How we’ll get there To achieve our 2030 vision, the Australian Government will: • clarify the scope of critical infrastructure regulation; • strengthen cyber security obligations and compliance for critical infrastructure; • uplift cyber security of the Commonwealth Government; and • pressure-test our critical infrastructure to identify vulnerabilities. 13 Clarify the scope of critical infrastructure regulation The problem we face Australians must have confidence in the security and resilience of critical infrastructure sectors to deliver essential goods and services. Telecommunications and financial services should be resilient to major disruptions and external hazards. Energy, water and healthcare services, as well as food and grocery providers, should be available when we need them. Australians should not have to worry about suffering from the consequences of a cyber attack on unsecured critical infrastructure providers or their supply chains. The SOCI Act provides a robust framework for defining and regulating the cyber security obligations for critical infrastructure. However, recent incidents have identified gaps in our cyber security regulation where it does not sufficiently cover specific sectors, entities or assets. In some cases, there are multiple regulatory frameworks that cover the same type of entity, creating unnecessary duplication and complexity. In other cases, obligations are unclear or some entities are not held to consistent cyber security standards. How the Government will take action The Australian Government will continue consultation with industry to ensure that our world leading critical infrastructure laws remain fit for purpose. Under this initiative, the Government will: 1. Ensure we are protecting the right entities The Government will work with industry to move the security regulation of the telecommunications sector from the Telecommunications Sector Security Reforms (TSSR) in the Telecommunications Act 1997 to the SOCI Act. This will better align obligations for critical infrastructure entities that span multiple sectors, reduce regulatory duplication and complexity, and provide scalable obligations for the telecommunications sector. The Government will also seek to clarify cyber security obligations for managed service providers, aligning closely with data protection initiatives established under Shield 2. Together, these initiatives will complement the protections and obligations for personal information established by the Privacy Act and action taken by the Government to strengthen individuals’ trust in the management and storage of personal data. 40 2023–2030 Australian Cyber Security Strategy

Select target paragraph3