Australia’s first standalone cyber security legislation, the Cyber Security Act 2024, has been passed into law. The law requires applicable businesses to report ransom payments to the Department of Home Affairs and the Australian Signals Directorate within 72 hours. Failure to comply may result in penalties of about $94,000. The reporting requirements will commence at latest six months after the act receives royal assent.
The legislation aims to increase collaboration between government agencies and businesses when responding to cyber incidents. A Cyber Incident Review Board will conduct no-fault post-incident reviews of major cyber security incidents in Australia. The board will make recommendations to aid in prevention, detection, response, and minimization of future incidents. The Act also introduces mandatory cyber security standards for Internet of Things (IoT) devices.