 million.
Within what timeframe must a ransomware payment be reported?
The report must be made within 72 hours of the ransomware payment being made, and the entity making the payment is liable irrespective of how the attack occurred, even via a third-party organisation.
What obligation does the Act place on smart device manufacturers and suppliers?
Manufacturers and suppliers of smart devices in Australia must ensure devices meet specified security standards and provide a statement of compliance to the regulator, who may test and publish a non-compliance notice.
What is the role of the Cyber Incident Review Board described in the article?
It is an Independent Statutory Advisory Body that conducts no-fault, post-incident reviews of significant cyber security incidents in Australia and makes recommendations to government on preventing, detecting, responding to or minimising similar future incidents.
What "limited use" protection does the Act give the National Cyber Security Coordinator function?
It establishes a limited use obligation so information shared by affected businesses is not passed to regulators or law enforcement for regulatory or law enforcement proceedings, unless the business has committed a criminal offense.
What legislation preceded the Cyber Security Act 2024 for personal data breach reporting?
The Notifiable Data Breaches scheme, in place since February 2018, under which data breaches of individuals' personal information must be reported to the Office of the Australian Information Commissioner (OAIC).
What does blueAPACHE say it offers clients in relation to this legislation?
The article says blueAPACHE helps clients build a risk management framework, runs scenario-based simulations to assess response and recovery, holds ISO27001-certified practices across its emPOWER portfolio, and offers a vCISO (Virtual Chief Information Security Officer) capability for strategic compliance oversight.
Source
- origin post (2025)
Knowledge Base
When did the Cyber Security Act 2024 receive Royal Assent and become law in Australia?
The Cyber Security Act 2024 received Royal Assent and became law on 29 November 2024, as part of the Cyber Security Legislative Package formed in November 2023.
What is the 2023-2030 Australian Cyber Security Strategy?
The 2023-2030 Australian Cyber Security Strategy is the roadmap to realise the Australian Government's vision of becoming a world leader in cyber security by 2030. The Cyber Security Act 2024 is part of this strategy.
What are the cyber security standards requirements for smart devices under the Cyber Security Act 2024?
Manufacturers and suppliers of smart devices in Australia must ensure their devices meet specified security standards relevant to that product, and must provide a statement of compliance to the regulator. The regulator may test to verify the statement, and if there is a failure to comply, the regulator may publish a notice in the public domain, which could cause reputational damage.
What are the mandatory ransomware payment reporting requirements under the Cyber Security Act 2024?
Entities carrying on a business in Australia with revenue over $3M are required to report ransomware payments made to a threat actor. The report must be made within 72 hours of the payment, and the entity making the payment is liable regardless of how the attack occurred, even if it happened via a third-party organisation.
What is the 'limited use' obligation for the National Cyber Security Coordinator under the Cyber Security Act 2024?
This component establishes a limited use obligation on the National Cyber Security Coordinator, giving confidence to affected businesses that information they share won't be provided to regulators or law enforcement for regulatory or law enforcement proceedings, unless the affected business has committed a criminal offense.
What is the Cyber Incident Review Board established under the Cyber Security Act 2024?
The Cyber Incident Review Board is an Independent Statutory Advisory Body established to conduct no-fault, post-incident reviews of significant cyber security incidents in Australia. It makes recommendations to the government on actions to prevent, detect, respond to, or minimise the impact of similar cyber security incidents in the future.
What steps does the article recommend organisations take to protect themselves under the new legislation?
The article recommends: conducting regular cyber risk assessments to identify vulnerabilities; developing strong, tested incident response plans; keeping software and systems updated with patches; maintaining threat intelligence to anticipate and detect threats; and understanding third-party and supply chain risks by vetting partners' cyber security resiliency, including identity and access management, governance, risk management, and information asset management.
What are the consequences of failing to meet the Cyber Security Act 2024's legislated expectations?
Failing to meet legislated expectations can expose an organisation to regulatory and legal risks, including potential fines and severe reputational damage, and can significantly tarnish a brand's credibility due to customer and stakeholder expectations of robust data protection.
How does blueAPACHE support clients in complying with the Cyber Security Act 2024?
blueAPACHE helps clients build a robust risk management framework to address security risk and implement controls protecting key assets. It offers scenario-based simulations to assess response processes and recovery, maintains ISO27001-certified practices across its emPOWER portfolio, and provides a vCISO (Virtual Chief Information Security Officer) capability for cost-effective, strategic oversight to ensure compliance and resilience.
What data breach reporting scheme has been in place in Australia since before the Cyber Security Act 2024, and what does it require?
The Notifiable Data Breaches scheme has been in place since February 2018, requiring that data breaches involving individuals' personal information be reported to the Office of the Australian Information Commissioner (OAIC).
Images on This Page
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a6ffec7d87be5a881637bba_31b5a84971e1d1ce71dc99ca059bfbde_blueAPACHE.svg
blueAPACHE logo on a dark blue background
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bba07b7741bf53e29c4_bA-Branded-Images-9.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a713402a5a7f7ebf553f0bf_Background-Top.avif
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701b59b153d68a8eeb0e36_BBanner-1-Windows-10-is-out.-AI-is-in.-.avif
You’ve Invest in Security. So Why Are Breaches Still Happening?
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb807b7741bf53e298a_BBanner-1-Windows-10-is-out.-AI-is-in.-8.avif
EOFY 2026: The Reset Is Done – Now It’s About Getting Ahead
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d0_BBanner-2-When-support-ends-risk-begins-4.avif
Why Every Business Needs AI Guardrails
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbb07b7741bf53e29d7_BBanner-2-When-support-ends-risk-begins-3.avif
Ransomware Incident Response: Why Paying the Ransom Is a Failure of Preparation
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bb707b7741bf53e297d_BBanner-2-When-support-ends-risk-begins-1.avif
The 7 Cyber Truths Boards Must Act On In 2026
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29f9_BBanner-1-Windows-10-is-out.-AI-is-in.-7.avif
Reflecting on an Outstanding 2025 – Thank You for Your Partnership
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e2a0c_Procurement-Portal.avif
The blueAPACHE e-Store: IT purchasing made simple
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a701bbc07b7741bf53e29ec_BBanner-1-Windows-10-is-out.-AI-is-in.-5.avif
Building Our Cyber Safe Culture: A Practical Guide for CSAM 2025
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fbfad31fa678fefd51a_6a704f395a0a01b8e482853a_support-monitor.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4563e_6a704f3a400fc8e661400519_support-user.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45639_6a704f3a91ffd7d0dbc40847_support-phone.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc4562f_6a704f3747d60bd3f65b7a31_support-globe.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45636_6a704f38eb60992797acf5d9_support-mail.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a70181278f802e23979d547/6a704fd991ffd7d0dbc45633_6a704f3a07b7741bf54f2122_support-speech-bubble.svg
(no alt text)
-
https://cdn.prod.website-files.com/6a6ffec7d87be5a881637bb3/6a707520ca872d1b5a69a518_Sensiba.avif
Sensiba ISO/IEC 27001 Certified badge with a diamond-shaped logo below the text.