How the Government will take action The Australian Government will work with industry to ensure cyber security is appropriately considered in the boardroom, informed by clear guidance on cyber best-practice and lessons learned from previous cyber incidents. Under this initiative, the Government will: 1. Clarify business expectations of cyber governance The Government will consider how best to provide additional information on cyber security guidance for businesses to help them navigate important obligations and requirements that should be considered when developing cyber security frameworks. As a first step, the Government will publish an overview of corporate obligations for critical infrastructure owners and operators. Next, the Government will consider how best to collaborate with industry to design best-practice principles to guide good cyber governance. Initiatives in this space would aim to be principles-based, technology neutral and applicable to a range of organisations, regardless of their cyber maturity. It will build on existing resources available through the Australian Institute of Company Directors, Australian Information Security Association, Australian Securities and Investments Commission, ASD’s Australian Cyber Security Centre (ACSC), the National Anti-Scam Centre, and the Cyber Security Cooperative Research Centre. 2. Share lessons learned from cyber incidents The Government will establish a new process for conducting lessons-learned reviews of significant cyber incidents. We will work with industry to establish a new Cyber Incident Review Board, drawing on international and domestic models, including the United States Cyber Safety Review Board and the Australian Transport Safety Bureau. Following major cyber incidents, this no-fault post-incident review mechanism will seek to uplift collective cyber security, boosting our ability to hone incident preparation and response. The proposed review mechanism will not make findings of fault and will not interfere with incident response or regulatory, intelligence or law enforcement functions. Lessons learned from these reviews will be shared with the business community and the wider public. Insights on cyber best-practice will be fed into our national threat intelligence sharing and blocking networks, our cyber awareness programs, national cyber exercises and other initiatives to continue to improve our national cyber resilience. 24 2023–2030 Australian Cyber Security Strategy

Select target paragraph3