How the Government will take action
The Australian Government will work with industry to ensure cyber security is appropriately
considered in the boardroom, informed by clear guidance on cyber best-practice and lessons
learned from previous cyber incidents.
Under this initiative, the Government will:
1. Clarify business expectations of cyber governance
The Government will consider how best to provide additional information on cyber security
guidance for businesses to help them navigate important obligations and requirements that
should be considered when developing cyber security frameworks. As a first step, the Government
will publish an overview of corporate obligations for critical infrastructure owners and operators.
Next, the Government will consider how best to collaborate with industry to design best-practice
principles to guide good cyber governance.
Initiatives in this space would aim to be principles-based, technology neutral and applicable
to a range of organisations, regardless of their cyber maturity. It will build on existing resources
available through the Australian Institute of Company Directors, Australian Information
Security Association, Australian Securities and Investments Commission, ASD’s Australian
Cyber Security Centre (ACSC), the National Anti-Scam Centre, and the Cyber Security
Cooperative Research Centre.
2. Share lessons learned from cyber incidents
The Government will establish a new process for conducting lessons-learned reviews of
significant cyber incidents. We will work with industry to establish a new Cyber Incident
Review Board, drawing on international and domestic models, including the United States
Cyber Safety Review Board and the Australian Transport Safety Bureau.
Following major cyber incidents, this no-fault post-incident review mechanism will seek to
uplift collective cyber security, boosting our ability to hone incident preparation and response.
The proposed review mechanism will not make findings of fault and will not interfere with
incident response or regulatory, intelligence or law enforcement functions.
Lessons learned from these reviews will be shared with the business community and the wider
public. Insights on cyber best-practice will be fed into our national threat intelligence sharing
and blocking networks, our cyber awareness programs, national cyber exercises and other
initiatives to continue to improve our national cyber resilience.
24
2023–2030 Australian Cyber Security Strategy