Critical infrastructure entities are legally required to report cyber security incidents Critical Infrastructure entities are required to report cyber security incidents to the ACSC within: 12 hours, if the incident is having a significant impact on the availability of the asset, or 72 hours, if the incident is having an impact on the availability, integrity or reliability of the asset, or on the confidentiality of information about, or held by, the asset. Report a cyber security incident Organisations & critical infrastructure This page is currently under maintenance, please try again in 30-45 minutes.