Cyber Town; training data next 100 miles

VU23223 Apply cyber security legislation, privacy and ethical practices

VU2322330 nominal hoursIn progressUpdated 3 September 2026

The unit as writtenunit scope

This is the official scope of the TAFE unit, kept here (folded) so the unit's intended coverage is visible at a glance and my own notes can be placed against it. The notes below are mine; they follow this scope where it still holds and go past it where current practice has moved on.

Unit: VU23223 Apply cyber security legislation, privacy and ethical practices. Nominal hours: 30. A core unit in 22603VIC Certificate IV in Cyber Security, the Victorian accredited course, with no prerequisite units.

What the unit expects you to be able to do: identify the cyber security legislation that applies across organisations in different sectors; assess an organisation's compliance with its privacy obligations and report on it in writing; and document examples of unethical conduct by an ICT or cyber security technician and explain the potential impact of each.

Required knowledge. Commonwealth legislation: Telecommunications (Interception and Access) Act 1979; Criminal Code Act 1995; Corporations Act 2001; Privacy Act 1988. Australian regulators: APRA (including CPS 234), ASIC, ACCC, the Australian Energy Sector Cyber Security Framework, and the Australian Government's Protective Security Policy Framework. International standards and instruments: the Budapest Convention on Cybercrime; PCI DSS; ISO/IEC 27001; AS 27701:2022. Plus organisational privacy policies, red and blue team ethics, unauthorised device access, copyright and file sharing, and ethical codes of practice.

Assessment conditions, from the accredited course document. The unit can be assessed in the workplace or in a simulated workplace environment; where it is simulated, the range of conditions must reflect a realistic workplace environment. The resources required are access to relevant documentation, including workplace procedures (privacy and ethics policies), cyber security legislation and relevant codes and standards. Assessors must satisfy the assessor requirements in the applicable vocational education and training legislation, frameworks and standards.

Source: the nominal hours, core placement and assessment conditions are from the CDU TAFE course document for 22603VIC Certificate IV in Cyber Security (V001, held in the vault); the coverage and required-knowledge summary follows the Victoria University published unit page for VU23223, read 15 August 2026. The numbered elements and performance criteria sit in the separate 22603VIC accreditation unit descriptors.

Who's who in Australian cyber security

Australian Cyber Security Centre (ACSC)

The Australian Cyber Security Centre (ACSC) leads the Australian Government's efforts to improve cyber security. Their role is to help make Australia the most secure place to connect online.

https://www.cyber.gov.au

Australian Signals Directorate (ASD)

The Australian Signals Directorate (ASD) is a vital member of Australia's national security community, working across the full spectrum of operations required of contemporary signals intelligence and security agencies: intelligence, cyber security and offensive operations in support of the Australian Government and Australian Defence Force (ADF).

https://www.asd.gov.au/

Australian Government's Federal Register of Legislation

The Federal Register of Legislation (the Legislation Register) is the authorised whole-of-government website for Commonwealth legislation and related documents. It contains the full text and details of the lifecycle of individual laws and the relationships between them.

The Legislation Register is managed by the Office of Parliamentary Counsel in accordance with the Legislation Act 2003.

https://www.legislation.gov.au/

Australian Federal Police

Criminal law enforcement and policy agency in the Attorney-General's portfolio and have the jurisdiction to investigate Commonwealth (federal) crimes across Australia. AFP are responsible for enforcing Commonwealth criminal law; leading and contributing to combating complex, transnational, serious and organised crime; disrupting crime offshore; supporting regional security as Australia's main international law enforcement representative; protecting Australian interests from criminal activity here and overseas.

https://www.afp.gov.au/

Cyber security terms and hacker types

Red Hat

Red hat hackers comprise one of the six types of hackers based on the colour of hat they wear. Apart from red hats, hackers can also be classified as black, white, grey, blue, and green hats.

Red Hat Hackers versus Black Hat Hackers

Red and black hats lie on the opposite ends of the spectrum. While they both know how to infect systems with malware, launch distributed denial-of-service (DDoS) attacks, and gain remote access to devices, red hats don't do these things for their gain. Red hats employ destructive means to accomplish a good end. They essentially give the bad guys a dose of their own medicine.

Red Hat Hackers versus White Hat Hackers

Among the six types of hackers, red hats have the most in common with white hats. They both use their advanced technical skills and know-how to go after black hats. Unlike white hats, who won't resort to attacking the black hats, red hats aren't afraid to get their hands dirty. To defend users against black hats, white hats find and fix vulnerabilities, develop tools to detect and mitigate cyber attacks, enhance the security of applications and systems, and create security software instead.

Red Hat Hackers versus Grey Hat Hackers

Grey hats typically charge users to fix bugs, strengthen their security defences, and provide vulnerability patches. In a sense, that's their primary difference from red hats, who don't usually get paid for what they do. Both may be after fame, though. A lot of grey hats, for instance, release the vulnerability patches they create to the public but only if the affected vendors don't pay them for their findings. Instead of money, therefore, they gain popularity, which helps them further their cybersecurity careers. Red hats gain fame when they're recognised for taking down bad guys.

Red Hat Hackers versus Blue Hat Hackers

Unlike red hats, blue hats come in two kinds; revenge seekers and external security professionals. Revenge seekers, as the name suggests, want payback for a sleight their victims made. External security pros, meanwhile, are outsiders that companies invite to test their soon-to-be-released software or hardware products for bugs. Some get invited to launch attacks on the organisation's network without causing any damage. Red hats don't need anything from the bad guys, nor do they get invited by companies to test their wares, systems, and applications against possible attacks.

Red Hat Hackers versus Green Hat Hackers

Green hats are hacking newbies. They have much to learn about hacking processes, tools, and what-not. Compared to green hats, red hats already know pretty much everything there is to know about hacking.

White Hat

These hackers as we all know are "ethical hackers" and they are the good guys who want to help people and organisations. They will help with finding your security gaps, help you with viruses etc.

Script Kiddie

Script Kiddies generally do not care to hack and steal things. They are generally known as hacker amateurs and will copy code and use it for viruses, SQLi or other purposes. they generally will download software to perform hacking, and you will generally see two different types of attacks from them; DoS or DDoS.

Red Team / Blue Team

In a red team/blue team exercise, the red team is made up of offensive security experts who try to attack an organisation's cybersecurity defences. The blue team defends against and responds to the red team attack.

Modelled after military training exercises, this drill is a face-off between two teams of highly trained cybersecurity professionals: a red team that uses real-world adversary tradecraft in an attempt to compromise the environment, and a blue team that consists of incident responders who work within the security unit to identify, assess and respond to the intrusion.

In a red team/blue team cybersecurity simulation, the red team acts as an adversary, attempting to identify and exploit potential weaknesses within the organisation's cyber defences using sophisticated attack techniques. These offensive teams typically consist of highly experienced security professionals or independent ethical hackers who focus on penetration testing by imitating real-world attack techniques and methods.

The red team gains initial access usually through the theft of user credentials or social engineering techniques. Once inside the network, the red team elevates its privileges and moves laterally across systems with the goal of progressing as deeply as possible into the network, exfiltrating data while avoiding detection.

If the red team is playing offense, then the blue team is on defence. Typically, this group consists of incident response consultants who provide guidance to the IT security team on where to make improvements to stop sophisticated types of cyberattacks and threats. The IT security team is then responsible for maintaining the internal network against various types of risk.

While many organisations consider prevention the gold standard of security, detection and remediation are equally important to overall defence capabilities. One key metric is the organisation's "breakout time"; the critical window between when an intruder compromises the first machine and when they can move laterally to other systems on the network.

CrowdStrike typically recommends a "1-10-60 rule," which means that organisations should be able to detect an intrusion in under a minute, assess its risk level within 10 minutes and eject the adversary in less than one hour.

Purple Team

Purple Teams exist to ensure and maximise the effectiveness of the Red and Blue teams. They do this by integrating the defensive tactics and controls from the Blue Team with the threats and vulnerabilities found by the Red Team into a single narrative that maximises both. Ideally Purple shouldn't be a team at all, but rather a permanent dynamic between Red and Blue.

How laws are made in Australia

To create new laws a Bill (a draft Act) is debated in parliament. If it is passed by a majority in both houses (Upper House and Lower House) of parliament it is sent to the governor for formal approval. After approval it becomes an Act. Approval by the governor is called royal assent.

To learn more about the Australian levels of Government, please read this light reading.

To learn more about how laws are made in Australia, this is a great article from parliament.act.gov.au.

Cybercrime and the Criminal Code Act 1995

To put it simply, it is illegal to attempt any form of testing / probing / viewing of any electronic system / electronic files / servers / social engineering in Australia without expressed written permission from the target.

In Australia, the term 'cybercrime' is used to describe both:

  • crimes directed at computers or other information communications technologies (ICTs) (such as hacking and denial of service attacks)
  • crimes where computers or ICTs are an integral part of an offence (such as online fraud, identity theft and the distribution of child exploitation material).

Responsibility for combating the different forms of cybercrime in Australia is shared between Australian Government agencies and state and territory agencies.

Criminal offences

The Commonwealth has enacted a comprehensive set of offences to address cybercrime, contained in the Criminal Code Act 1995 (Criminal Code). These offences are based on model laws agreed to by Commonwealth, state and territory governments in 2001. The offences are consistent with those required by the Council of Europe Convention on Cybercrime and are drafted in technology-neutral terms to accommodate advances in technology.

Definition:

Reasonable person:

The reasonable person refers to a hypothetical person who demonstrates average judgment or skill. The reasonable person has various generalised attributes including risk aversion, sound judgment, and a sense of self-preservation, which prevents them from walking blindly into danger.

Further reading: The 'Reasonable tort victim': CONTRIBUTORY NEGLIGENCE, STANDARD OF CARE AND THE 'EQUIVALENCE THEORY' - Melbourne University Law Review - View this article

Key Commonwealth offences are contained in Part 10.6 and Part 10.7 of the Criminal Code, which contains offences criminalising the misuse of telecommunication networks, 'carriage services' (a term which includes the internet and online services, as well as wired and mobile services) and computers.

The Commonwealth computer offences are complemented by state and territory laws which criminalise the misuse of data and computer systems.

Update, current as at September 2026. The Criminal Code gained new doxxing offences on 10 December 2024, inserted by Schedule 3 of the Privacy and Other Legislation Amendment Act 2024. In outline, it is an offence to use a carriage service to make available personal data of one or more individuals in a way that a reasonable person would regard as menacing or harassing, with a higher penalty where the individuals are targeted because of race, religion, sex, sexual orientation, gender identity, intersex status, disability, nationality or national or ethnic origin. This matters for this unit because doxxing had previously been prosecuted, when it was prosecuted at all, under the general menacing-use-of-a-carriage-service offence, and because releasing personal data taken from a breach can now attract a specific criminal offence in addition to the civil privacy consequences.

Types of cybercrime

Hacking (ie. Unauthorised access)

In Australia, unauthorised access to computer systems is criminalised by both State and Federal legislation. In the Federal jurisdiction, hacking is criminalised under the Criminal Code Act 1995 (Cth) ("the Code"). Most commonly, persons suspected of engaging in cybercrime are charged pursuant to the Code, given its universal application in all States and Territories in Australia.

Persons suspected of unauthorised access to computer systems are charged pursuant to s. 478.1 of the Code, which provides for the offence of "Unauthorised access to, or modification of, restricted data". The offence comprises three elements of proof. The offence is committed if: a person causes any unauthorised access to, or modification of, restricted data; the person intends to cause the access or modification; and the person knows that the access or modification is unauthorised. The maximum penalty for a contravention of s. 478.1 of the Code is two years' imprisonment. For the purposes of this offence, "restricted data" means data to which access is restricted by an access control system associated with a function of the computer.

As an example of state-based legislation criminalising hacking against private computer systems, Part 6 the New South Wales Crimes Act 1900 ("NSW Crimes Act") - Computer Offences sets out multiple offences centred around unauthorised access, modification, or impairment of restricted data and electronic communications.

Denial-of-service attacks

Denial-of-Service attacks ("DoS attacks") or Distributed Denial-of-Service attacks ("DDoS attacks") are criminalised by s. 477.3 of the Code, which provides for the offence of "Unauthorised impairment of electronic communication".

The offence comprises two elements and is committed if a person causes any unauthorised impairment of electronic communication to or from a computer and the person knows that the impairment is unauthorised. The maximum penalty for a contravention of s. 477.3 of the Code is 10 years' imprisonment.

Cross-site scripting (XSS)

Cross-site scripting, often abbreviated as XSS, is a type of attack in which malicious scripts are injected into websites and web applications for the purpose of running on the end user's device. During this process, unsanitized or unvalidated inputs (user-entered data) are used to change outputs.

Some XSS attacks do not have a specific target; the attacker simply exploits a vulnerability in the application or site, taking advantage of anyone unlucky enough to fall victim. But in many cases, XSS is performed in a more direct way, such as in an email message. An XSS attack can turn a web application or website into a vector for delivering malicious scripts to the web browsers of unsuspecting victims.

XSS attacks can exploit vulnerabilities in a range of programming environments, including VBScript, Flash, ActiveX, and JavaScript. Most often, XSS targets JavaScript because of the language's tight integration with most browsers. This ability to exploit commonly used platforms makes XSS attacks both dangerous and common.

Phishing

Phishing, being a form of online fraud, is criminalised under the Code in instances where the victim is said to be a Commonwealth entity. When the victim is a member of the public, charges are brought under parallel State or Territory legislation. In New South Wales ("NSW"), charges could be brought under s. 192E of the NSW Crimes Act, which criminalises the general offence of fraud.

Vishing is another form of this fraud, but using voice solicitation over a telephone to try and trick someone into disclosing sensitive information.

Skimming

Skimming occurs when devices illegally installed on ATMs, point-of-sale (POS) terminals, or fuel pumps capture data or record cardholders' PINs. Criminals use the data to create fake debit or credit cards and then steal from victims' accounts. It is estimated that skimming costs financial institutions and consumers more than $1 billion each year.

ATM and POS Terminal Skimming
  • ATM skimmer devices usually fit over the original card reader.
  • Some ATM skimmers are inserted in the card reader, placed in the terminal, or situated along exposed cables.
  • Pinhole cameras installed on ATMs record a customer entering their PIN. Pinhole camera placement varies widely.
  • In some cases, keypad overlays are used instead of pinhole cameras to records PINs. Keypad overlays record a customer's keystrokes.
  • Skimming devices store data to be downloaded or wirelessly transferred later.
From Skimmers to Shimmers

When the US banks finally caught up with the rest of the world and started issuing chip cards, it was a major security boon for consumers. These chip cards, or EMV cards, offer more robust security than the painfully simple magstripes of older payment cards. But thieves learn fast, and they've had years to perfect attacks in Europe and Canada that target chip cards.

Instead of skimmers, which sit on top of the magstripe readers, shimmers are inside the card readers. These are very, very thin devices and cannot be seen from the outside. When you slide your card in, the shimmer reads the data from the chip on your card, much the same way a skimmer reads the data on your card's magstripe.

SIM Card Skimmer hardware

Credit card fraud (not the only type)

Hackers will purchase massive databases of credit card credentials and using a script will bulk charge a small amount to each and every card, like $5. The hacker is relying on the fact that most people will not go to the effort of contacting their bank to dispute such a small transaction; and when they if fact do challenge the charge, the hacker will claim it was a simple error and reverse the charge thus maintaining apparent legality of their scam.

Prosecutions for Commonwealth fraud could encompass a wide variety of offending conduct, including phishing-style offences that would affect a Federal government body. Depending on the subsequent financial gain or loss suffered subsequent to the activity, the below charges are available:

  • S. 134.2(1) - obtaining a financial advantage by deception.
  • S. 135.1(1) - general dishonesty - obtaining a gain.
  • S. 135.1(3) - general dishonesty - causing a loss.
  • S. 135.1(5) - general dishonesty - causing a loss to another.

For the charge to be proven, the prosecution must establish that the accused obtains or causes a financial advantage, gain or loss by way of deception or dishonesty. The maximum penalty for each offence is 10 years' imprisonment.

Infection of IT systems with malware (including ransomware, spyware, worms, trojans and viruses)

The infection of IT systems with malware is criminalised by s. 478.2 of the Code, which provides for the offence of "unauthorised impairment of data held on a computer disk etc.".

The offence comprises three elements and is committed if: a person causes any unauthorised impairment of the reliability, security or operation of data held on a computer disk, a credit card or another device used to store data by electronic means; the person intends to cause the impairment; and the person knows that the impairment is unauthorised. The maximum penalty is two years' imprisonment.

As an example of state-based offences of this nature, conduct of this type would likely be encompassed within the "modification or impairment" aspects of the NSW Crimes Act computer offences.

Distribution, sale or offering for sale of hardware, software or other tools used to commit cybercrime

Distribution, sale or offering for sale of hardware, software or other tools used to commit cybercrime is criminalised by s. 478.4 of the Code, which provides for the offence of producing, supplying or obtaining data with intent to commit a computer offence. The offence comprises two elements.

The offence is committed if: a person produces, supplies or obtains data; and the person does so with the intention that the data be used, by the person or another person, in committing an offence against Division 477 of the Code or facilitating the commission of such an offence. The maximum penalty for a contravention of s. 478.4 of the Code is three years' imprisonment.

Possession or use of hardware, software or other tools used to commit cybercrime

Possession or use of hardware, software or other tools used to commit cybercrime is criminalised by s. 478.3 of the Code, which provides for the offence of possession or control of data with intent to commit a computer offence.

The offence comprises two elements. The offence is committed if: a person has possession or control of data; and the person has that possession or control with the intention that the data be used, by the person or another person, in committing an offence against Division 477 of the Code or facilitating the commission of such an offence. The maximum penalty for a contravention of s. 478.3 of the Code is three years' imprisonment.

An example of a state equivalent can be found in ss 308F and 308G of the NSW Crimes Act.

Identity theft or identity fraud (e.g. in connection with access devices)

Identity crime, and in particular identity fraud offences, are criminalised by Division 372 of the Code. Particular acts that are criminalised include dealing in identification information, dealing in identification information that involves use of a carriage service, possession of identification information and possession of equipment used to make identification information. The offence of "Dealing in identification information that involves use of a carriage service" is most relevant to cybercrime. It is criminalised by s. 372.1A of the Code and comprises four elements. The offence is committed if: a person deals in identification information; the person does so using a carriage service; the person intends that any person will use the identification information to pretend to be, or to pass the user off as, another person (whether living, dead, real or fictitious) for the purpose of committing an offence or facilitating the commission of an offence; and the offence is an indictable offence against the law of the Commonwealth, an indictable offence against a law of a State or Territory or a foreign indictable offence. The maximum penalty is five years' imprisonment.

Did you know?

US Senator Sarah Palin had her private Yahoo email account compromised by a 4chan hacker using OSINT.

The hacker didn't need any real skill, just Google.

The hacker simply reset Palin's password using her birthdate, ZIP code and information about where she met her spouse -the security question on her Yahoo account, which was answered (Wasilla High) by a simple Google search.

The simplicity of the attack, of course, makes it no less illegal.

The hacker said that he read all of the e-mails in the Palin account and found "nothing incriminating, nothing that would derail her campaign as I had hoped. All I saw was personal stuff, some clerical stuff from when she was governor…. And pictures of her family."

Once he posted the information to 4chan - the stronghold of the Anonymous griefer collective - a good Samaritan tried to step in to protect Palin by resetting her password and sending an e-mail to one of her aides, Ivy Frye. But the white hat posted a screen shot of that e-mail to 4chan, and it included the new password. That triggered a feeding frenzy on the forum, as legions of channers competed to log in and reset Palin's password again.

That flurry of activity triggered a security feature that froze Palin's account for 24 hours, which was long enough for the information to hit the media. Palin, or someone in her camp, closed the account early Wednesday morning.

Electronic theft (e.g. breach of confidence by a current or former employee, or criminal copyright infringement)

Electronic theft is criminalised by s. 478.1 of the Code. As the offence is committed if a person modifies restricted data, modification is defined in the Code as the alteration or removal of the data held in a computer, or an addition of the data held in a computer, the unauthorised copying of data from a computer would contravene the offence provision.

Unsolicited penetration testing (i.e. the exploitation of an IT system without the permission of its owner to determine its vulnerabilities and weak points)

Penetration testing activity without authority could offend the above-mentioned s. 478.1 of the Code, which provides for the offence of "Unauthorised access to, or modification of, restricted data".

Any other activity that adversely affects or threatens the security, confidentiality, integrity or availability of any IT system, infrastructure, communications network, device or data

Part 10.6 of the Code creates offences related to telecommunication services. They include offences relating to dishonesty with respect to carriage services and interference with telecommunications.

Additionally, the above-mentioned Part 6 of the NSW Crimes Act would likely be an example of state legislation that could cover these types of activities.

Do any of the above-mentioned offences have extraterritorial application?

Extended geographical jurisdiction applies to offences under Part 10.7 of the Code (Divisions 477 and 478).

A person will not commit offences under that Part unless: the conduct constituting the alleged offence occurs wholly or partly in Australia, or wholly or partly on-board an Australian aircraft or an Australian ship; or the conduct constituting the alleged offences occurs wholly outside Australia and a result of the conduct occurs wholly or partly in Australia, or wholly or partly on-board an Australian aircraft or an Australian ship; or the conduct constituting the alleged offence occurs wholly outside Australia and at the time of the alleged offence, the person is an Australian citizen or at the time of the alleged offence, the person is a body corporate incorporated by or under a law of the Commonwealth or of a State or Territory; or all of the following conditions are satisfied: the alleged offence is an ancillary offence; the conduct constituting the alleged offence occurs wholly outside Australia; and the conduct constituting the primary offence to which the ancillary offence relates, or a result of that conduct, occurs, or is intended by the person to occur, wholly or partly in Australia or wholly or partly on-board an Australian aircraft or an Australian ship.

Are there any factors that might mitigate any penalty or otherwise constitute an exception to any of the above-mentioned offences (e.g. where the offence involves "ethical hacking", with no intent to cause damage or make a financial gain)?

The Crimes Act 1914 (Cth) prescribes the sentences applicable to breaches of Federal legislation, such as the Code. Relevant matters for consideration on sentences are set out as a non-exhaustive list of factors under s. 16A of the NSW Crimes Act (Cth). Matters that generally will mitigate a penalty include the timing of any guilty plea, the offender's character, the offender's prior record, assistance provided by the offender to the authorities and the offender's prospect of rehabilitation and likelihood of reoffending. The absence of intent to cause damage or make a financial gain could be taken into account by a sentencing court as a factor of mitigation.

A number of the offences particularised above cannot be "attempted"; they must actually be committed. For example, a person cannot attempt to commit the offence of "Unauthorised access, modification or impairment with intent to commit a serious offence".

National Plan to Combat Cybercrime

As a key deliverable under Australia's Cyber Security Strategy 2020 (553KB PDF), the 2022 National Plan to Combat Cybercrime was released on 21 March 2022 and builds on the 2013 Plan to formalise a framework that focuses on three key pillars: Prevent and Protect; Investigate, Disrupt and Prosecute; and Recover. The framework outlined under these key pillars will support the development of a nationally coordinated approach to combating cybercrime in Australia.

To ensure the objectives of the 2022 National Plan are achieved, Home affairs will soon establish the National Cybercrime Forum that will consist of representatives from across Commonwealth, State and territory agencies. This forum will help drive outcomes and support the development of the Cybercrime Action Plan, which will bring together the powers, capabilities, experiences and intelligence of all jurisdictions to build a strong multi-faceted response to cybercrime in Australia.

See the 2022 National Plan to Combat Cybercrime (999KB PDF) for more details.

A full extract of the criminal code, Parts 10.6 & 10.7

Cyber security laws at a glance

The following laws in Australia relate to cybersecurity:

Federal legislation

  • the Privacy Act 1988 (Cth) ("Privacy Act");
  • The Privacy Act 1988 was introduced to promote and protect the privacy of individuals and to regulate how Australian Government agencies and organisations with an annual turnover of more than $3 million, and some other organisations, handle personal information.
  • the Crimes Act 1914 (Cth);
  • The Crimes Act sets out Commonwealth powers, authorities and obligations for dealing with Commonwealth criminal offences and related matters.
  • the Security of Critical Infrastructure Act 2018 (Cth);
  • the Criminal Code Act 1995 (Cth);
  • There are hundreds of Commonwealth Acts which contain criminal offences, perhaps the most notable of which is the Criminal Code Act 1995 ('the Act') - the stated purpose of which is 'to codify the general principles of criminal responsibility under laws of the Commonwealth'.
  • the Telecommunications (Interception and Access) Act 1979 (Cth).
  • The TIA Act makes it an offence for a person to intercept or access private telecommunications without the knowledge of those involved in that communication. The TIA Act permits access to communications content for law enforcement and national security purposes.
  • the Intelligence Services Act 2001 (Cth)
  • the Copyright Act 1968 (Cth).
  • The Copyright Act gives authors and other copyright owners of original 'works' the exclusive right to reproduce, publish, communicate, and adapt their material; and to licence, transfer, or sell it to other people.
  • and the Australian Human Rights Commission Act 1996

Northern Territory legislation

Reporting, prevention and governance

Reporting to authorities

Are organisations required under Applicable Laws, or otherwise expected by a regulatory or other authority, to report information related to Incidents or potential Incidents (including cyber threat information, such as malware signatures, network vulnerabilities and other technical characteristics identifying a cyber-attack or attack methodology) to a regulatory or other authority in your jurisdiction?

In February 2018, the Privacy Amendment (Notifiable Data Breaches) Act 2017 amended the Privacy Act to require Australian Privacy Principles ("APP") entities to, as soon as practicable, provide notice to the OAIC and affected individuals of an "eligible data breach", where there are reasonable grounds to believe that an "eligible data breach" has occurred. This process is called the Notifiable Data Breaches Scheme ("NDB Scheme").

Eligible data breaches arise when: there is unauthorised access to or unauthorised disclosure of personal information, or a loss of personal information, that an entity holds; this unauthorised disclosure of personal information, or loss of personal information, is likely to result in serious harm to one or more individuals; and the entity has not been able to prevent the likely risk of serious harm with remedial action. Indicators such as malware signatures, observable network vulnerabilities and other "red-flag" technical characteristics may represent reasonable grounds for an APP entity to form a belief that an eligible data breach has occurred.

The OAIC expects APP entities to conduct a quick assessment of a suspected data breach to determine whether it is likely to result in serious harm.

The notification to the OAIC must include the identity and contact details of the organisation, a description of the data breach, the kinds of information concerned and recommendations about the steps that individuals should take in response to the data breach.

Under the Privacy Act, an APP entity is defined as an "agency" or "organisation". "Agency" includes a Minister, a department, and most government bodies, whilst "organisation" means an individual, a body corporate, a partnership, any other unincorporated association or a trust that is not a small business operator, a registered political party, an agency, a State or Territory authority or a prescribed instrumentality of a State or Territory.

Reporting to affected individuals or third parties

The affected individual must also be notified of an "eligible data breach", as defined above. The notification must include the identity and contact details of the organisation, a description of the data breach, the kinds of information concerned and recommendations about the steps that individuals should take in response to the data breach.

A failure to comply with the notification obligations can result in the imposition of substantial civil penalties. A serious or repeated interference with privacy attracts a fine of 2,000 penalty units, currently AUD 444,000.00. The maximum penalty that a court can order for a body corporate is five times the amount listed in the civil penalty provision, currently a maximum of AUD 2.1 million.

Attack prevention

Are organisations permitted to use any of the following measures to protect their IT systems in your jurisdiction (including to detect and deflect Incidents on their IT systems)?

Beacons

Beacons (i.e. imperceptible, remotely hosted graphics inserted into content to trigger a contact with a remote server that will reveal the IP address of a computer that is viewing such content)

There are presently no laws in Australia that prohibit the use of a Beacon or near-field communication technology.

Honeypots

Honeypots (i.e. digital traps designed to trick cyber threat actors into taking action against a synthetic network, thereby allowing an organisation to detect and counteract attempts to attack its network without causing any damage to the organisation's real network or data)

There are presently no laws in Australia that prohibit the use of Honeypot technology or similar autonomous deception measures.

Sinkholes

Sinkholes (i.e. measures to re-direct malicious traffic away from an organisation's own IP addresses and servers, commonly used to prevent DDoS attacks)

There are presently no laws in Australia that prohibit the use of Sinkhole technology. The malicious use of Sinkhole methods to steer legitimate traffic away from its intended recipient may, however, constitute an offence under s. 477.3 of the Code.

Sinkholes can be lawfully used as a defensive practice for research and in reaction to cyber-attacks. In this capacity, Sinkholes are a tool used by both public and private agencies.

But education is the key!

Some companies are more proactive than others. See below a local NT company being leaders in their field offering local education to it's customers.

Education is also in the form of warnings and advice offered by software manufacturers; like Google Chrome. Google Chrome will notify you if it has found your email address / password combination posted on the dark web.

This warning (pictured below) will appear once you have filled in authentication credentials that were found in a data breach.

If you do see this message, it is advisable to change the passwords for the account(s) using this username / password combination.

Corporate Governance

A failure by a company to prevent, mitigate, manage or respond to an Incident may result in breaches of provisions of the Corporations Act 2001 (Cth). The Corporations Act 2001 (Cth) imposes duties on directors to exercise powers and duties with the care and diligence that a reasonable person would. A director who ignores the real possibility of an Incident may be liable for failing to exercise their duties with care and diligence.

Investigatory and Police Powers

A number of well-established legal investigatory powers are deployed by law enforcement authorities when investigating an Incident. These powers can include the issuing of search warrants, the seizure of IT equipment for forensic analysis, decryption (whether at encrypted or decrypted data points) and the compulsory examination of suspects in certain circumstances.

The Australian Signals Directorate ("ASD") assumes responsibilities for defending Australia from global threats and advances its national interests through the provision of foreign signals intelligence, cybersecurity and offensive cyber operations as directed by the Australian Government. One of the express strategic objectives of the ASD is to provide advice and assistance to law enforcement. To this end, the ASD can collaborate with the Federal, State and Territory police forces in relation to matters of national interest, including emerging areas such as cyberterrorism.

On 8 December 2018, the Federal Parliament passed the Telecommunications and Other Legislation Amendment (Assistance and Access) Bill 2018. The Bill provides for the facilitation of covert access to data for the purposes of disrupting and investigating criminal activity, as well as establishing a framework to facilitate lawful assistance from communications providers.

The legislation allows various Australian law enforcement and intelligence agencies to make a Technical Assistance Notice ("TAN"), ordering designated communications providers to provide data or assistance in relation to criminal investigations or matters of security. This may include access to encryption keys or provision of decrypted data. Similarly, a Technical Capability Notice ("TCN") can be issued, mandating that a designated communications provider establish new capability to intercept and decrypt communications that would otherwise be encrypted or inaccessible.

The above notices may be issued in a broad variety of circumstances, including the enforcement of criminal laws and laws imposing pecuniary penalties, either in Australia or in a foreign country, or if it is in the interests of Australia's national security, Australia's foreign relations, or Australia's national economic wellbeing.

A designated communications provider, including an individual employed or acting on behalf of such providers, who has been compelled to provide data or assistance under a computer access warrant and fails to do so, may face up to 10 years' imprisonment, a fine of up to 600 penalty units (currently AUD 133,200.00) or both.

Reference: Nyman, Gibson & Maralis - Defence Lawyers and Advisors

Know Your Customer (KYC): a pointer

KYC is only flagged here; it is covered in full in the AML/CTF, digital currencies and Know Your Customer section later in these notes.

Privacy and cyber security in Australia

Australian privacy laws and cybersecurity are two crucial aspects of modern-day digital life. Australia has several laws and regulations in place to protect personal data and ensure cybersecurity.

The primary law governing privacy in Australia is the Privacy Act 1988, which regulates how personal information is collected, used, and disclosed by businesses and government agencies. The act also established the Australian Privacy Principles (APPs), which outline the standards for the handling of personal information in Australia. The APPs cover various aspects of privacy, including the collection, use, disclosure, and storage of personal information.

The Privacy Act 1988 also establishes the Office of the Australian Information Commissioner (OAIC), which is responsible for enforcing privacy laws and regulations in Australia. The OAIC has the power to investigate privacy breaches, issue fines and penalties, and provide guidance and education on privacy issues.

In addition to privacy laws, Australia has several cybersecurity laws and regulations in place to protect against cyber threats. Other legislation in Australia is the Online Safety Act 2021. The Act builds upon the existing online regulatory framework established in the Enhancing Online Safety Act 2015 (EOSA) and creates additional compliance obligations.

In the NT...

The NT government's privacy obligations are primarily governed by the Northern Territory's Information Act 2002, not the Australian Privacy Act, which primarily applies to federal agencies and private sector entities.

Here's a more detailed explanation:

NT Information Act 2002: This Act, which took effect on July 1, 2003, addresses freedom of information, privacy, and records management for the Northern Territory government and its agencies.

Information Privacy Principles (IPPs): The Act sets out 10 Information Privacy Principles that bind public sector organisations, outlining how personal information should be collected, used, disclosed, and managed.

Focus on Public Sector - The NT Information Act focuses on the privacy of information held by the Northern Territory public sector, including public sector health service providers.

Commonwealth Privacy Act - The Commonwealth Privacy Act primarily applies to Australian Government agencies, organisations with an annual turnover of more than $3 million, and some other entities, but it doesn't cover state and territory government agencies, including public hospitals and schools.

NT Government's Approach - The NT government has modified the principles from the Commonwealth Privacy Act and embedded them into the Information Privacy Principles under the NT Information Act.

Records and Archives Management -The NT Information Act also provides a framework for effective and responsible record keeping and records management.

Freedom of Information - The Act also deals with freedom of information (FOI), giving individuals the right to apply for access to government information.

Contact Information - For more information on privacy in the Northern Territory, you can visit the Office of the Information Commissioner website.

infocomm.nt.gov.au

nt.gov.au/law/rights/privacy-your-rights

APPs: Comprise 13 principles applicable to Australian Government agencies and many private sector organisations, including not-for-profits with an annual turnover exceeding AU$3 million. Certain smaller entities handling sensitive data or engaging in specific practices may also be required to comply.

IPPs: Consist of 10 principles binding on Northern Territory (NT) public sector organisations, as outlined in the NT Information Act 2002.

Open this word file to see a more detailed comparison: The NT government information ACT (Word document)

Information Privacy Principles

Image of the NT Information principles website

Reform of the Privacy Act

The Privacy Act Review reported in February 2023 with 116 recommendations, finding the existing law unfit for the digital age. The Attorney-General's response agreed to 38 of them and agreed in principle to another 68, opening the way to a direct cause of action for serious invasions of privacy and to removing the small business exemption.

Update, current as at September 2026. That review is no longer pending; it has produced law, in stages, and the staging is the thing to understand.

Already in force. The Privacy and Other Legislation Amendment Act 2024 received assent on 10 December 2024 and is the first tranche. It brought the tiered civil penalties described further down this page; a new statutory tort for serious invasions of privacy, which commenced 10 June 2025 and lets an individual sue directly rather than depending on regulator action; new doxxing offences, inserted into the Criminal Code Act 1995 by Schedule 3 of that Act and covered in the Criminal Code section above; a Children's Online Privacy Code to be developed by the OAIC; clearer powers for information sharing in emergencies and after eligible data breaches; and enhanced enforcement powers for the Commissioner.

Commencing 10 December 2026. The automated decision-making transparency requirement, covered in the artificial intelligence section above.

Still to come, and genuinely uncertain. A second tranche carrying the larger structural recommendations, including removal of the small business exemption, a fair and reasonable test for collection and use, and a broader definition of personal information. Consultation on a tranche two bill has been under way, but it has not passed, and it has slipped more than once. Anyone planning around it should plan for the direction rather than a date.

The practical consequence for a small Australian business, which is the question the assessment scenarios tend to raise: the small business exemption still stands as at September 2026, so a business with annual turnover of three million dollars or less that does not trade in personal information, provide a health service or fall into one of the other exceptions is still outside most of the Privacy Act. It is expected to go, it has been recommended for removal, and it has not gone yet. Advising a client that it will remain indefinitely would be unwise.

What is PII?

Personally identifiable information (PII) is any data that could potentially identify a specific individual.

Any information that can be used to distinguish one person from another and can be used to deanonymize previously anonymous data is considered PII.

So here is my question to you students, if I were to anonymise user data by removing a first and last name and replacing it with a serial number, do you think this would be sufficient to meet your expectations of what a anonymised dataset would be?

Gaining access to PII - what could go wrong?

There's nothing really wrong with using an online criminal marketplace to purchase stolen information, is there?

OF COURSE THERE IS! And it's plenty illegal.

A Melbourne man was today (19 January, 2024) sentenced for using an online criminal marketplace to purchase stolen information.

The Endeavour Hills man, 32, was sentenced in the Melbourne Magistrates Court after pleading guilty on 16 January, 2024.

An investigation began after the man was found using an invite-only website; known as Genesis Market; which sold login credentials, browsing history, autofill form data and other sensitive data from compromised devices.

Police conducted a search warrant at the man's Endeavour Hills home on 5 April, 2023 where they seized a laptop and mobile phone.

Australian Federal Police article - 19 Jan 2024

The man pleaded guilty to the following offences:

One count of possessing data with the intent to commit a computer offence, contrary to section 478.3(1) of the Criminal Code 1995 (Cth).

He was sentenced to a 12-month Community Corrections Order, with 150 community work hours to complete.

You you think he got off lightly??

What was the maximum sentence the judge could have awarded?

More reading, Star News. 22/1/24

What other laws exist relating to PII in Australia?

Other laws and regulations related to cybersecurity in Australia include the Telecommunications Act 1997, which sets out the requirements for telecommunications providers to protect their networks and services from cyber threats, and the The Criminal Code 1995, which includes provisions related to computer-related offences.

Australia also has several initiatives and programs aimed at improving cybersecurity across the country. For example, the government launched the Cyber Security Strategy in 2016, which includes initiatives such as the establishment of a Cyber Security Growth Centre and a Cyber Security Cooperative Research Centre. The strategy also includes funding for cybersecurity education and training programs, as well as support for businesses and government agencies to improve their cybersecurity practices.

Update, current as at September 2026. The 2016 and 2020 strategies referenced on this page have both been replaced. The current one is the 2023 to 2030 Australian Cyber Security Strategy, which sets the stated ambition of Australia becoming a world leader in cyber security by 2030 and organises the work around six cyber shields: strong businesses and citizens; safe technology; world-class threat sharing and blocking; protected critical infrastructure; sovereign capabilities; and a resilient region and global leadership. It is delivered in three horizons. Horizon 1, from 2023 to 2025, was about strengthening foundations and closing gaps, and it produced most of the legislation described on this page, including the Cyber Security Act 2024 and the SOCI amendments. Horizon 2, announced on 11 June 2026 and running from 2026 to 2028, carries 19 actions and 64 initiatives under three objectives: enabling the human firewall, protecting critical infrastructure and government systems, and shaping, securing and embracing digital technology. Horizon 3, from 2029 to 2030, is aimed at advancing the global frontier. The shields are a useful map when you are asked which body or which law covers a particular problem, because most Australian cyber policy of the last three years traces back to one of them.

Despite these laws and initiatives, cybersecurity remains a significant challenge in Australia, with cyber threats becoming increasingly sophisticated and frequent. In 2020, the Australian Cyber Security Centre received 67,500 cybercrime reports, representing an increase of 13% from the previous year.

To address these challenges, businesses and individuals in Australia must take appropriate measures to protect their digital assets and personal information. This includes using strong passwords, enabling two-factor authentication, regularly updating software, and being cautious of suspicious emails or messages. Businesses must also implement robust cybersecurity policies and provide training and education to employees to ensure they are aware of the risks and best practices for cybersecurity.

In conclusion, Australian privacy laws and cybersecurity are essential aspects of modern-day digital life. With the increasing prevalence of cyber threats, it is crucial for individuals and businesses to take appropriate measures to protect their digital assets and personal information. The Australian government has taken steps to address these challenges, but continued efforts are necessary to ensure that Australia's digital environment remains safe and secure.

AS 27701: 2022 Security techniques - Extension to ISO/IEC 27001

There are International and Australian standards in this area (Information and privacy management), specifically the Australian standard AS27701. There will be more on this topic in the International standards sessions.

Update, current as at September 2026. The underlying international standard has been rewritten. ISO/IEC 27701:2019, which the Australian adoption follows, was an extension to ISO/IEC 27001 and 27002, so it could only be used by an organisation already running an ISO 27001 information security management system. The second edition, ISO/IEC 27701:2025, is a standalone management system standard, retitled "Information security, cybersecurity and privacy protection: privacy information management systems: requirements and guidance". The practical effect is that a privacy information management system can now be built and certified without first certifying to ISO 27001, which puts it within reach of a much wider set of organisations. It retains its mappings to the other privacy standards in the family and to the GDPR. When citing this standard, name the edition year, because the 2019 and 2025 editions are structurally different documents.

Technology advances and how they affect existing privacy laws

Technology advances have had a significant impact on existing privacy laws. The increasing use of technology has created new ways for individuals and organisations to collect, store, and use personal data, which has led to the need for new privacy laws and regulations.

For example, the rise of social media and the widespread use of smartphones have led to the creation of vast amounts of personal data that can be used to track individuals' online behaviour, location, and social interactions. This has raised concerns about how this data is collected, stored, and used, and has led to new laws such as the General Data Protection Regulation (GDPR) in the European Union and the California Consumer Privacy Act (CCPA) in the United States.

In addition to these laws, advances in technology have also led to the development of new tools and technologies that can help individuals protect their privacy. For example, there are now browser extensions and privacy-focused search engines that can help users avoid being tracked online.

Overall, technology advances have forced lawmakers to adapt and update privacy laws to keep up with the new ways in which personal data is being collected and used. While there is still much work to be done to ensure that individuals' privacy is protected in the digital age, these laws are an important step in the right direction.

Case Study: Ancestry DNA

Have you heard of the online family tree / family history website called Ancestry.com.au.

This website provides a service to its members where a user can upload a simple DNA test and the website can reveal those people who have also uploaded DNA samples whom are very closely related. This option is marketed as a great way to find long lost relatives or to find those closely related relatives to help fill in gaps in your own family tree.

This site has access to shared DNA databases from all over the world from similar sites.

Here's a quote from their website:

Ancestry screenshot

Are there any implications regarding privacy with this service?

Think a person's right to privacy.

What about law enforcement usage?

Would law enforcement have the right to gain access to this database with a warrant?

What about legitimate privacy concerns?

Think about past laws / procedures and how this new technology may affect current people.

What if you're found to be a near perfect or sibling match to the DNA found at a past murder? What unintended impact may that have on you or your family? What if you were adopted? What if you were conceived with the help of fertility treatment help back in the 1970's when men were paid to be sperm donors on the condition that they were guaranteed to remain anonymous?

What about possible inheritance challenges from unknown biological children?

Who would pay for the legal challenges of these cases?

What if the possible inheritance is LOTS of money? What if they try to forge a 'relationship' with their biological parents whilst they are alive with the view to strengthening their inheritance claim case later on?

Here is a video about AncestryDNA privacy

Ancestry does not voluntarily cooperate with law enforcement. To provide our Users with the greatest protection under the law, we require all government agencies seeking access to Ancestry customers' data to follow valid legal process and do not allow law enforcement to use Ancestry's services to investigate crimes or to identify human remains.

https://www.ancestry.com.au/c/legal/lawenforcement

Risk management / mitigation

The question that needs to be asked is, what could go wrong?

Imagine being the blue-team network engineer tasked with conducting a risk assessment on all this data with the knowledge that some of the most high-profile organisations have been hacked including The World Bank, Linkedin just to name a few. We'll be covering risk assessments later in the course.

Imagine the most uniquely identifying personal data being available to the highest bidder?

What could go wrong, I ask again?

What about genetic discrimination?

Genetic discrimination describes the different treatment of individuals or their relatives based on their actual or assumed genetic make-up. A person's genetic make-up may be identified by DNA testing or it can be assumed from the medical history of the person's family.

It's not currently illegal to discriminate based on genetics in Australia!

This exact topic is currently under review. Read more about it here (Public Health research & practice) and here (Aust Gov. Law Reform Commission).

The Australian Privacy Principles

Privacy Act 1988 - Chapter 11: APP 11 - Security of personal information

Key points

An APP (Australian Privacy Principles) entity must take reasonable steps to protect personal information it holds from misuse, interference and loss, as well as unauthorised access, modification or disclosure.

Where an APP entity no longer needs personal information for any purpose for which the information may be used or disclosed under the APPs, the entity must take reasonable steps to destroy the information or ensure that it is de-identified. This requirement applies except where:

  • the personal information is part of a Commonwealth record, or
  • the APP entity is required by law or a court/tribunal order to retain the personal information

Many of the issues discussed in this Chapter are discussed in more detail in the Office of the Australian Information Commissioner's (OAIC) Guide to Securing Personal Information.

What is an APP Entity?

oaic.gov.au (Office of the Australian Information Commissioner - APP Entities)

The Privacy Act imposes obligations on 'APP entities'.

An APP entity is, generally speaking:

  • an agency (which largely refers to a federal government entity and/or office holder) or
  • an organisation (which includes an individual, body corporate, partnership, unincorporated association, or trust).

An APP entity does not include:

  • a 'small business operator' (subject to the exceptions below), which is an operator of a business with an annual turnover of less than $3 million
  • a registered political party or
  • a state or territory authority.

However, a small business operator will be deemed to be an APP entity, and therefore required to comply with the Privacy Act if they:

  • operate another business with a turnover of $3 million or more
  • provide a health service or otherwise hold health information (other than in an employee record)
  • disclose, or collect, personal information about another individual for a benefit, service or advantage
  • are a contracted service provider for a Commonwealth contract or
  • are a credit reporting body.

APP 1: Open and transparent management of personal information

APP 1 requires an APP entity to implement privacy practices, procedures and systems:

  • to ensure compliance with the remaining APPs and
  • that enable them to deal with inquiries and complaints.

It also requires them to develop and make readily available a policy about its management of personal information.

APP 2: Anonymity and pseudonymity

APP 2 entitles individuals to the option of anonymity or using a pseudonym, when dealing with an APP entity, except where impracticable or another prescribed exception applies.

APP 3: Collection of solicited personal information

APP 3, in summary:

  • permits an APP entity to collect personal information only where reasonably necessary for one or more of its legitimate functions or activities
  • requires personal information to be collected directly from the individual to whom it relates, unless impracticable or another prescribed exception applies and
  • requires the consent from an individual in order to collect that individual's sensitive information, or another prescribed exception applies.

APP 4: Dealing with unsolicited personal information

APP 4 requires an APP entity that receives unsolicited personal information to determine whether it would otherwise have had grounds on which to collect it (i.e. under APP 3) and:

  • where it does have such grounds, to ensure compliance with the remaining APPs or
  • where it does not have such grounds, to destroy or de-identify the personal information (provided it is lawful and reasonable to do so).

APP 5: Notification of the collection of personal information

APP 5 requires an APP entity to notify an individual (or ensure they are aware), at or before the time of collection, of prescribed matters. Such matters include but are not limited to whether the individual's personal information is collected from any third parties, the purpose(s) of collection, to whom personal information is disclosed and the processes through which an individual can seek access and/or correction to their personal information, or otherwise complain about the way in which it is handled.

Compliance with APP 5 usually requires 'collection statements' to be included on or with forms, or other materials, through which personal information is collected. Such statements should refer and include a link to the APP entity's privacy policy.

APP 6: Use or disclosure of personal information

APP 6 prohibits an APP entity from using or disclosing personal information for a purpose other than the purpose for which it was collected, unless the individual consents, the individual would reasonably expect their personal information to be used for the secondary purpose, or another prescribed exception applies.

Such prescribed exceptions generally arise where the disclosure is necessary to protect someone's health or safety or is otherwise in the public interest.

APP 7: Direct marketing

APP 7 generally prohibits personal information to be used for direct marketing purposes unless the individual reasonably expects it, or consents to it, and prescribed 'opt out' processes are in place through which the individual can elect not to receive direct marketing communications (and the individual has not elected as such).

APP 8: Cross-border disclosure of personal information

If an APP entity is to disclose personal information to an overseas recipient, APP 8 requires it to take reasonable steps to ensure the recipient does not breach the APPs. This usually requires the APP entity to impose contractual obligations on the recipient.

Relevantly, if the overseas recipient does breach the APPs, the Privacy Act imposes liability on the APP entity that made the overseas disclosure.

There are exceptions to this obligation, including but not limited to where:

  • the APP entity reasonably believes the overseas recipient is bound by a law or scheme that protects personal information in a substantially similar way to that of the APPs or
  • the individual consents to the disclosure in the knowledge that such consent will negate the APP entity's obligation to ensure the overseas recipient does not breach the APPs.

APP 9: Adoption, use or disclosure of government-related identifiers

APP 9 prohibits an APP entity from adopting, using or disclosing a government-related identifier unless:

  • required or authorised by law
  • necessary to verify an individual's identity and/or
  • another prescribed exception applies.

Government-related identifiers are identifiers that have been assigned by a government agency including an individual's licence number, Medicare number, passport number and tax file number.

APP 10: Quality of personal information

APP 10 requires an APP entity to take reasonable steps to ensure personal information it collects, uses, discloses and holds is accurate, up-to-date and complete. Additionally, personal information can only be used or disclosed to the extent to which it is relevant to the purpose of the use or disclosure.

APP 11: Security of personal information

APP 11 requires an APP entity to take reasonable steps to protect information from misuse, interference and loss and from unauthorised access, modification or disclosure.

An APP entity must also destroy or de-identify personal information it no longer requires (unless otherwise required to retain it by law).

APP 12: Access to personal information

APP 12 requires an APP entity to provide an individual, upon request, with access to their personal information unless a prescribed exception applies.

APP 13: Correction of personal information

APP 13 requires an APP entity to take reasonable steps to correct personal information it holds upon request from an individual for correction or where it is otherwise satisfied, having regard to the purpose for which it holds the personal information, that the personal information is inaccurate, out-of-date, incomplete, irrelevant or misleading.

If an APP entity refuses a request for correction, it needs to provide the individual with the reasons for the refusal and may be required to associate with the personal information a statement evidencing the individual's view that the information is incorrect.

Where correction does occur, the APP entity may need to notify third parties to which the personal information, in its incorrect form, was disclosed.

Security of Critical Infrastructure Act 2018

Security of Critical Infrastructure Act 2018

The Security of Critical Infrastructure Act 2018 (Cth), which commenced on 11 July 2018, seeks to manage national security risks of sabotage, espionage and coercion posed by foreign entities. The Act was implemented as a response to technological changes that have increased cyber connectivity to critical infrastructure. The Australian Government considers "the responsibility for ensuring the continuity of operations and the provision of essential services to the Australian economy and community" as being shared "between owners and operators of critical infrastructure, state and territory governments and the Australian Government". The Act applies to approximately 165 specific assets in the electricity, gas, water and ports sectors.

The Act establishes a Register of Critical Infrastructure Assets, empowers the Secretary of the Department of Home Affairs with an information-gathering power (whereby certain information can be requested of direct interest holders, responsible entities and operators of critical infrastructure assets), and a Minister has the power to issue a direction to an owner or operator of critical infrastructure assets to mitigate national security risks.

What is critical infrastructure?

The Australian Government defines critical infrastructure as:

'those physical facilities, supply chains, information technologies and communication networks which, if destroyed, degraded or rendered unavailable for an extended period, would significantly impact the social or economic wellbeing of the nation or affect Australia's ability to conduct national defence and ensure national security'.

About the Act

Protecting Critical Infrastructure and Systems of National Significance.

On 2 December 2021, the Security of Critical Infrastructure Act 2018 was amended to expand coverage from 4 sectors to 11 sectors and 22 asset classes.

Update, current as at September 2026. The Act was amended again by the cyber security legislative package that passed in November 2024 and commenced through 2025. The changes worth knowing: data storage systems holding business-critical data are now expressly captured, closing a gap that the 2022 breaches exposed; government has an all-hazards assistance and direction power, so it can step in during a significant incident that is not a cyber incident; telecommunications security obligations were consolidated into the SOCI Act rather than sitting separately in the Telecommunications Act; and there is a power to direct an entity to remediate a seriously deficient risk management program rather than only to respond to an incident after the fact. The reporting timeframes remain 12 hours for an incident with a significant impact and 72 hours for one with a relevant impact.

That package also created the Cyber Security Act 2024, Australia's first standalone cyber security statute, which is covered in the incident reporting material and is the source of the mandatory ransomware payment reporting obligation, the security standards for smart devices, the limited use obligation on information given to ASD during an incident, and the Cyber Incident Review Board.

The Security of Critical Infrastructure Act 2018 (the Act) seeks to manage the complex and evolving national security risks of sabotage, espionage and coercion posed by foreign involvement in Australia's critical infrastructure. The Act applies to 22 asset classes across 11 sectors including: communications, data storage or processing, defence, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, water and sewerage.

The key elements of the Act are:

  • a Register of Critical Infrastructure Assets; the register builds a clearer picture of critical infrastructure ownership and control in high-risk sectors, and support more proactive management of the risks these assets face.
  • mandatory cyber incident reporting; following recent amendments to the SOCI Act, responsible entities for critical infrastructure assets may be required to report critical and other cyber security incidents to the Australian Cyber Security Centre's online cyber incident reporting portal, found at Cyber.gov.au
  • The implementation of the 2023 Critical Infrastructure Resilience Strategy

For the purpose of the Act, critical infrastructure refers to:

  • critical electricity assets
  • critical gas assets
  • critical ports
  • critical water assets
  • assets declared under clause 51 to be critical infrastructure assets, or
  • assets prescribed by the rules of the Act including;
  • Communications
  • Financial services and markets
  • Data storage or processing
  • Defence industry
  • Higher education and research
  • Energy
  • Food and grocery
  • Health care and medical
  • Space technology
  • Transport
  • Water and sewerage

Requirements for reporting entities under the act factsheet

The Security of Critical Infrastructure Act 2018 (the Act) creates specific requirements for owners and operators of critical infrastructure assets to provide information on the Register of Critical Infrastructure Assets (the Register). The Register maintains information on who owns, controls and has access to critical infrastructure assets. This information allows the Australian Government to work with critical infrastructure owners and operators to identify and manage the national security risks of espionage, sabotage and coercion. To determine if you are an owner or operator of a critical infrastructure asset, please refer to the Act and supporting documentation such as the 'Coverage of the Security of Critical Infrastructure Act 2018' Factsheet.

The 2023 Critical Infrastructure Resilience Strategy (the Strategy)

Our national security, economy and general wellbeing can be negatively impacted if any of our critical infrastructure is damaged and unavailable, owing to, for example, a natural disaster, terrorist attack or interference from a foreign actor.

Prolonged and widespread failure in the energy sector could, for example, result in:

  • shortages or destruction of essential medical supplies
  • instability in the supply of food and groceries
  • impacts to water supply and sanitation
  • impacts to telecommunications networks, leaving Australians unable to communicate easily with family and loved ones
  • disruptions to transport, traffic management systems and fuel
  • reduced services or shutdown of the banking, finance and retail sectors
  • an inability of businesses and governments to function.

We have already experienced cyber-attacks on government networks and in our transport, education and health sectors, and felt the impact of natural disasters on our critical infrastructure.

In response, the government is strengthening the Security of Critical Infrastructure Act 2018 (the SOCI Act) and enhancing regulatory frameworks to better prepare, protect and respond to threats to our critical infrastructure. See Critical infrastructure for more information.

The Critical Infrastructure Resilience Strategy

The Australian Government has produced the 2023 Critical Infrastructure Resilience Strategy to direct its work with critical infrastructure entities and all levels of government to enhance the security and resilience of Australia's critical infrastructure.

The Strategy sets out:

  • an overarching vision for critical infrastructure
  • how changes in the operating environment of critical infrastructure impact on critical infrastructure security and resilience
  • how the Strategy complements existing work across government to achieve its objectives.

Download a copy of the strategy here.

Case Study: lawful intercept

Would router hardware for a major ISP be considered part of critical infrastructure?

Does it meet the definition?

Vodafone Greece telephone exchange services were compromised with an advanced persistent threat, specifically a wiretap for a specific list of 102 phone numbers; belonging to senior government officials including Greece's Prime Minister and his wife in the lead up to and during the 2004 Olympics.

At the time, the Greek Government had no legislation that legalised listening devices on Greek citizens. The Ericsson hardware used by the Greek Government had the capability to eavesdrop on communications, but was not enabled on the hardware is it was an extra licensing cost; and not needed.

Lawful intercept - wiretap by direction of a warrant for criminal interception.

The Ericsson exchange systems were the same base station for all customers worldwide. It made provisions for Lawful intercept technology; including an RES (Remote-control Equipment Subsystem) software feature that does the actual tapping and IMS (Interception management system); user interface that commands the RES.

These systems remained on the Vodafone Greece exchange systems and were exploited with a small command that forwarded all the targeted communication recordings / SMS traffic to a specific IP address.

Would this hack meet the requirements of the Critical Infrastructure definition? Perhaps not, but what if it disrupted the Olympic games infrastructure, where hundreds of thousands of spectators, athletes and dignitaries from all over the world had congregated? Might start to look more critical then...

So how did the malware get in? Who would be capable to pull off this offensive operation? Was it an inside job (insider threat)? Listen to the Podcast and video below for all the juicy details.

More reading / listening regarding this event: https://darknetdiaries.com/episode/64/

Telecommunications (Interception and Access) Act 1979

Access to telecommunications data, and the data retention obligations under the Telecommunications (Interception and Access) Act 1979

Sections 276, 277 and 278 of the Telecommunications Act 1997 (Cth) (Telecommunications Act) establish general prohibitions on carriers and carriage service providers disclosing certain information or documents, including telecommunications data.

Chapter 4 of the Telecommunications (Interception and Access) Act 1979 (Cth) (TIA Act) provides a framework to allow the Australian Security Intelligence Organisation (ASIO) or an enforcement agency to lawfully access, disclose and use telecommunications data without breaching the Telecommunications Act.

The Telecommunications (Interception and Access) Amendment (Data Retention) Act 2015 (Cth) (Data Retention Act) introduced a framework at Part 5-1A in the TIA Act to govern the retention of a prescribed set of telecommunications data for two years by communications service providers of relevant services (see section 187A(1) and (3)).

Download Complete Volume 1 of the act. (Thanks Sara-Jayne)

Section 276

Essentially Section 276 makes it illegal to disclose or use any information obtained from a carriage service without expressed permission or requirement as directed by an authorised agency. It is also illegal to mention the knowledge of this data or disclose any data which comes to your knowledge unintendedly.

Section 277

Essentially Section 277 makes it illegal to use or disclose information similar to Section 276, but more with use use of databases and a carriage service.

Section 278

Essentially Section 278 makes it illegal for the disclosure / use of information collected in the duties of an Emergency Call Service operator.

What is telecommunications data?

Telecommunications data is information about a communication, but does not include the content or substance of the communication.

Telecommunications data is available in relation to all forms of communications, including both fixed and mobile telephony services and for internet based applications including internet browsing and voice over internet telephony. If an agency wishes to covertly obtain telecommunications data under the TIA Act, they are required to do so under an authorisation in accordance with the provisions in Chapter 4 of the TIA Act.

If an agency wishes to covertly obtain the content of a communication; as opposed to telecommunications data; the agency is required to obtain a warrant in accordance with the provisions in Chapters 2 or 3 of the TIA Act, which regulate telecommunications interception and access to stored communications respectively.

Who do these requirements affect?

Section 187A of the TIA Act stipulates that the data retention obligations apply to communications services operated by carriers, carriage service providers and internet service providers. This captures providers that own or operate infrastructure (such as servers, routers and/or cables) within Australia that enables one or more of their communications services.

Section 187B of the TIA Act provides an exemption from the data retention obligations for service providers who provide services only to a person's 'immediate circle' such as internet and intranet services provided within corporate and university networks. This reflects an assessment that the benefits to agencies of imposing data retention obligations on these networks is outweighed by the privacy and compliance burden.

Further, section 187K of the TIA Act provides that the Communications Access Coordinator may exempt a service provider from any or all aspects of their data retention obligations after having regard for such matters as the interests of law enforcement and national security, and the costs of compliance. Under current administrative arrangements, the Office of the Communications Access Coordinator sits in the Department of Home Affairs.

What data is required to be stored?

The datasets to be retained are:

  • The subscriber of, the accounts, services, telecommunications devices and other relevant services relating to, the relevant service
  • The source of a communication
  • The destination of a communication
  • The date, time and duration of a communication, or of its connection to a relevant service
  • The type of a communication or of a relevant service used in connection with a communication
  • The location of equipment, or a line, used in connection with a communication

The above list of datasets must be retained by service providers for two years in accordance with section 187C of the TIA Act.

Offences for unauthorised disclosures

Section 182 of the TIA Act creates an offence attracting a penalty of two years imprisonment where a person discloses or uses telecommunications data lawfully obtained under Chapter 4 of the TIA Act unless the use or disclosure is reasonably necessary for specified purposes. This includes (amongst others) specified purposes in connection with reporting and oversight functions, for the performance by ASIO of its functions, or for the enforcement of a criminal law (refer to section 182(2) and (3)). Similarly, section 182A of the TIA Act creates an offence for the disclosure or use of information about a journalist information warrant except for the purposes outlined in section 182B.

Access to telecommunications data under the Telecommunications Act 1997

Section 280 of the Telecommunications Act provides an exemption to the general prohibition on the disclosure of telecommunications data provided for in sections 276, 277 and 278 of that Act. Section 280 allows carriers and carriage service providers to disclose telecommunications data if the disclosure is required or authorised under law.

Agencies that are defined as enforcement agencies under the TIA Act, and many other Commonwealth, State and Territory bodies that are not enforcement agencies, may have lawful authority to access telecommunications data under Commonwealth, State or Territory laws. Section 280 enables these laws to function as intended by providing an exemption from the prohibition against disclosing telecommunications data if it is in response to a lawful request from an agency under law.

However subsection 280(1B) clarifies that telecommunications data that is kept by a service provider solely for the purposes of complying with their data retention obligations under Part 5-1A of the TIA Act, cannot be disclosed under any circumstances to those bodies that are not enforcement agencies. Accordingly, section 280 does not expand the range of agencies with access to mandatorily retained data under the TIA Act.

Artificial intelligence, the law and the security technician

The unit says nothing about artificial intelligence, because when it was accredited there was nothing settled to say. That is now the largest gap in its scope, and it is a legal gap rather than a technical one, so it belongs on this page rather than somewhere else in the certificate.

Start with the fact that surprises people, because everything else follows from it.

Australia has no AI Act, and has decided not to have one for now. The laws already covered on this page are the laws that apply to artificial intelligence. If a model leaks personal information, that is the Privacy Act. If a board deploys a system it does not understand into a function it cannot supervise, that is section 180 of the Corporations Act. If an AI-generated claim about a product is false, that is the Australian Consumer Law. If someone uses a model to gain unauthorised access to a system, that is Part 10.7 of the Criminal Code, and the fact that a machine did the typing changes nothing. Technology-neutral drafting was a deliberate choice made decades ago, and it is now doing a great deal of work.

How Australia got to that position

Worth knowing as a sequence, because the direction reversed and a lot of commentary has not caught up.

Australia's AI Ethics Principles were published in 2019: eight voluntary principles covering human wellbeing, human-centred values, fairness, privacy and security, reliability and safety, transparency and explainability, contestability, and accountability. Voluntary, and still the reference point most Australian organisations cite in their own AI policies.

On 5 September 2024 the Department of Industry, Science and Resources published a Voluntary AI Safety Standard setting out ten guardrails for organisations deploying AI, and alongside it a proposals paper on introducing mandatory guardrails for AI in high-risk settings, canvassing three regulatory options: amending existing law domain by domain, a framework approach, or a whole-of-economy AI Act.

In October 2025 that standard was itself superseded by Guidance for AI Adoption, published by the department with the National AI Centre, which condenses the ten guardrails into six essential practices while keeping the eight ethics principles underneath: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control. It comes in a Foundations version for organisations starting out and a fuller Implementation Practices version. Still voluntary, and now the document an Australian organisation is most likely to be asked to align its AI policy against.

In December 2025 the government released the National AI Plan, and the mandatory guardrails did not survive it. After more than 300 consultation responses, the decision was not to proceed with AI-specific mandatory rules at this time, and to rely instead on existing technology-neutral law supported by voluntary guidance. The Plan committed over 460 million dollars to research, skills and adoption, and established an Australian AI Safety Institute, which began operating in early 2026 as a whole-of-government hub for monitoring AI developments, advising on policy, and recommending legislative change where existing law proves inadequate.

Update, current as at September 2026. This is a live position rather than a settled one, and it is contested. The government's stated view is that existing laws are fit for purpose and should apply to AI as they do to any other technology; the counter-argument, made in a good deal of the consultation response, is that applying general law after the fact is slower and less certain than setting rules in advance. The Safety Institute has an explicit remit to recommend legislative change, which is itself an acknowledgement that the current position may not hold. Treat "no AI Act" as true as at the date on this page and worth re-checking, not as a permanent feature of the landscape.

Privacy is where AI meets this unit most directly

The OAIC has published two pieces of guidance, both dated October 2024 and last updated January 2025, and they are the most useful practical documents an Australian technician can read on this subject: one on privacy and the use of commercially available AI products, aimed at organisations deploying AI, and one on privacy and developing and training generative AI models, aimed at those building them.

The foundational point is worth stating plainly, because a surprising number of organisations have assumed otherwise. Privacy obligations apply to personal information put into an AI system and to personal information contained in the output that comes out of it. There is no exemption for text that has passed through a model.

Which Australian Privacy Principles do the work, using the numbering from the APP section above:

APP 1, open and transparent management. If the organisation uses AI in a way that affects how it handles personal information, the privacy policy has to say so.

APP 3, collection of solicited personal information. Collection must be reasonably necessary for a function or activity, and by lawful and fair means. Scraping the open web to build a training set is precisely where "lawful and fair means" is being tested. Sensitive information needs consent, and the OAIC's position is that a model generating sensitive information about a person is collecting it.

APP 5, notification. People have to be told when their personal information is collected, including where an AI system is the thing collecting it.

APP 6, use and disclosure. Personal information collected for one purpose cannot simply be repurposed as training data. The OAIC's guidance is direct on this: if personal information was collected to provide a service, using it to train a model is a secondary purpose that needs consent or a reasonable expectation, and the reasonable expectation is hard to establish.

APP 10, quality. This is the one that trips people up, because it turns hallucination into a compliance problem rather than merely an annoyance. If a model generates inaccurate personal information about a person and the organisation uses it, the organisation has an accuracy obligation it is not meeting.

APP 11, security. The reasonable steps standard applies to personal information inside AI systems as it does anywhere else, and it now has to account for the model's providers, its logging, its retention and whoever else can reach it.

The OAIC's headline practical advice, which is worth repeating to any organisation because it is simple and it prevents most of the damage: do not enter personal information, and particularly not sensitive information, into publicly available AI chatbots. Do due diligence on a product before adopting it, covering what it was trained on, what it does with input, who else can see it, and where it is hosted. Run a privacy impact assessment before deployment. Keep a human in the loop for anything affecting a person's rights. Say in your privacy policy what you are doing.

The obligation that lands in December 2026

The Privacy and Other Legislation Amendment Act 2024 introduced a transparency requirement for automated decision-making that commences on 10 December 2026. It is worth knowing precisely, because it is the first Australian statutory obligation aimed squarely at automated systems, and because it arrives shortly.

From that date an APP entity whose privacy policy is required under APP 1 must include, where a computer program is used to make a decision, or to do something substantially and directly related to making a decision, that could reasonably be expected to significantly affect an individual's rights or interests:

the kinds of personal information used in the operation of that automated decision-making technology, and

the kinds of decisions made solely by it, or for which it does substantially and directly relevant work.

Read what that does and does not require. It is a transparency obligation, not a prohibition, not a right to an explanation of an individual decision, and not a right to human review. Australia has gone considerably lighter here than the European position. What it does require is that organisations know where automated decision-making sits in their own operations, which many do not, and that they say so in public. The work it creates is an inventory, and the entities that will struggle are the ones that cannot produce one.

Definition

Automated decision-making (ADM): a decision made by a computer program without meaningful human involvement, or one where a program does work substantially and directly related to the decision. The distinction that matters legally is between a system that informs a human decision-maker who genuinely exercises judgement, and one where the human is a rubber stamp. A person clicking "approve" on forty recommendations an hour is not meaningful human involvement, whatever the process diagram says.

AI and copyright

The copyright and file sharing material earlier on this page has a live extension. The question is whether training a model on copyright works without permission infringes copyright, and Australia has answered differently from several comparable countries.

In August 2025 the Productivity Commission floated a text and data mining exception, which would have permitted copying for the purpose of training AI. In October 2025 the government ruled it out; the Attorney-General stated there were no plans to weaken copyright protections in relation to AI. The alternative path being pursued through the Copyright and Artificial Intelligence Reference Group is licensing: paid collective licensing or voluntary arrangements, clarification of how copyright applies to AI-generated material, and a small claims forum for lower-value disputes.

Two consequences worth carrying. Australia is, for now, a comparatively restrictive jurisdiction for AI training on copyright material. And the question of who owns AI-generated output remains genuinely unsettled here; Australian copyright requires a human author, so material generated without meaningful human authorship may attract no copyright protection at all, which is a commercial problem as much as a legal one.

What this means for the technician's own practice

The part that applies to the person doing the work, rather than to the organisation.

Client and employer data does not go into a consumer AI tool. This is the AI equivalent of taking a copy of a client's database home, and it is the most common way a competent person creates a notifiable data breach without noticing. Where AI assistance is genuinely useful in security work, it belongs in a tool the organisation has assessed and approved, with the retention and training settings understood.

Authorisation still governs everything. Part 10.7 of the Criminal Code makes unauthorised access, modification or impairment an offence; nothing about that turns on whether the instruction was typed by a person or issued by an agent. Pointing an autonomous tool at a system you do not have written permission to test is the same offence as doing it by hand, and the fact that the tool decided on the specific action is not a defence. If anything the risk is higher, because an agent's scope is harder to bound than a person's.

Output is verified before it is relied on. In this field that means a finding is evidenced by a request, a response and a reproduction, and a legal proposition is checked against the legislation rather than against a model's recollection of it. Fabricated citations have already embarrassed people in Australian courts.

Disclose AI use where it is material. Professional and academic contexts increasingly require it, and the direction of travel is towards more disclosure rather than less.

Update, current as at September 2026. The genuinely unsettled questions, written as the grey areas they are. It is not established how liability is apportioned when an autonomous agent acting for an organisation causes harm, and no Australian case has settled it. It is not settled what "reasonable steps" under APP 11 requires of an organisation whose data passes through a third-party model. And the evidentiary status of AI-assisted analysis in Australian proceedings has not been comprehensively tested. Where a client asks about any of these, the honest answer is that the law has not caught up, and that the practical response is to document the decision and the reasoning at the time.

Ethics in practice

The unit is called Apply cyber security legislation, privacy and ethical practices, and one of the three things it expects you to be able to do is document examples of unethical conduct by an ICT or cyber security technician and explain the potential impact of each. So ethics is a third of the unit, and it deserves more than the hacker-hat taxonomy near the top of this page.

Legal and ethical are not the same question

The distinction is the whole foundation, and it runs both ways.

Plenty of conduct is legal and unethical. Reading a colleague's emails because you hold the administrator credentials and nobody has told you not to. Retaining access to a former employer's systems because nobody revoked it. Selling a client a service they do not need by overstating the severity of a finding. Collecting far more customer data than the business uses, because storage is cheap. None of that is a criminal offence and all of it is a breach of trust.

A smaller amount of conduct is arguably ethical and clearly illegal. Testing a system you believe to be dangerously insecure, without permission, in order to warn its owner. The motive may be good; the offence is complete. This is the trap that catches well-intentioned technical people, and the answer is the one stated at the top of the cybercrime section: in Australia, testing, probing or scanning a system you do not own requires express written permission from the target, and good intentions are not a defence.

Where the two overlap is where professional judgement lives, and it is judgement rather than rule-following because the rules do not reach far enough.

The codes that apply

Cyber security in Australia is not a licensed profession, so nobody is struck off. What exists instead is a set of codes attached to membership or certification, and increasingly to employment contracts.

The Australian Computer Society's Code of Professional Ethics is the closest thing to a domestic professional standard for ICT practitioners, and it sits alongside the ACS Code of Professional Conduct. It sets out six values that members undertake to uphold: the primacy of the public interest, enhancement of quality of life, honesty, competence, professional development, and professionalism. The first is the one that does the work, because it says that where the public interest conflicts with your personal, sectional or business interests, the public interest comes first. The ACS runs a complaints and disciplinary process against the codes, which is the closest thing the Australian ICT industry has to a professional sanction.

The ISC2 Code of Ethics binds holders of CISSP and the other ISC2 certifications, and is short enough to memorise. Its four canons, in the order ISC2 states they are to be applied when they conflict: protect society, the common good, necessary public trust and confidence, and the infrastructure; act honourably, honestly, justly, responsibly and legally; provide diligent and competent service to principals; and advance and protect the profession. The ordering is deliberate and useful, because it tells you what gives way when duties collide. Your duty to your employer sits third, below your duty to the public.

Update, current as at September 2026. ISC2 published a broader Code of Professional Conduct in February 2026, built on the existing Code of Ethics and intended to describe expected practice across the profession rather than only the conduct that attracts sanction. Worth reading alongside the four canons rather than instead of them.

Beyond those, most employers have an acceptable use policy and a code of conduct, and penetration testing firms operate under engagement-specific rules of engagement, which are covered next. For anyone working with government systems, the Australian Public Service Code of Conduct or its state equivalent applies as a matter of employment law rather than professional membership.

Red team and blue team ethics

The required knowledge for this unit names red and blue team ethics specifically, and the hacker taxonomy earlier on this page describes what the teams do without addressing how they are supposed to behave. The substance sits in the engagement, not in the job title.

Written authorisation, before anything. Signed by someone with authority to give it, which is not the person who invited you in. Scope stated as address ranges, domains and systems, in and out. Dates and times. Named contacts on both sides, reachable out of hours. A statement of what happens if you find evidence of a real, prior compromise, because that changes the engagement immediately.

Scope is a boundary, not a suggestion. Systems drift, shared hosting is common, and an address in scope can front a service that is not. When you find yourself somewhere you were not authorised to go, stop and call the contact.

Minimum necessary damage. Prove the vulnerability; do not exploit it further than proof requires. Take a screenshot of one record, not a copy of the table. Denial of service is tested only when it is explicitly in scope.

Data handled as if it were yours to protect, because during the engagement it is. Encrypted storage, defined retention, secure destruction at the end, and no client data in personal tooling or personal accounts. This is where the AI point above bites hardest.

Social engineering has a consent problem the other techniques do not. Testing people means deceiving employees who have not agreed to it, and the findings identify individuals. The ethical handling is to agree in advance that results will be reported in aggregate, that no individual will be named to their manager, and that nobody is disciplined for failing a test they were not told about. An organisation that wants a list of names is asking for something else.

Findings go to the client first, and stay confidential unless the engagement says otherwise. Publishing a client's vulnerabilities, or using them as marketing, is a serious breach whatever the disclosure timeline.

For the blue team, the ethical weight sits in a different place: on monitoring. Security monitoring reads people's activity, and the same capability that finds an intruder finds an employee's private messages. The controls are purpose limitation, proportionality, access controls on the monitoring tools themselves, and notice to staff. Workplace surveillance is regulated at state and territory level in Australia and the rules are not uniform, so what is lawful in one jurisdiction may not be in another. A security team that decides this alone has made a legal decision it is not qualified to make.

Vulnerability disclosure

A recurring ethical question with no fully settled answer, which is why it is worth writing as a live debate rather than a rule.

Coordinated disclosure is the mainstream position: tell the vendor privately, agree a timeline, publish once a fix is available or the timeline expires. Full disclosure publishes immediately, on the argument that users cannot defend themselves against a threat they do not know about and vendors do not act without pressure. Non-disclosure, whether selling the finding or sitting on it, is the position the other two are arguing against.

Ninety days became the informal standard because it was long enough for most vendors and short enough to maintain pressure. As the VU23222 notes set out in more detail, that window is now under real strain: AI-assisted discovery has raised the volume of findings sharply, maintainers of open-source projects cannot process the queues, and time from disclosure to exploitation has compressed to a few days. There is no settled replacement, and the debate about what should replace it is genuinely open.

The Australian legal layer on top: finding a vulnerability in someone else's system without authorisation is an offence regardless of what you do next, and a vendor's published vulnerability disclosure policy or bug bounty program is what converts unauthorised access into authorised testing. Read the scope before you start, and do not assume that a bug bounty on one product covers another.

Examples of unethical conduct, and what each one costs

This is the assessable part of the element, so it is worth having concrete examples with their consequences rather than abstractions. Each of these is conduct by a technician, using access they were legitimately given.

Looking at records out of curiosity. Checking a celebrity's account, a neighbour's file, an ex-partner's address. Impact: a privacy breach that is notifiable if it meets the serious harm threshold, complete loss of trust in the technical team, and in health and law enforcement contexts, specific statutory offences.

Using administrative access for personal advantage. Reading colleagues' communications ahead of a restructure, accessing salary data, monitoring a partner. Impact: dismissal, likely criminal exposure, and evidence at any subsequent hearing that the organisation's access controls were ineffective.

Retaining access after leaving. Keeping credentials, a VPN profile or a personal account attached to a former employer's tenancy. Impact: continued access is unauthorised access under the Criminal Code from the moment employment ends, whether or not it is used.

Taking a copy of work on the way out. Scripts, configurations, client lists, a copy of a database "for reference". Impact: breach of confidence and probably breach of contract, and where the material is client data, a data breach the former employer must notify.

Concealing an incident. Not reporting a breach you caused, or one you found, because of how it will look. Impact: the notification clocks in the incident response section start running regardless, so concealment converts a manageable incident into a regulatory failure, and it is the single behaviour most likely to end a career in this field.

Overstating or inventing findings. Inflating severity to justify a contract, or reporting a scanner result without verifying it. Impact: the client spends money on the wrong risk, which means the right risk stays open.

Testing outside scope, or without authorisation. Impact: criminal liability, professional consequences, and the discrediting of legitimate security testing generally.

Silent surveillance. Deploying monitoring beyond what staff were told about, or repurposing security telemetry for performance management. Impact: potential breach of workplace surveillance law, and the destruction of the reporting culture the awareness material depends on, because staff who feel watched stop telling you things.

Putting client or employee data into an unapproved AI tool. Impact: an unauthorised disclosure to a third party, possibly offshore, that the organisation cannot recall, undo or fully describe when it has to write the breach statement.

Staying silent about a decision you believe is dangerous. The passive failure, and the hardest one. Impact: nothing visible, until the incident.

Did you know?

The most common finding in post-incident reviews is not that nobody knew about the weakness. It is that somebody knew, said so once, was overruled or ignored, and did not raise it again. Professional ethics in this field is mostly not about dramatic moral choices; it is about being willing to put a concern in writing a second time, and about working somewhere that does not punish you for it.

A working test

When a decision is genuinely uncertain, four questions get most people to a defensible answer.

Is it lawful? If not, stop; the rest does not arise.

Am I authorised, in writing, by someone who can authorise it?

Would I be comfortable if the person whose data this is could see exactly what I am doing, and why?

Would I be comfortable explaining this decision, at the time I made it, to a regulator, a court, or the front page?

If any answer is no, the decision needs to change or the reasoning needs to be documented and escalated to someone whose job it is to carry that risk.

The Essential Eight

Update, current as at September 2026, and read this before the detail below. The material in this section was written against the October 2021 publication of the Essential Eight Maturity Model. Two things have happened since, and the second is still unfolding.

The November 2023 revision. The maturity model was substantially rewritten in November 2023, and the changes track where the threat went. Critical vulnerabilities in internet-facing services must now be patched within 48 hours, and that applies whether or not a working exploit is known to exist, rather than only where one is available. Multi-factor authentication requirements were brought forward, so that multi-factor authentication for online access to an organisation's sensitive data now appears at Maturity Level One, with phishing-resistant methods carrying greater weight at the higher levels. Privileged access controls were tightened, with validation and periodic revalidation of privileged access requests, restrictions on privileged accounts reaching the internet and email, and requirements around break-glass accounts. A few requirements were removed, including macro execution event logging and patching obligations for lower-priority devices. Where the maturity level descriptions below differ from those, the November 2023 model is the current one.

The Essentials series, and the retirement question. On 15 June 2026 ASD opened a consultation on evolving the Essential Eight into a broader Essentials series, grounded in the Information Security Manual and offering what ASD describes as prioritised, threat-informed mitigations for contemporary technology environments. The first chapter is Essentials for enterprise IT, with chapters on operational technology and cloud foreshadowed. Consultation closed on 12 July 2026. ASD's stated reasoning is that the 2017 model was designed for on-premises Windows environments and does not translate cleanly to cloud services, shared responsibility models or software as a service; the new approach is intended to be less prescriptive, more principles-based, and to explain the adversary techniques behind each mitigation rather than only stating the mitigation.

What is settled: the consultation happened, the Essential Eight remains published and current, and ASD has said organisations already using it can expect strong alignment with their existing controls and investments. What is not settled: the retirement date. An ACSC representative has publicly described an indicative path of running both documents in parallel, beginning to deprecate the Essential Eight around twelve months from the close of consultation and retiring it around twenty-four months, but ASD has published no schedule, and that is a named official's expectation rather than a commitment.

For anyone drafting or reviewing a contract, the practical lesson is to reference ASD's current baseline guidance rather than naming the Essential Eight specifically, because a contract that names a framework outlives the framework. For anyone studying, learn the Essential Eight: it is current, it is what audits and government contracts reference, and its underlying controls are durable whatever the wrapper ends up being called.

IRAP - InfoSec Registered Assessor Program

InfoSec Registered Assessor Program is an Australian government program managed by the ASD (Australian Signals Directorate) that is a certification to be an Essential 8 authorised assessor.

More information: https://www.cyber.gov.au/irap

The mitigation strategies that constitute the Essential Eight are:

  1. application control,
  2. patch applications,
  3. configure Microsoft Office macro settings,
  4. user application hardening,
  5. restrict administrative privileges,
  6. patch operating systems,
  7. multi-factor authentication and
  8. regular backups.

While no set of mitigation strategies are guaranteed to protect against all cyber threats, organisations are recommended to implement eight essential mitigation strategies from the ACSC's (Australian Cyber Security Centre) Strategies to Mitigate Cyber Security Incidents as a baseline. This baseline, known as the Essential Eight, makes it much harder for adversaries to compromise systems.

Source: Essential 8 | cyber.gov.au.

Maturity levels

To assist organisations with their implementation of the Essential Eight, four maturity levels have been defined (Maturity Level Zero through to Maturity Level Three). With the exception of Maturity Level Zero, the maturity levels are based on mitigating increasing levels of adversary tradecraft (i.e. tools, tactics, techniques and procedures) and targeting, which are discussed in more detail below. Depending on an adversary's overall capability, they may exhibit different levels of tradecraft for different operations against different targets. For example, an adversary capable of advanced tradecraft may use it against one target while using basic tradecraft against another. As such, organisations should consider what level of tradecraft and targeting, rather than which adversaries, they are aiming to mitigate.

Organisations need to consider that the likelihood of being targeted is influenced by their desirability to adversaries, and the consequences of a cyber security incident will depend on their requirement for the confidentiality of their data, as well as their requirement for the availability and integrity of their systems and data. This, in combination with the descriptions for each maturity level, can be used to help determine a target maturity level to implement.

Finally, Maturity Level Three will not stop adversaries that are willing and able to invest enough time, money and effort to compromise a target. As such, organisations still need to consider the remainder of the mitigation strategies from the Strategies to Mitigate Cyber Security Incidents and the Information Security Manual.

Maturity Level Zero

This maturity level signifies that there are weaknesses in an organisation's overall cyber security posture. When exploited, these weaknesses could facilitate the compromise of the confidentiality of their data, or the integrity or availability of their systems and data, as described by the tradecraft and targeting in Maturity Level One below.

Maturity Level One

The focus of this maturity level is adversaries who are content to simply leverage commodity tradecraft that is widely available in order to gain access to, and likely control of, systems. For example, adversaries opportunistically using a publicly-available exploit for a security vulnerability in an internet-facing service which had not been patched, or authenticating to an internet-facing service using credentials that were stolen, reused, brute forced or guessed.

Generally, adversaries are looking for any victim rather than a specific victim and will opportunistically seek common weaknesses in many targets rather than investing heavily in gaining access to a specific target. Adversaries will employ common social engineering techniques to trick users into weakening the security of a system and launch malicious applications, for example via Microsoft Office macros. If the account that an adversary compromises has special privileges they will seek to exploit it. Depending on their intent, adversaries may also destroy data (including backups).

Maturity Level Two

The focus of this maturity level is adversaries operating with a modest step-up in capability from the previous maturity level. These adversaries are willing to invest more time in a target and, perhaps more importantly, in the effectiveness of their tools. For example, these adversaries will likely employ well-known tradecraft in order to better attempt to bypass security controls implemented by a target and evade detection. This includes actively targeting credentials using phishing and employing technical and social engineering techniques to circumvent weak multi-factor authentication.

Generally, adversaries are likely to be more selective in their targeting but still somewhat conservative in the time, money and effort they may invest in a target. Adversaries will likely invest time to ensure their phishing is effective and employ common social engineering techniques to trick users to weaken the security of a system and launch malicious applications, for example via Microsoft Office macros. If the account that an adversary compromises has special privileges they will seek to exploit it, otherwise they will seek accounts with special privileges. Depending on their intent, adversaries may also destroy all data (including backups) accessible to an account with special privileges.

Maturity Level Three

The focus of this maturity level is adversaries who are more adaptive and much less reliant on public tools and techniques. These adversaries are able to exploit the opportunities provided by weaknesses in their target's cyber security posture, such as the existence of older software or inadequate logging and monitoring. Adversaries do this to not only extend their access once initial access has been gained to a target, but to evade detection and solidify their presence. Adversaries make swift use of exploits when they become publicly available as well as other tradecraft that can improve their chance of success.

Generally, adversaries may be more focused on particular targets and, more importantly, are willing and able to invest some effort into circumventing the idiosyncrasies and particular policy and technical security controls implemented by their targets. For example, this includes social engineering a user to not only open a document but also to unknowingly assist in bypassing security controls. This can also include circumventing stronger multi-factor authentication by stealing authentication token values to impersonate a user. Once a foothold is gained on a system, adversaries will seek to gain privileged credentials or password hashes, pivot to other parts of a network, and cover their tracks. Depending on their intent, adversaries may also destroy all data (including backups).

Essential 8 mitigation strategies

Application control

Application control is one of the most effective mitigation strategies in ensuring the security of systems. This section provides guidance on what application control is, what application control is not, and how to implement application control.

What application control is

Application control is a security approach designed to protect against malicious code (also known as malware) executing on systems. When implemented robustly, it ensures only approved applications (e.g. executables, software libraries, scripts, installers, compiled HTML, HTML applications, control panel applets and drivers) can be executed.

While application control is primarily designed to prevent the execution and spread of malicious code, it can also prevent the installation or use of unapproved applications.

What application control is not

The following approaches are not considered to be application control:

  • providing a portal or other means of installation for approved applications
  • using web or email content filters to prevent users from downloading applications from the internet
  • checking the reputation of an application using a cloud-based service before it is executed
  • using a next-generation firewall to identify whether network traffic is generated by an approved application.

For more information regarding the implementation of application control, visit cyber.gov.au for more detailed information.

Patch applications

Patching applications is one of the most effective controls an organisation can implement to prevent cyber criminals from gaining access to their devices and sensitive information. Patches improve the security of applications by fixing known vulnerabilities.

Why you should implement application patching controls

Patching applications is one of the most effective controls an organisation can implement to prevent cyber criminals from gaining access to their devices and sensitive information. Patches improve the security of applications by fixing known vulnerabilities. Cyber criminals exploit vulnerabilities as soon as they are publicly disclosed so organisations should patch their applications as a priority.

Cyber criminals scan internet-facing services with automated tools that gather information about potentially vulnerable systems. This information can be used by cyber-criminals to target at-risk businesses. Regular vulnerability scanning can identify gaps in your organisation's attack surface that require patching.

Requirements for application patching

This technical example is adapted from Essential Eight maturity level one. It is designed to meet the following requirements:

  • Patches, updates or vendor mitigations for security vulnerabilities in internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.
  • Patches, updates or vendor mitigations for security vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products are applied within one month of release.
  • A vulnerability scanner is used at least daily to identify missing patches or updates for security vulnerabilities in internet-facing services.
  • A vulnerability scanner is used at least fortnightly to identify missing patches or updates for security vulnerabilities in office productivity suites, web browsers and their extensions, email clients, PDF software, and security products.
  • Internet-facing services, office productivity suites, web browsers and their extensions, email clients, PDF software, Adobe Flash Player, and security products that are no longer supported by vendors are removed.

For more information regarding the implementation of patching control, visit cyber.gov.au for more detailed information.

Configure Microsoft Office macro settings

Microsoft Office applications can execute macros to automate routine tasks. However, macros can contain malicious code resulting in unauthorised access to sensitive information as part of a targeted cyber intrusion. This publication has been developed to discuss approaches that can be applied by organisations to secure systems against malicious macros while balancing both their business and security requirements.

Introduction

Microsoft Office applications can execute macros to automate routine tasks. However, macros can contain malicious code resulting in unauthorised access to sensitive information as part of a targeted cyber intrusion.

This publication has been developed to discuss approaches that can be applied by organisations to secure systems against malicious macros while balancing both their business and security requirements.

The names and locations of Group Policy settings used in this publication are taken from Microsoft Office 2016 and are equally applicable to Microsoft 365, Office 2021 and Office 2019. Some differences however may exist for earlier versions than Microsoft Office 2016.

Background

An increasing number of attempts to compromise organisations using malicious macros have been observed. In particular, adversaries have been observed using social engineering techniques to entice users into executing malicious macros in Microsoft Office files. The purpose of these malicious macros can range from cybercrime to more sophisticated exploitation attempts.

By understanding the business requirements for the use of macros, and applying the recommendations in this publication, organisations can effectively manage the risk of allowing macros in their environments.

Macros explained
What are macros?

Microsoft Office files can contain embedded code (known as a macro) written in the Visual Basic for Applications (VBA) programming language.

A macro can contain a series of commands that can be coded or recorded, and replayed at a later time to automate repetitive tasks. Macros are powerful tools that can be easily created by novice users to greatly improve their productivity. However, an adversary can also create macros to perform a variety of malicious activities, such as assisting in the compromise of workstations in order to exfiltrate or deny access to sensitive information.

How are macros verified and trusted?

Microsoft Office has both trusted document and trusted location functions. Once trusted documents or trusted locations are defined, macros in trusted documents or macros in Microsoft Office files in trusted locations automatically execute when the files are opened. While the use of trusted documents is discouraged, trusted locations when implemented in a controlled manner can allow organisations to appropriately balance both their business and security requirements.

Microsoft Office applications allow developers to include information about themselves by digitally signing their macros. The signing certificate that is used to create a signed macro confirms that the macro originated from the signatory, while the signature itself confirms that the macro has not been altered. Digital signing certificates can be self-generated by users, obtained from a commercial Certificate Authority or obtained from an organisation's security administrator if they operate their own Certificate Authority.

How can I determine which macros to trust?

To manage the use of macros within an organisation, all macros created by users or third parties should be reviewed by an independent party to the developer and assessed to be safe before being approved for use within the organisation.

When assessing whether macros are safe or not, assessors should ask themselves the following questions:

  • Is there a business requirement for a particular macro?
  • Has the macro been developed or provided by a trusted party?
  • Has the macro been validated by a trustworthy and technically skilled party?

For more information regarding the understanding of macros, visit cyber.gov.au for more detailed information.

User application hardening

User application hardening protects an organisation from a range of threats including malicious websites, advertisements running malicious scripts and exploitation of vulnerabilities in unsupported software. These attacks often take legitimate application functionality and use it for malicious purposes. User application hardening makes it harder for cybercriminals to exploit vulnerabilities or at-risk functionality in your organisation's applications.

Why you should harden user applications

User application hardening protects an organisation from a range of threats including malicious websites, advertisements running malicious scripts and exploitation of vulnerabilities in unsupported software. These attacks often take legitimate application functionality and use it for malicious purposes. User application hardening makes it harder for cybercriminals to exploit vulnerabilities or at-risk functionality in your organisation's applications. It limits the opportunities for attacks to occur by removing unnecessary system applications and placing restrictions on application functions that are vulnerable to malicious use. Hardening applications on workstations is an important part of reducing your organisation's cyber security risk.

Requirements for user application hardening

This technical example is adapted from Essential Eight maturity level one. It is designed to meet the following requirements:

  • Web browsers do not process Java from the internet.
  • Web browsers do not process web advertisements from the internet.
  • Internet Explorer does not process content from the internet.
  • Web browser security settings cannot be changed by the users.

For more information regarding the understanding of application hardening, visit cyber.gov.au for more detailed information.

Restrict administrative privileges

This publication provides guidance on restricting the use of administrative privileges. Restricting the use of administrative privileges is one of the eight essential mitigation strategies from the Strategies to Mitigate Cyber Security Incidents.

Introduction

Restricting administrative privileges is one of the most effective mitigation strategies in ensuring the security of systems. As such, restricting administrative privileges forms part of the Essential Eight from the Strategies to Mitigate Cyber Security Incidents.

Why administrative privileges should be restricted

Users with administrative privileges for operating systems and applications are able to make significant changes to their configuration and operation, bypass critical security settings and access sensitive information. Domain administrators have similar abilities for an entire network domain, which usually includes all of the workstations and servers on the network.

Adversaries often use malicious code (also known as malware) to exploit security vulnerabilities in workstations and servers. Restricting administrative privileges makes it more difficult for an adversary's malicious code to elevate its privileges, spread to other hosts, hide its existence, persist after reboot, obtain sensitive information or resist removal efforts.

An environment where administrative privileges are restricted is more stable, predictable, and easier to administer and support, as fewer users can make significant changes to their operating environment, either intentionally or unintentionally.

Approaches which do not restrict administrative privileges

There are a number of approaches which, while they may appear to provide many of the benefits of restricting administrative privileges, do not meet the intent of this mitigation strategy, and in some cases may actually increase the risk to an organisation's network. These approaches include:

  • simply minimising the total number of privileged accounts
  • implementing shared non-attributable privileged accounts
  • temporarily allocating administrative privileges to user accounts
  • placing standard user accounts in user groups with administrative privileges.
How to restrict administrative privileges

The correct approach to restricting administrative privileges is to:

  • identify tasks which require administrative privileges to be performed
  • validate which staff members are required and authorised to carry out those tasks as part of their duties
  • create separate attributable accounts for staff members with administrative privileges, ensuring that their accounts have the least amount of privileges needed to undertake their duties
  • revalidate staff members' requirements to have a privileged account on a frequent and regular basis, or when they change duties, leave the organisation or are involved in a cyber security incident.

To reduce the risks of using privileged accounts, organisations should ensure that:

  • technical controls prevent privileged accounts from undertaking risky activities such as reading emails and opening attachments or browsing the web
  • system administration is undertaken in a secure manner by implementing the guidance in the Secure Administration publication.

For more information regarding the understanding of restricting administrative privileges, visit cyber.gov.au for more detailed information.

Patch operating systems

An automated method of asset discovery is used at least fortnightly to support the detection of assets for subsequent vulnerability scanning activities.

A vulnerability scanner with an up-to-date vulnerability database is used for vulnerability scanning activities.

A vulnerability scanner is used at least daily to identify missing patches or updates for security vulnerabilities in operating systems of internet-facing services.

A vulnerability scanner is used at least weekly to identify missing patches or updates for security vulnerabilities in operating systems of workstations, servers and network devices.

Patches, updates or vendor mitigations for security vulnerabilities in operating systems of internet-facing services are applied within two weeks of release, or within 48 hours if an exploit exists.

Patches, updates or vendor mitigations for security vulnerabilities in operating systems of workstations, servers and network devices are applied within two weeks of release, or within 48 hours if an exploit exists.

The latest release, or the previous release, of operating systems are used.

Operating systems that are no longer supported by vendors are replaced.

Multi-factor authentication

Multi-factor authentication is one of the most effective controls an organisation can implement to prevent an adversary from gaining access to a device or network and accessing sensitive information. When implemented correctly, multi-factor authentication can make it significantly more difficult for an adversary to steal legitimate credentials to facilitate further malicious activities on a network. Due to its effectiveness, multi-factor authentication is one of the Essential Eight from the Strategies to Mitigate Cyber Security Incidents.

Introduction

Multi-factor authentication is one of the most effective controls an organisation can implement to prevent an adversary from gaining access to a device or network and accessing sensitive information. When implemented correctly, multi-factor authentication can make it significantly more difficult for an adversary to steal legitimate credentials to facilitate further malicious activities on a network. Due to its effectiveness, multi-factor authentication is one of the Essential Eight from the Strategies to Mitigate Cyber Security Incidents.

Multi-factor authentication should be implemented for remote access solutions, users performing privileged actions and users accessing important (sensitive or high-availability) data repositories. Using multi-factor authentication provides a secure authentication mechanism that is not as susceptible to brute force attacks as traditional single-factor authentication methods using passwords or passphrases.

Why multi-factor authentication is important?

Adversaries frequently attempt to steal legitimate user or administrative credentials when they compromise a network. These credentials allow them to easily propagate on a network and conduct malicious activities without additional exploits, thereby reducing the likelihood of detection. Adversaries will also try to gain credentials for remote access solutions, including Virtual Private Networks (VPNs), as these accesses can further mask their activities and reduce the likelihood of being detected.

When multi-factor authentication is implemented correctly, it is significantly more difficult for an adversary to steal a complete set of credentials as the user has to prove they have physical access to a second factor that either they have (e.g. a physical token, smartcard or software certificate) or are (e.g. a fingerprint or iris scan).

When implementing multi-factor authentication, it is essential that it is done so correctly to minimise security vulnerabilities and to avoid a false sense of security that could leave a network vulnerable. For example, when multi-factor authentication is used for remote access solutions in an organisation, but not for corporate workstations, an adversary could compromise the username/passphrase from a device used for remote access and then use it to authenticate either locally to a corporate workstation or to propagate within a network after compromising an initial workstation on the network via spear phishing techniques. In such a scenario, multi-factor authentication for remote access is significantly better than single-factor authentication but does not negate the requirement for appropriately hardened devices to be used as part of a comprehensive remote access solution.

For more information regarding the understanding of restricting administrative privileges, visit cyber.gov.au for more detailed information.

Regular backups.

Our devices are home to our important data. If they are damaged, lost or destroyed, your data may be lost. Whether it's hardware failure, theft, natural disaster or a virus, recovering data can be expensive and sometimes impossible. That's why it's so important to regularly back up data. Here is some information to help you back up your data.

What is a backup?

A backup is a digital copy of your important data, such as photos, documents, and financial records. If your data is lost, you can use your backup to restore it.

You can store backups using the cloud (which is like storing the data on the internet) or on physical media (such as external hard drives).

The data you back up should be determined by how important it is to you and the impact it would have if it was lost.

Decide what to back up

You need to choose what data is important and what you want to keep safe in the event of data loss. For a business, think about the data that your business couldn't function without such as calendars, emails, customer details and financial records.

Think about all of the devices in your home or business, from your smartphones and tablets to your computers or servers. Any devices with important data should be included in your backup plan.

You should also decide how much to include in your backup. You might just want to back up your important files such as photos, documents and messages. Or, you could back up the entire system which will include your operating system, applications and all other data on your device. Backing up your entire system is known as a system image. It will take a snapshot of all data on your device so you can restore the entire system to an earlier point in time.

Back up your files regularly

Maintaining a regular backup routine can help ensure you have a safe and up-to-date copy of your files. Your routine might be hourly or daily, or maybe you only need to back up once a week or once a month. How often you make a backup depends on how frequently your data changes and how important that data is.

Use automatic back ups

You can reduce the burden of managing backups by using a service that backs up for you automatically. There are several programs and cloud storage providers that can automatically back up your files.

Check that your backups work

It's important that you regularly try to restore your backups to check that they are working properly. Testing whether you can restore your data will give you peace of mind that if you lose any data, your backup will work.

For more information regarding the understanding of back ups, visit cyber.gov.au for more detailed information.

Test your knowledge

Knowledge quizzes direct from cyber.gov.au

https://www.cyber.gov.au/learn-basics/view-resources/quiz-library

Risk assessment and management

What is risk?

Risk

noun

a situation involving exposure to danger.

verb

expose (someone or something valued) to danger, harm, or loss.

A risk is the chance of something happening that will have a negative effect.

The level of risk reflects:

  • the likelihood of the unwanted event
  • the potential consequences of the unwanted event.

What are controls?

Controls are the measures put in place to decrease the likelihood or consequences from an unwanted event.

They can:

  • prevent the unwanted event / risk.
  • reduce the effects (e.g. provide shield from hazard; event has happened but emergency response mitigation policies are being followed which can reduce the severity and duration of consequences.

What is acceptable risk?

All businesses must identify their risks (Risk Audit) and then have some method of quantifying these risks against the organisation's business plan / business goals.

Some risks have consequences that are just far too great and from a business point of view, activities that involve these risks are to be avoided at all costs.

Alternatively, some activities may have only a slight risk impact, so these risks can be managed with controls.

The risk versus likelihood matrix is a simple yet practical way for an organisation to understand and manage it's risk.

Risk management

What is risk management?

No matter how secure you make a system, it can always be broken into with sufficient resources, time and motivation. In this task, you'll look at dealing with threats through robust risk management processes.

While risks can never be eliminated, they can be identified, reduced or transferred to a third party. Risk management enables an organisation to accomplish its missions by:

  • Enabling management to make well-informed risk management decisions to justify information security-related expenditure (cost-benefit analysis)
  • Assisting management in controlling risks and exercising good stewardship (by implementing a Risk Treatment Plan, where there is a risk owner for each risk), and
  • Better securing (safeguarding the confidentiality, integrity and availability of) the organisation's information based on risk assessment and risk analysis outputs.

Some of the key questions to keep in mind when looking at risks are:

  • Threat event; What could happen?
  • Threat impact; If it happened, how bad could it be?
  • Threat frequency; How often could it happen?
  • Probability; How certain are the answers to the first three questions?

Risk management is not about creating a totally secure environment. Instead, it's about identifying where the risks are, the probability that damage could occur and the cost of securing the environment.

Completing a risk analysis

Here is a sample checklist to help you identify all the types of risks: ISO27k ISMS A5.9 information asset checklist 2022

Here is a sample internal risk audit procedure: ISO27k ISMS A5.9 information asset checklist 2022

Here is a sample completed risk audit: ISO27k ISMS 9.2 audit example

A risk analysis identifies the risks and suggests appropriate mitigation. A risk analysis will answer three key questions:

  • Identify assets; What are you trying to protect?
  • Identify threats; What do you need to protect against?
  • Calculating risks; How much time, effort and money are you willing to extend to obtain adequate protection?

After you've determined your risks, you can develop and implement the security controls needed to reduce these risks.

Useful definitions

To help you in your business, here are some commonly used risk management terms and definitions.

Term Definition Example
Asset A tangible or intangible asset Windows Server 2008
Vulnerability A weakness that may be exploited by threats No service pack installed. A service pack is a collection of updates and fixes, called patches, for an operating system or a software program.
Exposure Area subject to impact by threats Internet access is available
Threat Any action or event that may cause adverse consequences A malware or DoS attack
Threat agent The threat source Malware
Risk Probability of exploitation of a vulnerability by a threat n/a
Impact The results and consequences of a risk materialising Reputation is ruined
Countermeasure Any action or process to reduce vulnerability Installing the service pack
Control or safeguard Any action or process to mitigate risks Installing an antivirus. An antivirus is software designed to detect and destroy computer viruses

Identifying assets: what has value?

When you think about 'business' and 'value', you're usually referring to the value of the business, its assets, annual revenue, goodwill and so on, and what would be a reasonable amount to pay if someone wanted to buy the business.

But what about the items of value in the business?

A business's assets each have value and are worth protecting. You can't protect everything though; it would be too expensive; so you will need to prioritise your business assets.

Let's look at some examples of valuable business assets.

Data

Data is quite possibly your business's largest asset. Depending on the nature of your business, your data could include patient health records, details of customer spending habits, or personally identifiable information (PII). Do you know what your data is worth to your business? Do you know what it's worth to a competitor or a cyber attacker? What would it cost to replace your data?

Intellectual property

Your business might have intellectual property such as research, designs, copyright, patents, trademarks or even trade secrets. What are these worth to your business? What are they worth to a cyber attacker or a foreign intelligence service?

Funds

All businesses need funds to survive. What if a cyber attacker drained your business's bank accounts or found a way to siphon small amounts over a long period of time without being detected?

System availability

Other items of value within a business include hardware and software, including web servers, file storage, general applications and how they contribute to your system being available. What would it cost your business in lost time and productivity if a cyber attack disabled part of your network? If you provide online services, what would be the impact of your users being unable to access their accounts or the service you provide?

When you are thinking about the value of an asset, as well as the original cost of acquisition for an asset, you should factor in:

  • Cost of acquiring a replacement
  • Implementation or development costs to support a replacement
  • Current or expected cost of controls to maintain or protect the asset, and
  • Cost of impact to production and productivity if an asset is compromised.

Identifying threats: risks and attacks

There are several categories of risk for a business. Risk categories apply both in the cybersphere, in particular attacks and data misuse/loss, and to business in general.

  • Equipment malfunction; Failure of systems and devices
  • Inside/outside attacks; Hacking and cracking
  • Misuse of data; Sharing trade secrets, fraud, espionage, theft
  • Loss of data; Intentional or unintentional loss of information through destructive means
  • Application error; Computation errors, input errors and buffer overflows
  • Social status; Loss of customer base and reputation
  • Physical damage; Fire, water, vandalism, power loss, natural disasters
  • Human interaction; Accidental or intentional action or inaction that can disrupt productivity.

What motivates an attacker?

Why do cyber attackers do what they do? The greatest motivator, without a doubt, is profit. There are different ways an attacker may seek profit; this could be:

  • Directly stealing funds from bank accounts
  • Extorting money using ransomware or Denial-of-Service attacks
  • Obtaining sensitive information (e.g. financial transaction details) for the purpose of blackmail.

But it's not always about the money. Let's look at some other motivations for cyber attackers.

Access to information

Sensitive information could have military, economic and political value to the attacker or to the attacker's paying customer. Attackers could be state-sponsored or a for-profit criminal group acting on behalf of a state or corporate entity. For example, a private company that develops technology for the military could be the target of industrial espionage.

Sabotage

Cyber attackers might want to sabotage industrial control systems (ICS) such as power companies, chemical companies and water systems. These cyber attackers can be motivated by political, patriotic or ideological beliefs.

Personal reasons

Sometimes cyber attackers have more personal reasons to carry out an attack. For example, an individual could be out for revenge against their employer or former employer. They might choose to target an organisation or an individual.

Asset inventories

As part of the risk management process, you will need to create an inventory of your assets. An asset inventory captures details about assets and their owners.

Listing assets

An organisation probably already has a number of asset inventories (e.g. fixed asset register, employee list, licensed software list) but these may be spread across departments. It's good practice to collate and incorporate these into your inventory.

Once you have collated these lists, the next step is to interview managers or team leads across the organisation and ask them to describe the assets their team use; depending on the organisation, this could be as simple as asking managers or leads to list all the software and files their team stores on their computer. Existing cyber monitoring tools can be used to find further information if you are able to track connections or services being used across devices on the network.

Once you are satisfied you have an accurate asset inventory, keep it updated! When your organisation purchases new equipment, ensure it is logged in the asset inventory. Likewise, if old equipment or software is removed, record it as deactivated or destroyed in the inventory.

Asset ownership

An asset owner is normally the person who operates the asset and ensures information related to the asset is protected. As an example, a system administrator may 'own' a server, and an employee may own the files they create. When treating employees as assets, their immediate manager would be the asset owner.

Start thinking about your organisation's assets while you work through the next tasks and activities. You'll create an asset inventory in this week's tasks.

Quantitative risk analysis

Quantitative risk analysis assigns numeric and monetary values to risk components such as asset value, business impact, frequency, countermeasure costs and values and uncertainty. An example would be assigning a monetary value to the purchase of an uninterruptible power supply.

There are several formulas that are commonly associated with quantitative security risk analysis. These cover the expected loss for specific security risks and the value of safeguards to reduce the security risk.

There are three classic quantitative security risk analysis formulas:

Single Loss Expectancy (SLE)

Single Loss Expectancy is used to determine the monetary loss (impact) for each occurrence of a threatened event:

Single Loss Expectancy = Asset Value x Exposure Factor

Where the Asset Value is the value of an asset, expressed in a monetary figure and Exposure Factor represents a measure of the magnitude of loss or impact on the value of an asset, expressed as a percentage, ranging from 0 to 100%, of asset loss arising from a threat event.

Annual Loss Expectancy (ALE)

Annual Loss Expectancy is the expected monetary loss for an asset due to risk over a one-year period:

Annual Loss Expectancy (ALE) = SLE x Annual Rate of Occurrence

Where Annual Rate of Occurrence is the frequency with which a threat is expected to occur (annually).

Safeguard Value

It is useful to determine how much you are willing to spend on a safeguard (countermeasure) for a specific security risk. Safeguard Value is defined as the reduction experienced in the annual loss expectancy minus the annual cost of implementing the countermeasure:

Safeguard Value = ALE before x ALE after x Annual Safeguard Cost (TCO)

Qualitative risk analysis - probability and impact matrix

Qualitative risk analysis combines opinions with the use of a rating system, applied to different scenarios. An example is applying a rating of High, Medium, Low or Insignificant to the risk of a particular event occurring combined with the damage it could cause.

In this course we will often focus on qualitative analysis, which is a common approach and is easier to complete with the information you will have access to.

A common approach to qualitative analysis is a probability and impact matrix.

Using this tool, you assign values to both the probability of a risk occurring and the impact if that risk were to occur.

risk matrix

Probability rankings typically range from 1 to 5, increasing in certainty:

  1. = Rare
  2. = Unlikely
  3. = Possible
  4. = Likely
  5. = Almost certain

Impact rankings typically range from 1 to 5, increasing in severity:

  1. = Insignificant
  2. = Minor
  3. = Moderate
  4. = Major
  5. = Severe

After the rankings for probability and impact are determined, the matrix identifies the total risk by combining the two inputs:

Risk ranking = Probability x Impact

This results in a final risk rating for each asset/threat. Using the scales above, the overall risk rankings will range from 1 to 25 and can be categorised as:

Risk Ranking Classification Possible Action
1-4 Insignificant risk No action required
5-9 Low risk Manage by routine procedures
10-14 Moderate risk Specify management responsibility
15-19 High risk Needs attention from senior management
20-25 Extreme risk Detailed planning or action required

Case study: Space Shuttle Challenger

On January 28, 1986, the Space Shuttle Challenger broke apart 73 seconds into its flight, killing all seven crew members aboard. The spacecraft disintegrated 46,000 feet (14 km) above the Atlantic Ocean, off the coast of Cape Canaveral, Florida, at 11:39 a.m. EST (16:39 UTC). It was the first fatal accident involving an American spacecraft while in flight.

The cause of the disaster was the failure of the primary and secondary redundant O-ring seals in a joint in the shuttle's right solid rocket booster (SRB). The record-low temperatures the morning of the launch had stiffened the rubber O-rings, reducing their ability to seal the joints. Shortly after liftoff, the seals were breached, and hot pressurized gas from within the SRB leaked through the joint and burned through the aft attachment strut connecting it to the external propellant tank (ET), then into the tank itself. The collapse of the ET's internal structures and the rotation of the SRB that followed threw the shuttle stack, traveling at a speed of Mach 1.92, into a direction which allowed aerodynamic forces to tear the orbiter apart. Both SRBs detached from the now-destroyed ET and continued to fly uncontrolled until the range safety officer destroyed them.

Greater complexity equals greater risk

With complexity comes more points of failure / risk. Any additional part to any system may present a risk to the overall system as a whole. Every single part needs to be engineered for expected usage, and usage expected outside of those tolerances; many with redundancy built in.

O-Ring concerns

Evaluations of the proposed SRB design in the early 1970s and field joint testing showed that the wide tolerances between the mated parts allowed the O-rings to be extruded from their seats rather than compressed. This extrusion was judged to be acceptable by NASA.

Joint rotation, which occurred when the tang and clevis bent away from each other, reduced the pressure on the O-rings, which weakened their seals and made it possible for combustion gases to erode the O-rings. NASA engineers suggested that the field joints should be redesigned to include shims around the O-rings, but they received no response.

Were the risks evaluated correctly?

The first occurrence of in-flight O-ring erosion occurred on the right SRB on STS-2 in November 1981. In August 1984, a post-flight inspection of the left SRB on STS-41-D revealed that soot had blown past the primary O-ring and was found in between the O-rings. Although there was no damage to the secondary O-ring, this indicated that the primary O-ring was not creating a reliable seal and was allowing hot gas to pass. The amount of O-ring erosion was insufficient to prevent the O-ring from sealing, and investigators concluded that the soot between the O-rings resulted from non-uniform pressure at the time of ignition.

Are environmental factors a part of the risk assessment?

The January 1985 launch of STS-51-C was the coldest Space Shuttle launch to date. The air temperature was 62 °F (17 °C) at the time of launch, and the calculated O-ring temperature was 53 °F (12 °C). Post-flight analysis revealed erosion in primary O-rings in both SRBs.

Source: Much of the technical information in this case study is from: https://en.wikipedia.org/wiki/Space_Shuttle_Challenger_disaster

No matter how strong a chain looks, it's strength is defined by the strength of it's weakest link.

-Stanislav Gritsienko

Epoch clock: 1,684,301,461

ISO 31000 – risk management methodology

The International Standards Organisation (ISO) is an independent, non-governmental, international organisation set up to create specifications for products, services and systems, to ensure quality, safety and efficiency. ISO have published over 20,000 International Standards and related documents, covering almost every industry, from technology and food safety to agriculture and healthcare.

Implementing a risk management methodology

The following risk management framework is based on the ISO 31000 Standard. Consistent application of this process enables continuous improvement in decision making and performance:

risk management chartSource: ISO

To understand what is happening at each section:

Communication and consultation

Communication and dialogue with internal and, if appropriate, external stakeholders as far as necessary should take place at each stage of the risk management process.

Establishing the context: This defines the internal and external parameters to be taken into account when managing risk and setting the scope and risk criteria for the remaining process.

Risk identification

The purpose of this step is to generate a comprehensive list of risks based on those events that might enhance, prevent, degrade or delay the achievement of the organisation's objectives.

Risk analysis

Risk analysis is about developing an understanding of a risk by considering the causes and sources of the risk, its positive and negative consequences and the likelihood that those consequences can occur. Existing risk controls and their effectiveness should be taken into account.

Risk evaluation: The purpose of risk evaluation is to assist in making decisions, based on the outcomes of risk analysis, about which risks are unacceptable and need treatment, and about how to prioritise implementing treatments for those risks.

Risk treatment: This involves selecting one or more options for modifying unacceptable risks and implementing those options. Risk treatment options include accepting the consequences of a risk, taking action to avoid it, mitigating against it (changing the likelihood or consequences), or transferring the risk to another party.

Monitoring and review: This step should encompass all aspects of the risk management process to:

  • Analyse and learn lessons from events, changes, and trends
  • Detect changes in the external and internal context including changes to the risk itself
  • Ensure that the risk controls and treatment measures are effective in both design and operation
  • Identify emerging risks.

Dealing with risk

There are four ways you can deal with risk; accept, avoid, mitigate or transfer. This applies to all types of risk, not just cybersecurity.

Let's look at these options in more detail and why an organisation might choose a particular option.

chart of actions

Accept

Accepting a risk is an informed decision to not take any action at all. An organisation might decide the risk is either so unlikely, or the impact is so low, it becomes too impractical or expensive to treat. This may be because the organisation finds that:

  • The risk level is low
  • The necessary personnel are not available
  • The financial resources are not available
  • The cost of implementing the control exceeds the perceived or actual cost of a security breach, or
  • The control or process will not align with organisation's culture.

The decision whether accept a risk will depend on your business's risk appetite. A risk that has the potential to cost $1 million in a three year period may be of little concern to a large, international organisation, but for a small start-up this could be catastrophic.

If there is a decision to accept a risk, you will need to develop an incident management plan to deal with the consequences of the risk if it occurs.

Avoid

To avoid a risk, an organisation may decide to stop an activity, or not start it in the first place, to prevent exposing the organisation to the risk.

Decisions to avoid risk will need to be considered alongside an organisation's strategic goals. In a simplified example, a small online shop believes that personalised recommendations would improve sales, but in order to do this it will need to create user accounts and store personal information about its customers. As with an organisation that decides to accept a risk, the shop's reasons to avoid risk include a lack of necessary technical skills and financial resources to store customer information securely. Instead, it decides to provide generic recommendations that do not require capturing personal information.

An organisation can also avoid risk if it's able to eliminate a threat or vulnerability.

Mitigate

Mitigating, or reducing, risk is where an organisation implements controls to reduce:

  • The likelihood of the risk occurring, or
  • The consequences of the risk occurring..

When reducing the likelihood of a risk, this does not necessarily mean eliminating the risk, but reducing the probability to an acceptable level. There are a number of ways to reduce the likelihood of a risk occurring, including:

  • implementing, or improving, quality control processes
  • implementing, or improving, prevention techniques
  • auditing
  • ensuring compliance with legislation
  • staff training
  • regular maintenance schedules, and
  • changes to procedures.

In order to reduce the consequence of a risk occurring, an organisation could:

  • Implement and test an Incident Response Plan
  • Ensure regular backups are taken and are adequately separated from production systems, and
  • Involve their public relations team to create incident disclosure plans.

Transfer

Some risks can be transferred to a third party. In this case the CISO:

  • Is responsible for ensuring that the responsibilities that have been discharged are appropriate to the risk and that the third parties are fully aware of their responsibilities, and
  • Undertakes an audit of the third party and the controls in place to verify they are appropriate and meet contractual obligations.

Examples of transferring risk include insurance, outsourcing, joint ventures and partnerships.

Note that while insurance is often cited as a way of transferring risk, Rick Howard of Palo Alto Networks includes this measure as a mitigation strategy. Regardless of its category, if your business is going to take out insurance, be sure that you're clear about what the insurer will and won't pay out for in the event of a cyber attack.

Determine the risk treatment plan

Given the options for dealing with risk, an organisation should establish and maintain a Risk Treatment Plan (RTP). The RTP is designed to identify priorities, starting with the risk scores and making adjustments based on the organisation's appetite for different types of risk.

Once risks have been ordered by priority, the RTP is used to capture information on how the organisation will approach each risk and responsibilities for implementation. For each risk the plan will capture:

  • Possible risk treatment options (accept, avoid, mitigate, transfer)
  • The preferred option, and
  • Expected risk rating after treatment.

When creating the RTP, an organisation may choose to do a cost-benefit analysis (CBA) on each treatment option and either accept or reject the option. A CBA compares the cost of a safeguard with the cost of not adding a safeguard. Safeguards should not be used if the cost outweighs the potential loss.

Cost Benefit

A CBA can be done to ensure:

  • The cost of the safeguard doesn't outweigh its benefit
  • The best safeguard is provided for the implementation cost
  • The budget is justified, and
  • Investments in cybersecurity technologies are based on value.

If conducted, the outcome of a CBA and decision to accept or reject a safeguard should be recorded in your plan.

For each agreed action, the RTP will document the person responsible for the implementation and expected completion date. It's good practice to establish how the risk and treatment option will be monitored in the RTP.

Cloud computing and the shared responsibility model

The "cloud" refers to a pool of hardware and software resources that can be rapidly provisioned in an automated, on-demand manner.

A model for enabling ubiquitous, convenient, on-demand network access to a shared pool of configurable computing resources (such as networks, servers, storage, applications, and services) that can be rapidly provisioned and released with minimal management effort or service provider interaction.

With the use of cloud computing technologies, your environment can evolve from a fixed environment where applications run on dedicated servers, toward a dynamic and automated environment. This is where pools of computing resources are available to support application workloads that can be accessed anywhere, any time, from any device.

Let's look at the three main cloud computing models.

Infrastructure-as-a-Service (IaaS)

IaaS provides you with computing infrastructure, physical or virtual machines and other resources such as virtual-machine disk image libraries, block and file-based storage, firewalls, load balancers, IP addresses and virtual local area networks.

Examples of IaaS include Amazon EC2, Windows Azure, Rackspace and Google Compute Engine.

Platform-as-a-Service (PaaS)

PaaS provides you with computing platforms such as operating systems, programming language execution environments, databases and web servers.

Examples of PaaS include AWS Elastic Beanstalk, Windows Azure, Heroku, Force.com, Google App Engine and Apache Stratos.

Software-as-a-Service (SaaS)

SaaS provides you with access to application software, often referred to as on-demand software. You don't have to worry about the installation, setup and running of the application. The service provider will do that for you. You just have to pay and use it through a client.

Examples of SaaS include Google Apps and Microsoft Office 365.

Benefits and challenges of cloud computing

Cloud computing solutions have several benefits to an organisation, for example:

  • You can pay as you go
  • They are scalable solutions that support rapid business growth
  • There is cost transparency to the end user or business
  • There is lower time to market for IT solutions
  • You can outsource competencies that are not core to the business
  • There is no separate cost for tracking and installing operating system patches
  • It's not limited to basic website hosting.

However, there are some challenges you should be aware of and consider as part of your risk management strategy. The challenges include:

  • Loss of physical control
  • Emerging security models and standards
  • Availability concerns, including the outsourcer's ability to react quickly to issues (consider how critical the application or data
  • you have on the cloud is, and plan for the worst)
  • Data privacy implications, e.g. the data could be in another country
  • Knowing who is responsible for what when a security breach happens
  • Possible extension of your organisation's trusted boundaries
  • Isolation/security between virtual machines
  • Evolving customer support practices
  • Browser vulnerability, and
  • Vendor failures.

The shared responsibility model

Cybersecurity remains a significant challenge when you embrace the cloud computing environment. The security risks that threaten your organisation today don't change when you move to the cloud.

The shared responsibility model defines who is responsible for what in the public cloud. In general terms, the cloud provider is responsible for the security of the cloud, including the physical security of the cloud data centres, and foundational networking, storage, compute, and virtualisation services. The cloud customer is responsible for security in the cloud, which is further delineated by the cloud service model.

Let's look at how the responsibility is shared between customer and vendors across the three cloud computing models.

IaaS

In an IaaS model, the customer is responsible for the security of the operating systems, middleware, runtime, applications, and data.

PaaS

In a PaaS model, the customer is responsible for the security of the applications and data and the cloud provider is responsible for the security of the operating systems, middleware, and run time.

SaaS

In a SaaS model, the customer is responsible for the security of the data only and the cloud provider is responsible for the full stack from the physical security of the cloud data centres to the application.

Good practices for using the cloud

Best practice in the cloud varies across each model and between vendors, however, there are some general recommendations that should be kept in mind when working with the cloud. This includes:

  • Encrypt sensitive data such as PII before sending it to the cloud.
  • Keep a formal process for sharing information and communicating in case of security and privacy incidents.
  • Use a secure connection when connecting to the cloud, whenever sensitive data is exchanged.
  • Integrate access to cloud computing resources with the organisation's identity and access management process.
  • Use multi-factor authentication (MFA).
  • Review the cloud service's independent review reports and certification.

How safe is the cloud?

Now you've learned about cybersecurity in the cloud, take a moment to discuss this with your peers. Think about the following:

  • How safe do you think the cloud is? For example, would you be comfortable if all of your personal data was backed up in the cloud?
  • What are some points or opinions from the 'Cybersecurity in the cloud' video that resonated with you?
  • Would these points make you look at doing anything differently regarding your own cloud security or that of your business?
Global standards: ISO/IEC 27001 and 27701

ISO/IEC 27001

ISO/IEC 27001 is an international standard on how to manage information security. The standard was originally published jointly by the International Organization for Standardization and the International Electrotechnical Commission in 2005 and then revised in 2013 and then again in 2022. The 2005 and 2013 are now non-compliant.

It details requirements for establishing, implementing, maintaining and continually improving an information security management system (ISMS); the aim of which is to help organisations make the information assets they hold more secure.

A European update of the standard was published in 2017. Organisations that meet the standard's requirements can choose to be certified by an accredited certification body following successful completion of an audit. The effectiveness of the ISO/IEC 27001 certification process and the overall standard has been addressed in a large-scale study conducted in 2020.

Source: Wikipedia

Here is a simple one page FAQs regarding this standard: ISO27k ISMS 7.3 FAQ one pager 2022.

Business case for an Information Security Management System (ISMS) based on the ISO/IEC 27000 family of standards

Benefits

The ISMS will bring information security under firm management control, allowing direction and improvement where needed. Better information security will reduce the risk (probability of occurrence and/or adverse impacts) of incidents, cutting incident-related losses and costs.

Other benefits of the ISMS include:

  • A structured, coherent and professional approach to the management of information security, aligned with other ISO management systems
  • Comprehensive information security risk assessment and treatment according to business and security priorities
  • Focuses information security investment to greatest advantage
  • Demonstrable governance using internationally-recognised good security practices

Costs

Most of the costs associated with information security would be incurred anyway since information security is a business and compliance imperative. The additional costs specifically relating to the ISMS are mainly:

  • Resources needed to design, implement and operate the ISMS, including project management for the implementation project
  • Changes needed to bring various business processes and activities in line with the ISO standards
  • Third party audits (optional; only required if we decide to go for certification, a decision that can be delayed until the ISMS is working)

The ISMS ISO 27001:2022 Standard

Reference: ISMS ISO 27001:2022 Standard

Download a complete PDF copy of the older standard ISO 27001:2013(E) standard here.

Key benefits

IDENTIFY INFORMATION SECURITY RISKS and implement appropriate organisational controls with ISO 27001 IMPLEMENT COMPREHENSIVE INFORMATION SECURITY POLICY specific to your business context and stakeholder needs SAFEGUARD YOUR REPUTATION by protecting customer information and reducing the risk of information security breaches ASSURE CUSTOMERS, REGULATORY BODIES AND STAKEHOLDERS of your information security processes by certifying to ISO 27001

ISO 27001 provides comprehensive guidance and support to systematically understand your information security risks and vulnerabilities. By implementing ISO 27001, you can apply rigorous information security methodologies, reducing risks and safeguarding against security breaches.

ISO 27001:2022

Title: Security techniques - Extension to ISO/IEC 27001 and ISO/IEC 27002 for privacy information management - Requirements and guidelines (ISO/IEC 27701:2019, MOD)

This new revision of the:2013 standard was released in 2023 and is now current. You can download a presentation outlining the differences in the two standards here. (Source: MSECB Management Systems Inc.)

AS 27701: 2022 Security techniques - Extension to ISO/IEC 27001

The International ISO27001 standard covers the implementation of corporate policies designed to ensure an organisation has adequate policies in place to meet the growing demands of information security in the future.

With the many data breaches recently occurring not only here in Australia, but world-wide, it has become evident that organisations create, implement and review all existing data security policies.

Some recent high profile data breaches

  • Optus data breach
  • 9.8 Million customer's data was compromised
  • Data included various amounts of sensitive data including 17,000 Medicare numbers
  • Many driver's license numbers were included.
  • Hackers released an initial 10,000 records as a proof of data acquisition and as a threat that if a ransom demand isn't paid, the rest will be published.
  • The security vulnerability was known to Optus.
  • The security vulnerability was a low-level technical exploit from an obsolete API (Application Programming Interface).
  • Medibank Data Breach
  • Sensitive data was stolen including healthcare claims
  • Hackers have published 100 individual policies of customers as a proof of data.
  • Data included first names and surnames, addresses, dates of birth, Medicare numbers, policy numbers, phone numbers and some claims data.
  • Medibank can not confirm the number of records that were compromised from it's 3.8 million records.
  • Hackers intend to release the sensitive medical records / medical conditions / addictions of targeted individuals, being those who have the most followers on social media, including politicians, actors, bloggers, LGBT activists etc.
  • Crypto.com Crypto Theft
  • 500 wallets compromised
  • Hackers stole $18Mil (USD) Bitcoin and $15Mil or Ethereum
  • Sim Swapping was used to bypass the 2FA.
AML/CTF, digital currencies and Know Your Customer

Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Act

Downloads:

What is the AML/CTF Act?

The Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act) is the main piece of Australian government legislation that regulates AUSTRAC's functions.

Update, current as at September 2026. This regime has just been through the largest change in its history, and the material below describes the position before it. The Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 passed on 29 November 2024 and extended the regime to what is universally called tranche two: roughly 90,000 new reporting entities across real estate professionals, professional service providers including lawyers, accountants and trust and company service providers, and dealers in precious metals and stones. New entities had to enrol with AUSTRAC by 31 March 2026, which is also when the reformed obligations began for existing reporting entities, and the full obligations for tranche two entities commenced on 1 July 2026.

Alongside the new sectors, the reforms rebuilt the obligations themselves: an explicit duty on the governing body to take reasonable steps to ensure the business identifies, assesses, manages and mitigates money laundering and terrorism financing risk; a redesigned customer due diligence framework; a revised risk assessment requirement; changes to value transfer reporting; and a new "reporting group" concept replacing the old designated business group.

Why it matters to a cyber security technician, which is the connection this unit cares about. Ninety thousand organisations that had never before been required to collect and verify identity documents are now required to do so, which means ninety thousand new stores of exactly the identity data that made the 2022 breaches so damaging. Many are small firms with no security function. The intersection of AML obligations and Australian Privacy Principle 11 is now a live problem in a lot of small businesses, and someone has to advise them.

Your obligations under the AML/CTF Act

If you provide one or more designated services as prescribed in the AML/CTF Act, you must enrol with AUSTRAC and comply with the obligations set out in the AML/CTF Act. You must also register with AUSTRAC if the designated service you provide includes remittance service or digital currency exchange service:

Once you have enrolled with AUSTRAC, they provide detailed guidance to help you comply with your obligations relating to:

An extract from the industry specific guidance:

Preventing the criminal abuse of digital currencies

This guide provides financial indicators to help businesses, including digital currency exchange providers, recognise and report criminal activity through digital currencies.

Digital currencies are increasing in value and acceptance as Australians have rapidly taken up this new technology. Digital currencies and blockchain technology enable digital transactions and financial products and services in new online networks, environments and marketplaces.

Criminals are attempting to take advantage of the rapid take-up of digital currencies to commit crimes and hide from law enforcement. The pseudo-anonymous and borderless nature of digital currencies can make them a risk for criminal activity including money laundering, terrorism financing, ransomware and more.

Download a copy of the PDF from the austrac.gov.au website: Preventing the Criminal Abuse of Digital Currencies - The Financial Crime Guide

Know Your Customer (KYC) requirements.

KYC and being familiar with your customers' typical financial transactions makes you aware of any unusual or suspicious activity and reduces the risk of your business or organisation being exploited for money laundering or terrorism financing purposes.

This is important to Cyber Security professionals as your organisation / customers whom you manage their digital security may have legislative requirements to collect sensitive personal information about their customers and it's this information which is valuable in the eyes of an CS aggressor.

Vulnerabilities in this area more affect critical infrastructure entities who have a requirement to collect and maintain large volumes of customer data.

Who needs to report?

A service that is listed in section 6 of the AML/CTF Act(Anti-Money Laundering and Counter-Terrorism Financing Act 2006) (because it has been identified as posing a risk for money laundering and terrorism financing) and which meets the geographical link. Designated services include a range of business activities in the financial services, bullion, gambling and digital currency exchange sectors. Entities that provide any of these services are reporting entities. Reporting entities have obligations under the AML/CTF Act.

You must document the customer identification procedures you use for different types of customers. The procedures you use must be based on the level of money laundering/terrorism financing risk that different customers pose.

You must check a customer's identity by collecting and verifying information before providing any designated services to them. You must identify both individual customers (people) and non-individual customers (such as companies, associations or trusts).

After checking a customer's identity you must be satisfied that:

  • an individual customer is who they claim to be
  • a customer who is not an individual is a real entity (a business or organisation that actually exists) and you know the details of its beneficial owners.

Extract from the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 legislation

Part 2 - Division 4 - Identification procedures etc.

Section 32 Carrying out applicable customer identification procedure before commencement of provision of designated service

(1) A reporting entity must not commence to provide a designated service to a customer unless the reporting entity has carried out the applicable customer identification procedure in respect of the customer.

Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Complete)

Digital Currencies

Quick overview

A digital currency is a medium of exchange that is generated, stored and transferred electronically. Digital currencies are not typically associated with any country's government or represented in physical forms like the coins and notes of traditional currencies.

Cryptocurrencies, the most common category of digital currency, are the type that comes to mind for most people when they hear the term. Cryptocurrencies rely on encryption to secure the processes involved in generating units and conducting transactions. They are used similarly to conventional money for purchases online and in person and are accepted by an increasing number of sellers.

The first widely-adopted cryptocurrency, Bitcoin, relies on blockchain's distributed ledger model to prevent a single point of failure and to ensure that the record of transactions is tamper-proof. Most other well-known cryptocurrencies also use blockchain and the technology is being explored in many industries as a secure and cost-effective way to create and manage a distributed database and maintain records for digital transactions of all types.

Cryptocurrencies are essentially digital tokens. They are a type of digital currency that allows people to make payments directly to each other through an online system. Cryptocurrencies have no legislated or intrinsic value; they are simply worth what people are willing to pay for them in the market. This is in contrast to national currencies, which get part of their value from being legislated as legal tender.

Virtual currencies, another subset of digital currencies, are mediums of monetary exchange that are confined to particular software-based environments. Think of in-game money, or customer reward points etc.

What is Blockchain?

A blockchain is a distributed database or ledger that is shared among the nodes of a computer network. As a database, a blockchain stores information electronically in digital format.

One key difference between a typical database and a blockchain is how the data is structured. A blockchain collects information together in groups, known as blocks, that hold sets of information. Blocks have certain storage capacities and, when filled, are closed and linked to the previously filled block, forming a chain of data known as the blockchain. All new information that follows that freshly added block is compiled into a newly formed block that will then also be added to the chain once filled.

What is Blockchain Architecture?

Blockchain is a technology where multiple parties involved in communication can perform different transactions without third-party intervention. Verification and validation of these transactions are carried out by special kinds of nodes.

Benefits of Blockchain:

  • It is safer than any other technology.
  • To avoid possible legal issues, a trusted third party has to supervise the transactions and validate the transactions.
  • There's no one central point of attack.
  • Data cannot be changed or manipulated, it's immutable.
Structure of Blockchain

  1. Header: It is used to identify the particular block in the entire blockchain. It handles all blocks in the blockchain. A block header is hashed periodically by miners by changing the nonce value as part of normal mining activity, also Three sets of block metadata are contained in the block header.
  2. Previous Block Address/ Hash: It is used to connect the i+1th block to the ith block using the hash. In short, it is a reference to the hash of the previous (parent) block in the chain.
  3. Timestamp: It is a system verify the data into the block and assigns a time or date of creation for digital documents. The timestamp is a string of characters that uniquely identifies the document or event and indicates when it was created.
  4. Nonce: A nonce number which uses only once. It is a central part of the proof of work in the block. It is compared to the live target if it is smaller or equal to the current target. People who mine, test, and eliminate many Nonce per second until they find that Valuable Nonce is valid.
  5. Merkel Root: It is a type of data structure frame of different blocks of data. A Merkle Tree stores all the transactions in a block by producing a digital fingerprint of the entire transaction. It allows the users to verify whether a transaction can be included in a block or not.

What is Central Bank Digital Currency?

A Central Bank Digital Currency (CBDC) can most easily be understood as a digital form of cash. It can be issued by the central bank, accessible to the general public, and used to settle transactions between firms and households. The unit of account would be the national currency, and it could be exchanged at parity (i.e. one for one) with other forms of money, such as physical currency or electronic deposits with well-regulated financial institutions.

What are the main differences between cryptocurrencies and CBDCs? In other words, what makes a CBDC money? A central bank has the ability to ensure that a digital currency it issues exhibits the three main features of money; that is, a CBDC could function as a widely accepted means of payment, store of value and unit of account.

Because it is issued by a central bank, a CBDC would have legal tender status, making it widely accepted as a means of payment. A CBDC would also be an equivalent store of value to other forms of money, since it could be exchanged for an equal value of physical cash or electronic deposits. Finally, the unit of account for CBDC issued by the Australian Reserve Bank would be the Australian dollar. This means it could be used to measure the value of goods and service. These and other key features have been summarised in the table below.

Features of Money: Cryptocurrency versus CBDCs

CHARACTERISTIC CRYPTOCURRENCIES CBDCs
Means of payment Accepted by a small number of retailers Universally accepted, legal tender
Store of value Tend to be volatile, depends on market price Stable, consistent with central bank price stability mandate
Unit of account Own unit of account Fiat currency (e.g. Australian dollars)
Governance Typically decentralised, relies on consensus between large number of entities. Centralised
Transaction verification Typically a large number of competing entities Small number of trusted entities

Case study: Bangladesh Bank heist

This story is about a bank robbery with the objective to steal 1 billion dollars. Which makes this the largest bank robbery in history. And it was all done over a computer.

Think big! Now, who would have $1B but also be a soft target?

The robbers knew that national banks would have a large amount of money like this, like a country's reserve bank, so they started looking around for what national banks might be a good target. They chose the Bangladesh Bank. This was an interesting target to choose as far as central banks go. Bangladesh has a growing economy and is starting to really flourish, but it's still a developing nation and its central bank doesn't have the best security. I don't know, which might make this an easier target than a more developed nation's national bank, like the US Federal Reserve Bank. The Bangladesh Bank became the target.

What is the national bank of Bangladesh? It's like the Federal Reserve Bank or the Bank of England. It's like the country's bank. Billions of dollars of reserve currency is sitting in there.

The Phish!

It starts a full year before. January 2015, the first e-mail started popping up inside Bangladesh Bank. A few employees get the classic phishing e-mail; it's a zip file that contains a CV for somebody who looks like a job applicant. Opens the zip file, has a look at the CV or perhaps doesn't ever get the CV but nonetheless, they get infected. Three people opened the e-mail in Bangladesh Bank and at least one of them got infected.

Swift

In order to transfer money, banks have this system called SWIFT. SWIFT is the international bank transfer system. There's an international bank version of that which transfers millions, billions of dollars around the world.

The thing about SWIFT is that it's pretty secure. It is secure. It has to be because it's handling this very sensitive financial communications. It's practically impossible to hack but as with all computers, there is a weakness and one of the biggest weaknesses is human error. Hackers rooted around the Bangladesh Bank network looking for the right computer that can authorize bank transfers. Of course, they find it; the computer authorized to make SWIFT transfers. Bingo. Instead of trying to hack into the SWIFT system, they got to the human users of the computer terminals that ran SWIFT. They watched how the users interacted with it and they learned how to impersonate those human users, and then trick the SWIFT network into thinking that they were authorized users making real transaction requests.

Not only did they know how to run SWIFT, but they knew what to type into SWIFT to make the transfers look legit. They had all this almost in advance. It was almost like how they knew how SWIFT ran.

It's all about timing...

In May 2015, five bank accounts were opened in the RCBC Bank on Jupiter Street in Manila, the capital of the Philippines. Each of these accounts were opened with an initial five hundred-dollar deposit. These accounts sat untouched for nearly a year until the weekend of February 5th, 2016. By that point, the bank robbers had everything set up.

Now, they're ready to roll. On February 3rd, 2016, the hackers entered the Bangladesh Bank network one more time. It was a Thursday. They waited for the bank to close that night and as soon as it did, they made the keystrokes needed to get into the SWIFT terminal. See, the Bangladesh Bank actually has a lot of money in the US Federal Reserve Bank, so they accessed the Bangladesh Bank account in the New York Federal Reserve Bank and started making transfers to thirty-six of the hacker's bank accounts all over the world. The thirty-six transactions totaled 951 million dollars. Now, the timing of this transaction was perfect; a Thursday night in Bangladesh.

In an already really well thought-out, elaborate plan, the timing was a stroke of genius because it meant that not only are the hackers dealing with a long weekend, but they're also taking advantage of…

Three time zones, here; you've got Bangladesh Bank which is the bank that's been hacked into where the money's gonna be transferred from, you've got where the actual money is which is New York, which is obviously a different time zone, and you've got where the money is going which is the Philippines which is yet another time zone. What they did was played these three time zones to their advantage.

Hear the full podcast here - Darknet Diaries Ep. 72

A YouTube version of the same story / event / incident

Corporations Act 2001 and directors' duties

Corporations Act 2001

Corporations Act 2001; Australian Securities and Investments Commission (ASIC) Regulatory Guide 104: Licensing: Meeting the general obligations.

CORPORATIONS ACT 2001 - SECT 180

Care and diligence--civil obligation only

Care and diligence--directors and other officers

  • (1) A director or other officer of a corporation must exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would exercise if they:
  • (a) were a director or officer of a corporation in the corporation's circumstances; and
  • (b) occupied the office held by, and had the same responsibilities within the corporation as, the director or officer.

Note: This subsection is a civil penalty provision (see section 1317E).

Business judgment rule

  • (2) A director or other officer of a corporation who makes a business judgment is taken to meet the requirements of subsection (1), and their equivalent duties at common law and in equity, in respect of the judgment if they:
  • (a) make the judgment in good faith for a proper purpose; and
  • (b) do not have a material personal interest in the subject matter of the judgment; and
  • (c) inform themselves about the subject matter of the judgment to the extent they reasonably believe to be appropriate; and
  • (d) rationally believe that the judgment is in the best interests of the corporation.

The director's or officer's belief that the judgment is in the best interests of the corporation is a rational one unless the belief is one that no reasonable person in their position would hold.

Note: This subsection only operates in relation to duties under this section and their equivalent duties at common law or in equity (including the duty of care that arises under the common law principles governing liability for negligence)--it does not operate in relation to duties under any other provision of this Act or under any other laws.

  • (3) In this section:

"business judgment" means any decision to take or not take action in respect of a matter relevant to the business operations of the corporation.

Directors duties and the reform agenda.

The increasing frequency, scale and sophistication of cyber security incidents and costs, not just in pecuniary terms, but to reputation as well, have become increasingly important in terms of directors' duties and legal standards. Managing cyber risks is now a core governance concern.

In terms of the relevant legal duties, the most relevant is Section 180(1) of the Corporations Act; a duty of care and diligence.

(1) A director or other officer of a corporation must exercise their powers and discharge their duties with the degree of care and diligence that a reasonable person would exercise if they:

  • (a) were a director or officer of a corporation in the corporation's circumstances; and
  • (b) occupied the office held by, and had the same responsibilities within the corporation as, the director or officer.

When this duty is applied it takes into account the circumstances of the company and the position and responsibilities of the relevant director or officer. There is reference to it as a shifting objective standard. So the standard will vary depending on the type of company; that could include whether it's proprietary or publicly listed or unlisted, the size and nature of the business, the risks it faces, composition of the board and the way it's set up. It also varies depending on the position and actual responsibilities of the director or officer. This includes whether a director is executive or non-executive and the director's experience and skills, although there are minimum standards and directors are required to take active steps to guide and monitor the company and to keep informed. There's no one size fits all standard, but there are minimum standards required.

How might this be relevant in the context of cybersecurity? If, for example, directors failed to set up proper standards of cyber security to be implemented by management, for the protection of the company's business, there could be exposure under Section 180. ASIC has issued statements on cyber guidance, emphasising the importance of active engagement by the board in managing cyber risks. Further, judicial expectations of what a reasonable director might do to oversee the management of cyber risks are likely to increase.

A second way directors might be potentially liable under Section 180 is via what's known as stepping stones. Stepping stones liability arises where a company breaches or potentially breaches the law, particularly the Corporations Act, and the director is found to have failed to exercise reasonable care and diligence under Section 180 in causing or allowing the breach or failing to prevent the company from breaching the law.

Australian regulatory authorities

Australian Prudential Regulation Authority (APRA)

Dictionary

Definitions from Oxford Languages

prudential

/prʊˈdɛnʃl/

adjective

involving or showing care and forethought, especially in business.

"the US prudential rules prevented banks from lending more than fifteen per cent of their capital to any one borrower"

CPS234 (Prudential regulator) website link | Or download the CPS234 standard here.

Objectives and key requirements of this Prudential Standard

APRA is known as Australia's "prudential regulator". But what does "prudential regulation" mean?

Put simply, prudential regulation is a legal framework focused on the financial safety and stability of institutions and the broader financial system.

As Australia's prudential regulator, APRA is responsible for ensuring that the entities it regulates can, under all reasonable circumstances, meet the financial commitments they make to a core group of customers. As such, APRA is sometimes described as Australia's financial safety regulator.

This Prudential Standard aims to ensure that an APRA-regulated entity takes measures to be resilient against information security incidents (including cyberattacks) by maintaining an information security capability commensurate with information security vulnerabilities and threats. A key objective is to minimise the likelihood and impact of information security incidents on the confidentiality, integrity or availability of information assets, including information assets managed by related parties or third parties. The Board of an APRA-regulated entity is ultimately responsible for ensuring that the entity maintains its information security.

What industries does APRA regulate?

Each industry that APRA regulates; that is, banking, insurance and superannuation; has specific prudential standards, prudential guidelines and reporting standards that apply to them. In addition, APRA has standards and guidelines that apply to multiple industries. These are known as cross-industry standards and cross-industry guidelines.

The key requirements of this Prudential Standard (CPS 234) are that an APRA-regulated entity must:

  1. clearly define the information security-related roles and responsibilities of the Board, senior management, governing bodies and individuals;
  2. maintain an information security capability commensurate with the size and extent of threats to its information assets, and which enables the continued sound operation of the entity;
  3. implement controls to protect its information assets commensurate with the criticality and sensitivity of those information assets, and undertake systematic testing and assurance regarding the effectiveness of those controls; and
  4. notify APRA of material information security incidents.

Australian Security and Investments Commission (ASIC) (Corporate regulator)

https://asic.gov.au/

The Australian Securities and Investments Commission is an independent commission of the Australian Government tasked as the national corporate regulator. ASIC's role is to regulate company and financial services and enforce laws to protect Australian consumers, investors and creditors.

Australian Competition and Consumer Commission (ACCC) (Consumer & Consumer data rights)

https://www.accc.gov.au/

The Australian Competition and Consumer Commission is the chief competition regulator of the Government of Australia, located within the Department of the Treasury.

Australian Energy Sector Cyber Security Framework (AESCSF) (Energy regulator)

Australian Energy Sector Cyber Security Framework

The Australian Energy Sector Cyber Security Framework (AESCSF) has been developed through collaboration with industry and government stakeholders, including the Australian Energy Market Operator (AEMO), Australian Cyber Security Centre (ACSC), Cyber and Infrastructure Security Centre (CISC), and representatives from Australian energy organisations.

The AESCSF leverages recognised industry frameworks such as the US Department of Energy's Electricity Subsector Cybersecurity Capability Maturity Model (ES-C2M2) and the National Institute of Standards and Technology Cyber Security Framework (NIST CSF), and references global best-practice control standards (e.g. ISO/IEC 27001, NIST SP 800-53, COBIT, etc.). The AESCSF also incorporates Australian-specific control references, such as the ACSC Essential 8 Strategies to Mitigate Cyber Security Incidents, the Australian Privacy Principles (APPs), and the Notifiable Data Breaches (NDB) scheme.

Protective Service Manual (Australian Governmental rules for cyber security)

cyber.gov.au - Protective Service Manual

The Australian Cyber Security Centre (ACSC) produces the Information Security Manual (ISM). The purpose of the ISM is to outline a cyber security framework that organisations can apply, using their risk management framework, to protect their systems and data from cyber threats. The ISM is intended for Chief Information Security Officers, Chief Information Officers, cyber security professionals and information technology managers.

International law and conventions

International treaties

Are international treaties that Australia is signatory too automatically law in Australia? The short answer is no.

There is a formal process of adopting international treaties / conventions / agreements into law in Australia. The Australian constitution states that only laws legislated in both houses of parliament can be enacted in law.

The full Australian Constitution available online.

The Process

Here is a very basic overview of the process of adopting international treaties into Australian law. A more detailed version is available on this page which was taken directly from the Australian Government, Department of Foreign Affairs and Trade website.

  1. Negotiations and finalisation of the wording of the international agreement.
  2. Ministerial and Executive Council approval, and the signing.
  3. Present the agreement to both houses of parlamant for scrutiny and approval into legislation
  4. Entry into enforcement.

Is Australian IP legislation enforceable overseas?

Australia is a party to a number of international treaties that protect copyright material. These include the Berne Convention for the Protection of Literary and Artistic Works (Berne Convention) and the Universal Copyright Convention (UCC).

Read more: https://www.copyright.com.au/about-copyright/international-copyright/

Council of Europe Convention on Cybercrime

Cybercrime is a global problem which requires a coordinated international response.

Australia has acceded to the Council of Europe Convention on Cybercrime. The convention is the leading, binding international instrument directed at cybercrime, to which a number of other countries are also parties including the United States, Japan and many European countries. The convention came into force for Australia on 1 March 2013.

The objectives of the convention are to harmonise domestic legal frameworks on cybercrime, provide for domestic powers to investigate and prosecute cybercrime, and establish an effective regime of international legal cooperation.

Accession to the convention also helps improve the ability of our agencies to work effectively with their overseas counterparts in responding to cybercrime.

Reference: Australian Department of Home Affairs.

The Budapest Convention on Cybercrime & the GFCE (Global Forum on Cyber Expertise)

Information regarding the Budapest Convention is available here.

The Convention on Cybercrime of the Council of Europe was opened for signature in Budapest in November 2001. Fifteen years later, it remains the most relevant international agreement on cybercrime and electronic evidence. Membership keeps growing, while both the quality of implementation and the level of cooperation between Parties keep improving, and the treaty itself is evolving to meet new challenges. The formula for success is a "dynamic triangle"; The Budapest Convention is complemented by an effective follow up mechanism and by capacity building programmes, which are fed back into the Committee, contributing towards the Convention's evolution. The leitmotif of this approach is "to protect you and your rights in cyberspace".

In November 2001, the Convention on Cybercrime was opened for signature in Budapest, Hungary. Over time, that treaty, known as the "Budapest Convention", remains the most relevant international agreement on cybercrime and electronic evidence. It provides for the criminalisation of offences against and by means of computers, procedural law tools to secure electronic evidence and for international cooperation among Parties.

It is not only a cybercrime treaty. It also enables exercise of procedural powers and international cooperation mechanism in relation to any offence entailing electronic evidence. Thanks to its technology neutral language, the Budapest Convention has been providing responses to complex challenges of crime in cyberspace since 2001.

And from the outset it had a global ambition and was designed to go beyond the membership of the Council of Europe. Canada, Japan, South Africa and the USA participated in its negotiation. The Convention is open for accession by any country that is prepared to implement its provisions and engage in international cooperation, and many States have made use of this possibility.

Australian Criminal Code Act 1995

Please refer back to the course subject material: Criminal Code session.

Payment Card Industry Data Security Standard (PCI DSS)

What is PCI?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.

The Payment Card Industry Security Standards Council (PCI SSC) was launched on September 7, 2006 to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with a focus on improving payment account security throughout the transaction process. The PCI DSS is administered and managed by the PCI SSC (www.pcisecuritystandards.org), an independent body that was created by the major payment card brands (Visa, MasterCard, American Express, Discover and JCB.). It is important to note that the payment brands and acquirers are responsible for enforcing compliance, not the PCI council. A copy of the PCI DSS is available here.

To whom does the PCI DSS apply?

The PCI DSS applies to ANY organisation, regardless of size or number of transactions, that accepts, transmits or stores any cardholder data.

Where can I find the PCI Data Security Standard (PCI DSS)?

The current PCI DSS documents can be found on the PCI Security Standards Council website.

Update, current as at September 2026. The current standard is PCI DSS v4.0.1, a maintenance release of v4.0. The transition detail that matters: v4.0 introduced a large set of requirements that were flagged as best practice until 31 March 2025 and mandatory from that date. That deadline has passed, so all of the future-dated requirements are now in force and an assessment against them is no longer optional. The themes in that group are targeted risk analysis in place of one-size-fits-all frequencies, stronger authentication including multi-factor authentication for all access into the cardholder data environment, more rigorous script and payment page integrity controls aimed at web skimming, and expanded requirements around service providers. If a client tells you they achieved PCI compliance under v3.2.1, or under v4.0 before the deadline, that is not the same as compliance today.

A very useful FAQs on this standard: FAQ by ComplianceGuide.org

What are the PCI compliance 'levels' and how are they determined?

All merchants will fall into one of the four merchant levels based on Visa transaction volume over a 12-month period. Transaction volume is based on the aggregate number of Visa transactions (inclusive of credit, debit and prepaid) from a merchant Doing Business As ('DBA'). In cases where a merchant corporation has more than one DBA, Visa acquirers must consider the aggregate volume of transactions stored, processed or transmitted by the corporate entity to determine the validation level. If data is not aggregated, such that the corporate entity does not store, process or transmit cardholder data on behalf of multiple DBAs, acquirers will continue to consider the DBA's individual transaction volume to determine the validation level.

Merchant levels as defined by Visa:

Merchant Level Description
1 Any merchant, regardless of acceptance channel, processing over 6M Visa transactions per year. Any merchant that Visa, at its sole discretion, determines should meet the Level 1 merchant requirements to minimise risk to the Visa system.
2 Any merchant, regardless of acceptance channel, processing 1M to 6M Visa transactions per year.
3 Any merchant processing 20,000 to 1M Visa e-commerce transactions per year.
4 Any merchant processing fewer than 20,000 Visa e-commerce transactions per year, and all other merchants, regardless of acceptance channel.

* Any merchant that has suffered a breach that resulted in an account data compromise may be escalated to a higher validation level.

If I only accept credit cards over the phone, does PCI DSS still apply to me?

Yes. All business that store, process or transmit payment cardholder data must be PCI Compliant.

Do organisations using third-party processors have to be PCI DSS compliant?

Yes. Merely using a third-party company does not exclude a company from PCI DSS compliance. It may cut down on their risk exposure and consequently reduce the effort to validate compliance. However, it does not mean they can ignore the PCI DSS.

My company doesn't store credit card data so PCI compliance doesn't apply to us, right?

If you accept credit or debit cards as a form of payment, then PCI compliance applies to you. The storage of card data is risky, so if you don't store card data, then becoming secure and compliant may be easier.

Am I PCI compliant if I have an SSL certificate?

SSL certificates do not secure a web server from malicious attacks or intrusions. High assurance SSL certificates provide the first tier of customer security and reassurance such as the below, but there are other steps to achieve PCI compliance.

  • A secure connection between the customer's browser and the web server
  • Validation that the website operators are a legitimate, legally accountable organisation

My company wants to store credit card data. What methods can we use?

Most merchants that need to store credit card data are doing it for recurring billing. The best way to store credit card data for recurring billing is by utilising a third party credit card vault and tokenization provider. By utilising a vault, the card data is removed from your possession and you are given back a "token" that can be used for the purpose of recurring billing. By using a third party, you move the risk of storing card data to someone who specialises in doing that and has all of the security controls in place to keep the card data safe.

If you need to store the card data yourself, your bar for self-assessment is very high and you may need to have a QSA (Qualified Security Assessor) come onsite and perform an audit to ensure that you have all of the controls in place necessary to meet the PCI DSS specifications.

Australian Human Rights Commission Act 1986

The Australian Human Rights Commission Act 1986 articulates the Australian Human Rights Commission role and responsibilities. It gives effect to Australia's obligations under many International conventions / Declarations and rights of people. Specifically regarding Cyber Security, the International Covenant on Civil and Political Rights specifically addresses everyone's fundamental basic rights.

International Covenant on Civil and Political Rights, Part 1, Article 1.2 states:

All peoples may, for their own ends, freely dispose of their natural wealth and resources without prejudice to any obligations arising out of international economic co-operation, based upon the principle of mutual benefit, and international law. In no case may a people be deprived of its own means of subsistence.

And Part 2, Article 5 states:

  1. Nothing in the present Covenant may be interpreted as implying for any State, group or person any right to engage in any activity or perform any act aimed at the destruction of any of the rights and freedoms recognized herein or at their limitation to a greater extent than is provided for in the present Covenant.

  2. There shall be no restriction upon or derogation from any of the fundamental human rights recognized or existing in any State Party to the present Covenant pursuant to law, conventions, regulations or custom on the pretext that the present Covenant does not recognize such rights or that it recognizes them to a lesser extent.

Sources used

These notes were collated by the site owner from the Charles Darwin University VU23223 course pages (vu23223.brambling.cdu.edu.au) and the Australian Government, legislation and legal sources linked inline throughout, including legislation.gov.au, oaic.gov.au, cyber.gov.au, homeaffairs.gov.au, afp.gov.au and others; the unit scope block draws on the Victoria University published unit page for VU23223, read 15 August 2026.

The current privacy penalty figures added under "Notifiable Data Breaches scheme, consent and penalties" draw on the Office of the Australian Information Commissioner guidance on civil penalties (oaic.gov.au) and a Johnson Winter Slattery summary of the Privacy and Other Legislation Amendment Act 2024, "Changes to Australian privacy laws now in force" (jws.com.au), both read 15 August 2026.

The artificial intelligence and ethics sections, and the currency updates marked "Update, current as at September 2026", were added in September 2026 from the following. Australian AI policy: the AI Ethics Principles, the Voluntary AI Safety Standard of 5 September 2024 and the Guidance for AI Adoption that replaced it on 21 October 2025, all at industry.gov.au; and reporting of the National AI Plan of December 2025 and the decision not to proceed with mandatory guardrails, including the Gadens legal insight of 17 December 2025 and the Montreal AI Ethics Institute policy summary of 25 May 2026. Privacy and AI: the OAIC's two guidance documents on privacy and commercially available AI products, and on privacy and developing and training generative AI models, both published 21 October 2024 and updated in late 2024 and January 2025. The automated decision-making commencement date of 10 December 2026 and the tranche one and tranche two staging come from the Privacy and Other Legislation Amendment Act 2024 on the Federal Register of Legislation and from Australian legal commentary read in September 2026. Copyright and AI: reporting of the Productivity Commission's August 2025 text and data mining proposal and the government's decision of October 2025 not to proceed with it. Professional ethics: the Australian Computer Society Code of Professional Ethics and Code of Professional Conduct (acs.org.au), and the ISC2 Code of Ethics together with the Code of Professional Conduct ISC2 published in February 2026 (isc2.org).

Currency updates elsewhere on the page: the Essential Eight material draws on the ASD Essential Eight Maturity Model and its November 2023 change summary, and on the ASD consultation notice on the evolution of the Essential Eight published 15 June 2026 with consultation closing 12 July 2026, all at cyber.gov.au; the indicative retirement timeline attributed to an ACSC representative is reported commentary rather than published ASD policy and is described that way in the text. The Cyber Security Strategy update draws on the Department of Home Affairs pages for the 2023 to 2030 strategy and for Horizon 2, announced 11 June 2026. The AML/CTF update draws on AUSTRAC's reform material and on Norton Rose Fulbright's tranche two summary. The ISO/IEC 27701:2025 note draws on the ISO catalogue entry and the ANSI standards commentary on the second edition. The PCI DSS note draws on the PCI Security Standards Council's own material on the v4.x future-dated requirements that became mandatory on 31 March 2025. All read 2 September 2026.