ARTICLE
13 August 2024

Disclosure Obligations For Cyber Ransom Payments: A New Cyber Security Act Is Coming

KG
K&L Gates

Contributor

At K&L Gates, we foster an inclusive and collaborative environment across our fully integrated global platform that enables us to diligently combine the knowledge and expertise of our lawyers and policy professionals to create teams that provide exceptional client solutions. With offices spanning across five continents, we represent leading global corporations in every major industry, capital markets participants, and ambitious middle-market and emerging growth companies. Our lawyers also serve public sector entities, educational institutions, philanthropic organizations, and individuals. We are leaders in legal issues related to industries critical to the economies of both the developed and developing worlds—including technology, manufacturing, financial services, health care, energy, and more.
A new Cyber Security Act is set to be unveiled in Parliament's next sitting from 12 August, as reported by the ABC. The proposed Act would require Australian businesses and government bodies to disclose.
Australia Technology
To print this article, all you need is to be registered or login on Mondaq.com.

A new Cyber Security Act is set to be unveiled in Parliament's next sitting from 12 August, as reported by the ABC. The proposed Act would require Australian businesses and government bodies to disclose when they make a ransom payment to cybercriminals in the event of a hack, or face penalties of up to AU$15,000 for failing to notify.

The current proposal exempts small businesses at the same AU$3 million threshold as the Privacy Act's rules, though some believe the threshold is too low – the Australian Chamber of Commerce and Industry argues the rules should only apply to businesses with an annual turnover exceeding AU$10 million.

This bill would be in addition to the Cyber Resilience Service and Cyber Health Check services for small business expected to be operating by the end of 2024 as well as the Cyber Wardens Program currently operating that provides online cyber security training, designed to assist small businesses prevent and recover from cyber-attacks.

Under the proposed bill, Australia would also adopt international benchmarks in relation to connected consumer objects or 'IoT devices' (such as home security cameras and smartphone-controlled appliances). Standards already in place in the US and the UK seek to limit the amount of data businesses and governments collect through such devices and reduce the data at risk in the event of a cyber breach.

More information is yet to be released about the proposed Cyber Security Act, but in the meantime, you can be prepared by:

  • Implementing a recognised cyber security framework such as NIST or ASD's Essential 8.
  • Ensuring you have a Data Breach Response Plan and keeping it up-to-date.
  • Conducting annual cyber health checks: do you know what state your cyber security is currently in?
  • Keeping records of processing activities and make sure your organisation actively reviews its information holdings.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More