Schedule 1 Security of critical infrastructure Part 1 General amendments (d) if the Minister is aware that an entity is the responsible entity for an asset that is, or is proposed to be, specified in the rules: (i) give the entity a copy of the draft rules or amendments; and (ii) if a submission is received from the entity within the 28-day period mentioned in paragraph (a)—give the entity a written statement that sets out the Minister’s response to the submission. 30BC Notification of critical cyber security incidents (1) If: (a) an entity is the responsible entity for a critical infrastructure asset; and (b) the entity becomes aware that: (i) a cyber security incident has occurred or is occurring; and (ii) the incident has had, or is having, a significant impact (whether direct or indirect) on the availability of the asset; the entity must: (c) give the relevant Commonwealth body (see section 30BF) a report that: (i) is about the incident; and (ii) includes such information (if any) as is prescribed by the rules; and (d) do so as soon as practicable, and in any event within 12 hours, after the entity becomes so aware. Civil penalty: 50 penalty units. Form of report etc. (2) A report under subsection (1) may be given: (a) orally; or (b) in writing. (3) If a report under subsection (1) is given orally, the entity must: (a) do both of the following: 56 Security Legislation Amendment (Critical Infrastructure) Act 2021 Authorised Version C2021A00124 No. 124, 2021

Select target paragraph3