Cyber Security Act 2024: Legislative Updates and What You Need to Know

Summary

This blog post, "Cyber Security Act 2024: Legislative Updates and What You Need to Know", is a blueAPACHE article from 2025 covering security. Australia has traditionally been lagging the rest of the world when it comes to cyber security legislation. It is written for readers evaluating emPOWER Security, Managed Detection and Response. The underlying security practice it describes, reducing attack surface and improving detection and response, is not tied to a specific product version and remains relevant to any organisation managing cyber risk today.

Key facts

Label Value
Publication year 2025
Topic Cyber Security Act 2024: Legislative Updates and What You Need to Know
Services referenced emPOWER Security, Managed Detection and Response, Governance, Risk and Compliance
Named products or vendors None named beyond blueAPACHE
Cited statistic Mandatory Ransomware Payment Reporting: Reporting requirements are enforced where a ransom has been paid to a threat actor for entities carrying on a business in Australia with a revenue over $3M.

Article

Australia has traditionally been lagging the rest of the world when it comes to cyber security legislation. There continues to be the Notifiable Data Breaches scheme, which has been in place since February 2018, where data breaches of individuals personal information needs to be reported to the Office of the Australian Information Commissioner (OAIC) but only just recently we now have new legislation for Cyber. In November 2023 the Cyber Security Legislative Package was formed. The 2023-2030 Australian Cyber Security Strategy is the roadmap to realise the Australian Governments vision of becoming world leader in cyber security by 2030. As part of this strategy, on the 29 November 2024, the Cyber Security Act 2024 received Royal Assent and became Law.

What You Need to Know

The regulator may then conduct testing to verify the statement of compliance and if there is a failure to comply the regulator may publish a notice in the public domain which could cause reputational damage.

The report must be made within 72 hours of the ransomware payment being made, the entity making the payment is liable irrespective of how the attack occurred, even via a third-party organisation.

How to Protect Your Organisation

What Happens If You Don’t Act

Failing to meet legislated expectations can expose your organisation to regulatory and legal risks, with potential fines and severe reputational damage. Customers and stakeholders expect robust data protection, and any failure in this area can significantly tarnish your brand’s credibility. It is important to recognise that any information contained in this document, or the links shared are general in nature and does not constitute legal advice. Readers are encouraged to obtain legal advice that applies to their particular circumstances.

How blueAPACHE Can Support You

At blueAPACHE, we support our clients by helping to build a robust risk management framework which adequately addresses its security risk, and ensures controls are implemented to protect our client’s key assets, thereby enhancing their cyber resilience. blueAPACHE helps our clients with scenario-based simulations to assess response processes and recovery with gaps identified for improvement and remediation. Complimenting this our ISO27001-certified practices across our entire emPOWER portfolio, ensures that our infrastructure meets the highest standards of information security. This certification demonstrates our commitment to maintaining rigorous cybersecurity measures and helps you align with compliance requirements. Our vCISO (Virtual Chief Information Security Officer) capability provides a cost-effective, strategic oversight tailored to your organisation’s needs. This service ensures you remain compliant, resilient, and prepared to navigate today’s complex regulatory landscape. For further assistance or to discuss your cybersecurity needs, please reach out to us here.

Related

Frequently asked questions

When did the Cyber Security Act 2024 receive Royal Assent?

29 November 2024, as part of the Cyber Security Legislative Package formed in November 2023 under the 2023-2030 Australian Cyber Security Strategy.

What is the revenue threshold that triggers mandatory ransomware payment reporting?

The article states reporting requirements are enforced where a ransom has been paid to a threat actor for entities carrying on a business in Australia with a revenue over $3 million.

Within what timeframe must a ransomware payment be reported?

The report must be made within 72 hours of the ransomware payment being made, and the entity making the payment is liable irrespective of how the attack occurred, even via a third-party organisation.

What obligation does the Act place on smart device manufacturers and suppliers?

Manufacturers and suppliers of smart devices in Australia must ensure devices meet specified security standards and provide a statement of compliance to the regulator, who may test and publish a non-compliance notice.

What is the role of the Cyber Incident Review Board described in the article?

It is an Independent Statutory Advisory Body that conducts no-fault, post-incident reviews of significant cyber security incidents in Australia and makes recommendations to government on preventing, detecting, responding to or minimising similar future incidents.

What "limited use" protection does the Act give the National Cyber Security Coordinator function?

It establishes a limited use obligation so information shared by affected businesses is not passed to regulators or law enforcement for regulatory or law enforcement proceedings, unless the business has committed a criminal offense.

What legislation preceded the Cyber Security Act 2024 for personal data breach reporting?

The Notifiable Data Breaches scheme, in place since February 2018, under which data breaches of individuals' personal information must be reported to the Office of the Australian Information Commissioner (OAIC).

What does blueAPACHE say it offers clients in relation to this legislation?

The article says blueAPACHE helps clients build a risk management framework, runs scenario-based simulations to assess response and recovery, holds ISO27001-certified practices across its emPOWER portfolio, and offers a vCISO (Virtual Chief Information Security Officer) capability for strategic compliance oversight.

Source

Knowledge Base

When did the Cyber Security Act 2024 receive Royal Assent and become law in Australia?

The Cyber Security Act 2024 received Royal Assent and became law on 29 November 2024, as part of the Cyber Security Legislative Package formed in November 2023.

What is the 2023-2030 Australian Cyber Security Strategy?

The 2023-2030 Australian Cyber Security Strategy is the roadmap to realise the Australian Government's vision of becoming a world leader in cyber security by 2030. The Cyber Security Act 2024 is part of this strategy.

What are the cyber security standards requirements for smart devices under the Cyber Security Act 2024?

Manufacturers and suppliers of smart devices in Australia must ensure their devices meet specified security standards relevant to that product, and must provide a statement of compliance to the regulator. The regulator may test to verify the statement, and if there is a failure to comply, the regulator may publish a notice in the public domain, which could cause reputational damage.

What are the mandatory ransomware payment reporting requirements under the Cyber Security Act 2024?

Entities carrying on a business in Australia with revenue over $3M are required to report ransomware payments made to a threat actor. The report must be made within 72 hours of the payment, and the entity making the payment is liable regardless of how the attack occurred, even if it happened via a third-party organisation.

What is the 'limited use' obligation for the National Cyber Security Coordinator under the Cyber Security Act 2024?

This component establishes a limited use obligation on the National Cyber Security Coordinator, giving confidence to affected businesses that information they share won't be provided to regulators or law enforcement for regulatory or law enforcement proceedings, unless the affected business has committed a criminal offense.

What is the Cyber Incident Review Board established under the Cyber Security Act 2024?

The Cyber Incident Review Board is an Independent Statutory Advisory Body established to conduct no-fault, post-incident reviews of significant cyber security incidents in Australia. It makes recommendations to the government on actions to prevent, detect, respond to, or minimise the impact of similar cyber security incidents in the future.

What steps does the article recommend organisations take to protect themselves under the new legislation?

The article recommends: conducting regular cyber risk assessments to identify vulnerabilities; developing strong, tested incident response plans; keeping software and systems updated with patches; maintaining threat intelligence to anticipate and detect threats; and understanding third-party and supply chain risks by vetting partners' cyber security resiliency, including identity and access management, governance, risk management, and information asset management.

What are the consequences of failing to meet the Cyber Security Act 2024's legislated expectations?

Failing to meet legislated expectations can expose an organisation to regulatory and legal risks, including potential fines and severe reputational damage, and can significantly tarnish a brand's credibility due to customer and stakeholder expectations of robust data protection.

How does blueAPACHE support clients in complying with the Cyber Security Act 2024?

blueAPACHE helps clients build a robust risk management framework to address security risk and implement controls protecting key assets. It offers scenario-based simulations to assess response processes and recovery, maintains ISO27001-certified practices across its emPOWER portfolio, and provides a vCISO (Virtual Chief Information Security Officer) capability for cost-effective, strategic oversight to ensure compliance and resilience.

What data breach reporting scheme has been in place in Australia since before the Cyber Security Act 2024, and what does it require?

The Notifiable Data Breaches scheme has been in place since February 2018, requiring that data breaches involving individuals' personal information be reported to the Office of the Australian Information Commissioner (OAIC).

Images on This Page