The Government will explore options to incorporate cyber security regulation into ‘all hazards’ requirements for the aviation and maritime sectors. The Government will develop a reform agenda to strengthen Australia’s aviation, maritime and offshore facility security settings, including positive obligations to proactively manage cyber-related risks under existing legislation. This will include stronger cyber security obligations on aviation, maritime and offshore facility regulated entities, including other critical infrastructure that enables international transport and shipping routes. 2. Ensure we are protecting the right assets Government will also consult with industry to clarify the application of the SOCI Act to ensure critical infrastructure entities are adequately protecting their data storage systems. This consultation will focus on ‘business-critical’ data storage systems where vulnerabilities could impact the availability, integrity, reliability or confidentiality of critical infrastructure assets. 14 Strengthen cyber security obligations and compliance for critical infrastructure The problem we face Our critical infrastructure must be resilient to cyber threats in the face of heightened geopolitical risk, capable nation-state actors, and sophisticated cybercriminals. Cyber incidents affecting critical infrastructure entities may cause cascading impacts across the Australian economy due to our heavy reliance on their services. Systems of National Significance are systems that would cause disproportionate damage to Australia’s economy or national security if they were subjected to a cyber attack. To reduce the risk of major disruptions to our communities and businesses, these systems need to be able to withstand large-scale cyber attacks. When cyber attacks are launched against our critical infrastructure and government systems, we must bounce back by responding and recovering quickly. However, responding to a cyber incident is not just about the technical event. Government and industry also need to work together to appropriately manage the ongoing consequences of a cyber attack. Following recent cyber incidents, critical infrastructure entities have called for better government support to help manage the ongoing impacts of an incident. 2023–2030 Australian Cyber Security Strategy 41

Select target paragraph3