Reporting requirements are changing for federal critical infrastructure. Are you ready?

Under new legislation amendments, major operators of certain pieces of infrastructure will be required to report cyber threat activity and provide ownership details to the Australian Cyber Security Centre (ACSC). These amendments to the Security of Critical Infrastructure Act 2018 (the SOCI Act) came into effect on 8th April 2022. While a three-month grace period is currently in place for businesses that are not yet ready to fulfil these new reporting requirements, mandatory reporting will be required under the legislation from 8th July 2022. The industries impacted by these changes include:
  • broadcasting 
  • domain name systems 
  • data storage or processing banking 
  • hospital 
  • education 
  • freight infrastructure 
  • freight services 
  • public transport 
  • liquid fuel 
  • energy market operator 
  • aviation, that is any of the following: 
  • a designated airport 
  • an Australian prescribed air service operating screened air services that depart from a designated airport, or 
  • a regulated air cargo agent that is also a cargo terminal operator at a designated airport 
Another bill, the Security Legislation Amendment (Critical Infrastructure Protection) Bill 2022 is currently before the senate, and introduces further security measures and requirements for Australia’s critical infrastructure assets to comply with. The bill passed the House of Representatives on 16th February 2022 and is currently under review by the Parliamentary Joint Committee on Intelligence and Security. The second bill will:
  • introduce an additional Positive Security Obligation, the Risk Management Program, which will be applied to entities responsible for critical infrastructure. 
  • ​introduce Enhanced Cyber Security Obligations, including vulnerability reporting, cyber incident response planning and exercises, for entities responsible for assets most critical to the nation (known as systems of national significance). 
The Risk Management Program creates a mandatory requirement for owners and operators of critical infrastructure to have cyber risk management systems in place, whereas the Enhanced Cyber Security Obligations will provide obligations for exercising, reporting vulnerability with government and being subject to audit.
The second bill will not pass parliament before the election, but will likely become law in the near future. This, along with the new mandatory cyber incident reporting requirements will likely catch many operators off guard if they are not already aware of the changes. Is your business ready? Don’t leave it until the last minute. Put your business in the safest hands possible, and see how our experienced and knowledgeable team can help your business in this constantly changing world.

Talk to Australia’s Crisis & Emergency Management Specialists

Whether you’re strengthening preparedness, meeting regulatory obligations, enhancing crisis capability, or planning exercises and training, our expert team is here to help.

We work with organisations across Australia to design and deliver practical solutions in:

Emergency management & disaster management
✔ Warden & Part 7A exercise support
Crisis management and leadership capability
Business continuity and disaster recovery planning
Risk mitigation and compliance alignment
Emergency exercises and simulations
Tailored training and capability building
Critical infrastructure resilience

Telephone: 03 9003 9370

info@resilientservices.com.au

 

Tell us a little about your organisation, your risks, and your resilience objectives, and we’ll connect you with the right specialist to support your needs.

"*" indicates required fields

Want to join us?

Resilient Services is always looking for more brilliant people to join our growing business. Do you want to join our exceptional team? Get in touch, and tell us about yourself at info@resilientservices.com.au.

Stay updated

EOFY Business Resilience Review

AS 3745 Warden & Chief Warden Training

Disaster Recovery Planning Services for Australian Organisations

Types of Disruptions Organisations Face — And Why Planning Ahead Is Critical

What to Expect From an Emergency Exercise or Simulation

ISO 22301 Explained: Building a Strong Business Continuity Management System