How does the Australia Cyber Security Act overlap with the Security of Critical Infrastructure Act?
The Cyber Security Act does not supersede the Security of Critical Infrastructure Act 2018 (SOCI Act). It imports SOCI concepts for a and a , and its ransomware payment reporting regime expressly covers a responsible entity for a critical infrastructure asset to which SOCI Act applies.
The same event can therefore require a Cyber Security Act ransomware payment report and a SOCI Act cyber security incident report. The triggers differ: the Cyber Security Act report follows a payment or benefit tied to an extortion demand, while SOCI reporting turns on the incident's impact on a covered asset. One report does not replace the other. For SOCI, a on availability uses the test in section 30BEA; other reportable incidents use the broader concept, which includes availability, integrity, reliability, and specified confidentiality impacts.
- Confirm whether the affected system is a under SOCI Act materials.
- Identify whether the organisation is the for that asset.
- If a ransomware payment was made by, or on behalf of, that entity, assess the Cyber Security Act ransomware report obligation alongside SOCI incident notification.
- Run the clocks separately: the ransomware payment report is due within 72 hours of payment or awareness of payment; a critical SOCI incident must be reported as soon as practicable and within 12 hours of awareness, while another reportable SOCI incident must be reported as soon as practicable and within 72 hours of awareness. If a critical-incident report is oral, provide the approved-form written record within 84 hours after the oral report. If another reportable-incident report is oral, provide its approved-form written record within 48 hours after the oral report. A written-record exemption may be given under the SOCI Act.
Defines critical infrastructure asset and responsible entity by reference to the SOCI Act and sets when responsible entities for Part 2B assets are reporting business entities.
Sections 30BB to 30BEA support Part 2B application, the 12-hour and 72-hour incident-notification duties, the 84-hour written record after an oral critical-incident report, the 48-hour written record after another oral reportable-incident report, the possible written-record exemptions, and the significant-impact test.
Application Rules source for checking whether SOCI Act Part 2 or Part 2B applies before treating the organisation as in the critical-infrastructure overlap path.