How we’ll get there
To achieve our 2030 vision, the Australian Government will:
• clarify the scope of critical infrastructure regulation;
• strengthen cyber security obligations and compliance for critical infrastructure;
• uplift cyber security of the Commonwealth Government; and
• pressure-test our critical infrastructure to identify vulnerabilities.
13
Clarify the scope of critical
infrastructure regulation
The problem we face
Australians must have confidence in the security and resilience of critical infrastructure sectors to
deliver essential goods and services. Telecommunications and financial services should be
resilient to major disruptions and external hazards. Energy, water and healthcare services, as well
as food and grocery providers, should be available when we need them. Australians should not
have to worry about suffering from the consequences of a cyber attack on unsecured critical
infrastructure providers or their supply chains.
The SOCI Act provides a robust framework for defining and regulating the cyber security
obligations for critical infrastructure. However, recent incidents have identified gaps in our cyber
security regulation where it does not sufficiently cover specific sectors, entities or assets. In some
cases, there are multiple regulatory frameworks that cover the same type of entity, creating
unnecessary duplication and complexity. In other cases, obligations are unclear or some entities
are not held to consistent cyber security standards.
How the Government will take action
The Australian Government will continue consultation with industry to ensure that our world
leading critical infrastructure laws remain fit for purpose.
Under this initiative, the Government will:
1. Ensure we are protecting the right entities
The Government will work with industry to move the security regulation of the telecommunications
sector from the Telecommunications Sector Security Reforms (TSSR) in the Telecommunications
Act 1997 to the SOCI Act. This will better align obligations for critical infrastructure entities that
span multiple sectors, reduce regulatory duplication and complexity, and provide scalable
obligations for the telecommunications sector.
The Government will also seek to clarify cyber security obligations for managed service providers,
aligning closely with data protection initiatives established under Shield 2. Together, these
initiatives will complement the protections and obligations for personal information established
by the Privacy Act and action taken by the Government to strengthen individuals’ trust in the
management and storage of personal data.
40
2023–2030 Australian Cyber Security Strategy