Report cyber security incidents to ASD (SOCI)
Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
Who must comply
Responsible entities for the 11 critical infrastructure sectors covered by SOCI.
What triggers it
A cyber security incident with significant impact (12h) or other reportable impact (72h).
When due
12 hours (significant) / 72 hours (other) of becoming aware.
Evidence required
Incident report to ASD, internal IR playbook records, log evidence.
Max penalty
Civil penalties up to $91,000 (250 penalty units, body corporate) per contravention, plus mandatory direction risks
Who must comply with this? The applicability test by industry, business structure and size.
Summary
Under the Security of Critical Infrastructure Act 2018, responsible entities for critical infrastructure assets must report cyber security incidents that have a 'significant impact' on the availability of the asset within 12 hours; other reportable cyber incidents within 72 hours. Reports go to ASD's ACSC.
Enforced by
Source legislation
Industries
Topics
Related
- CWLTHGovernment cyber incident reporting via ASD ACSCFederal entities + critical infrastructure report cyber incidents to ASD ACSC.
- CWLTHComply with SOCI Positive Security Obligation (PSO) per sectorSector-specific cyber + risk obligations under SOCI Part 2.
- CWLTHAdopt and maintain a Critical Infrastructure Risk Management Program (CIRMP)Covered critical infrastructure entities must adopt a CIRMP addressing cyber, physical, personnel, and supply-chain hazards.
- CWLTHReport ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)Businesses with turnover over $3M, and critical infrastructure responsible entities, must report any ransomware payment to the Government within 72 hours.
- CWLTHAdopt Essential Eight Maturity Level 2 (federal subcontractors)Federal government contractors handling OFFICIAL: Sensitive must meet Right Fit For Risk (RFFR) including E8 ML2.
- CWLTHComply with Serious Incident Response Scheme (aged care)Registered aged care providers must maintain an incident management system and notify Priority 1 reportable incidents within 24 hours and Priority 2 within 30 days.
Reading
Frequently asked questions
- Who must comply with cyber security incidents to ASD (SOCI)?
- Responsible entities for the 11 critical infrastructure sectors covered by SOCI.
- What triggers cyber security incidents to ASD (SOCI)?
- A cyber security incident with significant impact (12h) or other reportable impact (72h).
- When is cyber security incidents to ASD (SOCI) due?
- 12 hours (significant) / 72 hours (other) of becoming aware.
- What is the maximum penalty for cyber security incidents to ASD (SOCI)?
- Civil penalties up to $91,000 (250 penalty units, body corporate) per contravention, plus mandatory direction risks
- What evidence is required for cyber security incidents to ASD (SOCI)?
- Incident report to ASD, internal IR playbook records, log evidence.
Source: https://www.cisc.gov.au/legislation-regulation-and-compliance/. Rules Mate is not a law firm. Always verify against the live regulator source before acting.