Australia Cyber Security Act 2024

Statute Australia · 2024

Australia's first standalone cyber security statute does three things: it creates mandatory security standards for smart devices, it requires businesses above a turnover threshold to report ransomware and cyber extortion payments within 72 hours, and it establishes a Cyber Incident Review Board with a limited-use protection so information given to government during an incident cannot be turned against the victim. The ransomware payment reporting obligation is the first of its kind at national scale.

Horizontal regime. It binds companies by what they do with data, software or customers, not by the sector they sit in. The industries below are where it creates specific, additional duties — not the limit of who has to comply.

Countries

Where this binds. Each links to the providers apis.io has catalogued there.

Regions

anz

Industries

Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.

Implemented by these standards

A regulation is the law; a standard is the machine-readable contract that satisfies it. Almost every regime in this catalog restricts an interface rather than requiring one — where a standard exists, it is the part a provider can actually publish.