The Times Australia
The Times Australia
.

The Australian government has introduced new cyber security laws. Here’s what you need to know

  • Written by David Tuffley, Senior Lecturer in Applied Ethics & CyberSecurity, Griffith University

The Albanese government today introduced long-awaited legislation to parliament which is set to revolutionise Australia’s cyber security preparedness.

The legislation[1], if passed, will be Australia’s first standalone cyber security act. It’s aimed at protecting businesses and consumers from the rising tide of cyber crime.

So what are the key provisions, and will it be enough?

What’s in the new laws?

The new laws have a strong focus on victims of “ransomware” – malicious software cyber criminals use to block access to crucial files or data until a ransom has been paid[2].

People who pay a ransom do not always regain lost data[3]. The payments also sustain the hacker’s business model.

Under the new law, victims of ransomware attacks who make payments must report the payment to authorities. This will help[4] the government track cyber criminal activities and understand how much money is being lost to ransomware.

The laws also involve new obligations for the National Cyber Security Coordinator[5] and Australian Signals Directorate[6]. These obligations restrict how these two bodies can use information provided to them by businesses and industry about cyber security incidents. The government hopes this will encourage organisations to more openly share information knowing it will be safeguarded.

Separately, organisations in critical infrastructure – such as energy, transport, communications, health and finance – will be required to strengthen programs used to secure individuals’ private data.

The new legislation will also upgrade the investigative powers of the Cyber Incident Review Board[7]. The board will conduct[8] “no-fault” investigations after significant cyber attacks. The board will then share insights to promote improvements in cyber security practices more generally. These insights will be anonymised to ensure the identities of victims of cyber attacks aren’t publicly revealed.

The legislation will also introduce new minimum cyber security standards for all smart devices[9], such as watches, televisions, speakers and doorbells.

These standards will establish a baseline level of security for consumers. They will include secure default settings, unique device passwords, regular security updates and encryption of sensitive data.

This is a welcome step that will ensure everyday devices meet minimum security criteria before they can be sold in Australia.

A long-overdue step

Cyber security incidents[10] have surged by 23% in the past financial year, to more than 94,000 reported cases. This is equivalent to one attack every six minutes.

This dramatic increase underscores the growing sophistication and frequency of cyber attacks targeting Australian businesses and individuals. It also highlights the urgent need for a comprehensive national response.

High-profile cyber attacks have further emphasised the need to strengthen Australia’s cyber security framework. The 2022 Optus data breach is perhaps the most prominent example. The breach compromised the personal information of more than 11 million Australians, alarming both the government and the public, not to mention Optus.

Cyber Security Minister Tony Burke says[11] the Cyber Security Act is a “long-overdue step” that reflects the government’s concern about these threats.

Prime Minister Anthony Albanese has also acknowledged recent high-profile attacks as a “wake-up call[12]” for businesses, emphasising the need for a unified approach to cyber security.

The Australian government wants[13] to establish Australia as a world leader in cyber security by 2030. This goal reflects the government’s acknowledgement that cyber security is fundamental to national security, economic prosperity and social well being.

Man with white hair wearing suit and tie standing at microphone in parliament house in front of green leather bench.
Minister for Cyber Security Tony Burke says the creation of a new cyber security act is long overdue. Mick Tsikas/AAP[14]

Broader implications

The proposed laws will enhance national security. But they could also present challenges.

For example, even though the laws place limitations on how the National Cyber Security Coordinator and Australian Signals Directorate can use information, some businesses might still be unwilling to share confidential data because they are worried about damage to their reputation.

Businesses, especially smaller ones, will also face a substantial compliance[15] burden as they adapt to new reporting requirements. They will also potentially need to invest more heavily in cyber security measures. This could lead to increased costs, which might ultimately be passed on to consumers.

The proposed legislation will require careful implementation to balance the needs of national security, business operations and individual privacy rights.

References

  1. ^ legislation (www.aph.gov.au)
  2. ^ until a ransom has been paid (theconversation.com)
  3. ^ do not always regain lost data (www.austrac.gov.au)
  4. ^ will help (cybercx.com.au)
  5. ^ National Cyber Security Coordinator (www.homeaffairs.gov.au)
  6. ^ Australian Signals Directorate (www.asd.gov.au)
  7. ^ Cyber Incident Review Board (publicspectrum.co)
  8. ^ conduct (bn.nswbar.asn.au)
  9. ^ smart devices (thenightly.com.au)
  10. ^ Cyber security incidents (www.abc.net.au)
  11. ^ says (www.abc.net.au)
  12. ^ wake-up call (iapp.org)
  13. ^ The Australian government wants (www.homeaffairs.gov.au)
  14. ^ Mick Tsikas/AAP (www.aph.gov.au)
  15. ^ compliance (cybercx.com.au)

Read more https://theconversation.com/the-australian-government-has-introduced-new-cyber-security-laws-heres-what-you-need-to-know-240889

The company tax regime is a roadblock to business investment. Here’s what needs to change

Productivity growth is a key driver of improvements in living standards. But in Australia over the last deca...

Times Magazine

When Touchscreens Turn Temperamental: What to Do Before You Panic

When your touchscreen starts acting up, ignoring taps, registering phantom touches, or freezing entirely, it can feel like your entire setup is falling apart. Before you rush to replace the device, it’s worth taking a deep breath and exploring what c...

Why Social Media Marketing Matters for Businesses in Australia

Today social media is a big part of daily life. All over Australia people use Facebook, Instagram, TikTok , LinkedIn and Twitter to stay connected, share updates and find new ideas. For businesses this means a great chance to reach new customers and...

Building an AI-First Culture in Your Company

AI isn't just something to think about anymore - it's becoming part of how we live and work, whether we like it or not. At the office, it definitely helps us move faster. But here's the thing: just using tools like ChatGPT or plugging AI into your wo...

Data Management Isn't Just About Tech—Here’s Why It’s a Human Problem Too

Photo by Kevin Kuby Manuel O. Diaz Jr.We live in a world drowning in data. Every click, swipe, medical scan, and financial transaction generates information, so much that managing it all has become one of the biggest challenges of our digital age. Bu...

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Decline of Hyper-Casual: How Mid-Core Mobile Games Took Over in 2025

In recent years, the mobile gaming landscape has undergone a significant transformation, with mid-core mobile games emerging as the dominant force in app stores by 2025. This shift is underpinned by changing user habits and evolving monetization tr...

The Times Features

Sydney Fertility Specialist – Expert IVF Treatment for Your Parenthood Journey

Improving the world with the help of a new child is the most valuable dream of many couples. To the infertile, though, this process can be daunting. It is here that a Sydney Fertil...

Could we one day get vaccinated against the gastro bug norovirus? Here’s where scientists are at

Norovirus is the leading cause[1] of acute gastroenteritis outbreaks worldwide. It’s responsible for roughly one in every five cases[2] of gastro annually. Sometimes dubbed ...

Does running ruin your knees? And how old is too old to start?

You’ve probably heard that running is tough on your knees – and even that it can cause long-term damage. But is this true? Running is a relatively high-impact activity. Eve...

Jetstar announces first ever Brisbane to Rarotonga flights with launch fares from just $249^ one-way

Jetstar will start operating direct flights between Brisbane and Rarotonga, the stunning capital island of the Cook Islands, in May 2026, with launch sale fares available today...

Introducing the SE 2 and Mini hair dryers from Laifen

The Mane Attractions for Professional Styling at Home Without the Price Tag Fast, flawless hair is now possible with the launch of Laifen’s two professional quality hair dryers th...

Home Gym Recovery Routines: What Pro Athletes Do After Workouts

Training is only half the equation. What you do after your workout has just as much impact on your progress, performance, and long-term health. Professional athletes know this, w...