6
Make it easier for Australian businesses to access
advice and support after a cyber incident
The problem we face
When a cyber incident occurs, every moment matters. Rapid response will increase the chances
of timely recovery and help Australian businesses bounce back quickly. However, industry have
flagged barriers that make it challenging to get help after a cyber incident.
Australia’s current regulatory reporting requirements for cyber incidents are complex. Businesses
often need to report an incident to multiple regulators, depending on their sector, the nature of
the incident, and the severity of the consequences. These obligations serve an important
purpose, but they must not hinder the capacity of business leaders to respond to an incident.
Additionally, industry are increasingly reluctant to share detailed and timely cyber incident
information with ASD. Businesses are concerned that the information they share could be used for
regulatory action. Such reluctance can limit the Government’s capacity to offer support during an
incident, and it reduces our understanding of the national threat picture.
Industry has also flagged difficulties when engaging incident response firms. There is lack of clarity
around professional standards for incident response providers, leading to inconsistent service
quality. Without rapid and high-quality support, incidents can grow in scale and cause
devastating consequences for Australian businesses and citizens.
How the Government will take action
The Australian Government has already taken steps by appointing the Cyber Coordinator to
lead the coordination and triaging of government action in response to a major cyber incident.
Building on this, the Government will put measures in place to ensure industry is supported as
effectively as possible during a cyber incident.
Under this initiative, the Government will:
1. Simplify incident reporting
Through Project REDSPICE, the Government is already enhancing cyber security incident
reporting through its one-stop shop at cyber.gov.au. To help industry navigate mandatory cyber
incident reporting obligations, the Government has developed a single reporting portal on
cyber.gov.au that brings key reporting links together in one place.
As a next step, the Government will explore options to make it easier for businesses to meet their
regulatory obligations, which may include potential regulatory change or form simplification.
2023–2030 Australian Cyber Security Strategy
25