Summary
Introduced with the Intelligence Services and Other Legislation Amendment (Cyber Security) Bill 2024 and Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Bill 2024 to implement certain measures proposed by the 2023-2030 Australian Cyber Security Strategy, the bill provides for: mandatory security standards for smart devices; mandatory obligations on certain businesses to report ransomware and cyber extortion payments; a ‘limited use’ obligation that restricts how cyber security information voluntarily provided to the National Cyber Security Coordinator can be used and disclosed; and the establishment of a Cyber Incident Review Board to conduct post-incident reviews into significant cyber security incidents.