- Supports collecting ransomware payment, demand, communications, incident impact, ABN, address, malware, vulnerability, and payment-method evidence in the payment-reporting lane.
"communications with the extorting entity"
Use this workflow when one Australian cyber issue may touch the Security of Critical Infrastructure Act 2018, the Cyber Security Act 2024 ransomware-payment rules, or the smart-device security standards.
Identify the responsible entity and critical-infrastructure asset first. Then decide whether Part 2B incident reporting, Part 2A risk-management evidence, Part 3 ransomware reporting, or smart-device compliance needs its own owner and record.
Structured answer sets in this page tree.
Cited legal and guidance references.
overlap triage starts by asking which legal stream the facts belong to. A for a may have SOCI register, risk-management-program, and cyber incident work. The same incident can also trigger Cyber Security Act reporting if a makes a payment or becomes aware that another entity made one on its behalf. A smart device raises a separate product-security question unless the device or service is also part of a critical-infrastructure asset.
Open the triage record with three yes-or-no lanes. Lane one is : is there a , a , and a Part 2, , or obligation? Lane two is Cyber Security Act Part 3: did a make, or become aware that another entity made on its behalf, a after a cyber security incident? Lane three is smart-device compliance: is the product a that the or knows, or could reasonably be expected to know, will be acquired in Australia by a ?
Do not merge the evidence packs. incident reporting, reporting, and smart-device statements of compliance answer different questions and may be handled by different owners even when the same event or product family triggered the review.
This workflow helps separate SOCI responsible-entity records, ransomware payment reports, smart-device statements of compliance, and review tasks in Sorena.
Turn the SOCI, ransomware, and smart-device lanes into scoped questions, owners, and evidence requests.
Use Research Copilot to answer follow-up questions with cited SOCI and Cyber Security Act source material.
Review asset scope, payment-reporting facts, smart-device evidence, and next compliance actions with Sorena.
The branch should start with the asset, not a generic organisation name. Section 12L identifies the separately for each asset class; it is not a single across-the-board test that can safely be reduced to whoever owns or operates the asset. Record the applicable asset provision and the person or organisation that provision designates.
Once the asset and are identified, check which obligation is in play. Part 2 concerns the Register of Critical Infrastructure Assets. concerns the critical infrastructure risk management program. concerns mandatory cyber incident reporting. The Application Rules are the source to check whether Part 2 or Part 2B applies to the relevant asset class.
For , use the 10 June 2026 compilation of the program rules. now apply to specified broadcasting, domain-name-system, electricity, energy-market-operator, freight, gas, liquid-fuel, and water assets. Section 4A gives existing covered assets 12 months from commencement for section 6A and specified parts of sections 8A and 9A, and 24 months for the other enhanced provisions; an asset that becomes critical infrastructure later receives the corresponding period from that date.
Treat a cyber incident report and a Cyber Security Act report as separate filings. Part 2B belongs to the SOCI critical-infrastructure stream. The Cyber Security Act Part 3 stream applies when the ransomware-payment conditions are met: a is impacted by a cyber security incident and provides, or becomes aware that another entity provided on its behalf, a payment or benefit to the extorting entity.
Start the clock from awareness of the qualifying impact on the covered asset: within 12 hours for a critical incident that materially disrupts essential goods or services, or within 72 hours for another incident with a relevant impact. Start the ransomware clock from the payment or awareness of an on-behalf payment. Build the ransomware record around what the knows or can find out by reasonable search or enquiry within that separate 72-hour period.
The smart-device branch is product compliance, not critical-infrastructure asset classification. Cyber Security Act Part 2 commenced on 29 November 2025, while Part 2 and Schedule 1 of the Smart Devices Rules, which contain the -grade standard and statement requirements, commenced on 4 March 2026. Use this branch for consumer grade relevant connectable products that can directly or indirectly connect to the internet when the or is aware, or could reasonably be expected to be aware, that a consumer will acquire the product in Australia, subject to the Rules' exclusions. The Rules set the binding scope test; the official explanatory statement gives smart TVs, smart watches, home assistants, baby monitors, and consumer energy resources as examples, but each product still needs its own connectivity, intended-use, acquisition, awareness, date, and exclusion analysis. A smart product used inside a critical-infrastructure environment may create operational risk evidence for , but the statement-of-compliance and security-standard evidence remain product records.
The Rules require a -prepared statement of compliance for covered products and set product-security evidence around passwords, reporting security issues, and defined support periods for security updates. Suppliers have their own supply-side check because the Rules outline when non-compliant products must not be supplied and when products must be supplied with the statement of compliance.
Keep the overlap triage record after the incident or product release. It should show why a lane was opened or closed, who owned it, which official source supported the decision, what evidence was reviewed, and which record remains authoritative for later audit or regulator questions.
Use a short matrix rather than a narrative memo. Each row should identify the lane, trigger fact, obligation checked, owner, evidence, source, decision, reviewer, and follow-up. Mark unknown facts as unknown and assign a collection owner instead of filling gaps with assumptions.
"communications with the extorting entity"
"prepared by, or on behalf of, the manufacturer"
"Security standards for smart devices"
"supply chain hazards"
"Application of Part 2B of the Act"
"Register of Critical Infrastructure Assets"