We’ve consistently heard that Australian businesses and citizens need clearer advice on how to respond to ransom demands. As a next step, the Government will build a ransomware playbook. This playbook will provide clear guidance to businesses and citizens on how to prepare for, deal with, and bounce back from ransom demands. 3. Drive global counter-ransomware operations We will continue to work with our international partners to drive the CRI and lead global cooperation to break the ransomware business model. Australia will take a leadership role to drive international action to fight back against the threat, starting with our role as Chair of the International Counter Ransomware Taskforce. Under the CRI, we are working with 50 international partners to execute counter-ransomware operations. The Australian Government will continue working with CRI members to strongly discourage anyone from paying a ransomware demand. The Government will also continue its efforts to regulate the use of cryptocurrencies. The Attorney-General’s Department is consulting on major reforms of Australia’s anti-money laundering and counter-terrorism financing laws, including their application to transactions involving digital currencies. Separately, the Department of the Treasury is consulting industry on defining digital asset types and seeking to identify gaps in the current regulatory framework in relation to digital currencies. 5 Provide clear cyber guidance for businesses The problem we face Cyber security is not just good practice; it’s good business. A clear understanding of how to manage cyber risks is essential for Australian businesses embracing the digital economy. Many cyber risks could be mitigated by better corporate governance from the board down. Businesses already have existing obligations to protect their businesses from risk. These obligations include protecting their businesses and customers from cyber attacks. But many expectations of cyber governance are unclear, and there is scope to identify gaps in the current suite of cyber obligations. Industry feedback has flagged that more could be done to help businesses understand what good cyber security looks like. When a major incident occurs, it is important that we understand the vulnerabilities that led to the malicious attack – and share lessons learned with industry to enhance future cyber readiness. The Government must enable the efficient and well-targeted delivery of appropriate guidance to industry to ensure identified vulnerabilities are not further exploited. 2023–2030 Australian Cyber Security Strategy 23

Select target paragraph3