At a glance
Submit a report as soon as possible after becoming aware of an incident. Some critical infrastructure entities and telecommunications providers must report incidents within strict timeframes. Reports are handled confidentially, and we can provide technical advice and assistance during an incident.
Regulated entities keyboard_arrow_down
Regulated entities under the following Acts may be subject to mandatory cyber incident reporting requirements:
- Part 2b of the Security of Critical Infrastructure Act 2018
- Part 6 of the Aviation Transport Security Act 2004
- Part 9 of the Maritime Transport and Offshore Facilities Security Act 2003
- the Telecommunications Act 1997 covered by the Telecommunications Security Information instruments
- Part 2 of the Telecommunications (Carriage Service Provider—Security Information) Determination 2022 or, the Telecommunications (Carrier Licence Conditions—Security Information) Declaration 2022.
Critical infrastructure entities keyboard_arrow_down
Reporting critical cyber security incidents under the SOCI Act
If you become aware that a critical cyber security incident has occurred, or is occurring, and the incident has had, or is having, a significant impact on the availability of your asset, you must notify the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) within 12 hours after you become aware of the incident.
A significant impact is one where the critical infrastructure is used in connection with the provision of essential goods and services; and the incident has materially disrupted the availability of those essential goods or services.
If you make the report verbally you must make a written record using the form on this page within 84 hours of verbally notifying ASD's ACSC.
Reporting other cyber security incidents under the SOCI Act
If you become aware that a cyber security incident has occurred, or is occurring, and the incident has had, is having, or is likely to have, a relevant impact on your asset you must notify the ASD's ACSC within 72 hours after you become aware of the incident.
A relevant impact is an impact on the integrity, reliability or confidentiality of your asset or systems.
If you make the report verbally you must make a written record using the form on this page within 48 hours of verbally notifying ASD's ACSC.
You can also notify the ASD’s ACSC about other cyber security incidents that don’t meet the threshold for a significant or relevant impact. You can then receive assistance and advice as needed. Any information that ASD shares will be covered by Limited Use protections.
Find more information on reporting under the SOCI Act on the Critical Infrastructure Security Centre website.
Aviation, maritime and offshore participants keyboard_arrow_down
Aviation industry participants under Part 6 of the Aviation Transport Security Act 2004 (ATSA), and maritime and offshore industry participants under Part 9 of the Maritime Transport and Offshore Facilities Security Act 2003 (MTOFSA) are required to report cyber security incidents that have had, are having, or are likely to have a significant or relevant impact on your asset.
Cyber security incidents with a significant or relevant impact must be reported to both the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) and the Department of Home Affairs (the Department). When reporting to ASD’s ACSC, if you don’t consent to this report being shared with the Department, you must submit a separate report to the Department online. Find more information on your reporting obligations under the ATSA and the MOFSA and report here:
- For aviation industry participants: Report an aviation security incident
- For maritime industry participants: Report a maritime security incident.
To receive assistance and advice, you can also notify the ASD’s ACSC about cyber security incidents that don’t meet the significant or relevant impact threshold. Any information that ASD shares will be covered by Limited Use protections.
Reporting cyber security incidents with a significant impact under the ATSA or the MTOFSA
If you become aware that a cyber security incident has had, is having, or is likely to have a significant impact on your asset, you must notify ASD’s ACSC, and the Department, within 12 hours after you become aware of the incident.
Significant impact means that your asset is used in connection with the provision of essential goods or services; and the cyber security incident has materially disrupted their availability.
Reporting cyber security incidents with a relevant impact under the ATSA or the MTOFSA
If you become aware that a cyber security incident has had, is having or is likely to have a relevant impact on your asset, you must notify the ASD’s ACSC, and the Department, within 72 hours after you become aware of the incident.
Relevant impact means the cyber security incident has affected the availability, integrity, or reliability of your asset; or the confidentiality of information about, or stored in, the asset.
List of critical infrastructure sectors and asset classes keyboard_arrow_down
Communications
- a critical telecommunications asset (carriers and eligible carriage service providers)
- a critical broadcasting asset
- a critical domain name system
Data storage or processing
- a critical data storage or processing asset
Defence industry
- a critical defence industry asset
Energy
- a critical electricity asset
- a critical gas asset
- a critical energy market operator asset
- a critical liquid fuel asset
Financial services and markets
- a critical banking asset
- a critical superannuation asset
- a critical insurance asset
- a critical financial market infrastructure asset
Food and grocery
- a critical food and grocery asset
Health care and medical
- a critical hospital
Higher education and research
- a critical education asset
Space technology
Transport
- a critical port
- a critical freight infrastructure asset
- a critical freight services asset
- a critical public transport asset
- a critical aviation asset
Water and sewerage
- a critical water asset
More information keyboard_arrow_down
Find more information on reporting under the SOCI Act, the ATSA and the MTOFSA on the Critical Infrastructure Security Centre website.
Find more information on reporting for Telecommunications providers on the Department of Infrastructure, Transport, Regional Development, Communications and the Arts website.
Who must report
A cyber security incident is an unexpected event(s) that has compromised, or could disrupt, business operations. This could include unauthorised access to, modification of, or impairment of systems, data, programs, or communications, including impacts to their availability, reliability, security, or operation.
This form is for:
- organisations with 250+ staff or an annual turnover of at least $250 million
- government departments
- critical infrastructure entities
- regulated entities.
If none of these categories apply to you, you may need to report your issue as a cybercrime. If you’re unsure, call our hotline on 1300 CYBER1 (1300 292 371), 24 hours a day, 7 days a week.
Support
We (the Australian Signals Directorate’s Australian Cyber Security Centre) offer free technical incident response advice and assistance. Reporting early, whether the incident is confirmed or not, means you will also:
- benefit from our broader threat visibility and intelligence that strengthens your response
- help protect your organisation and the wider community.
How we protect your privacy
We handle incidents with strict confidentiality and are bound by Limited Use obligations. This means information an Australian organisation voluntarily shares to ASD about an actual or potential cyber security incident can’t be used for regulatory purposes.
Learn more about our Limited Use obligation.
Submit a cyber security incident report
⚠ Do not submit a report using a network you believe is compromised. Use a separate system and secure contact details.
To report fraud or cybercrime, visit ReportCyber.