• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Logo of Agilient Security Consultants, Australia

Agilient Security Consultants Australia

The Best Security Consultants

Menu
  • Industries
      • Aviation and Airport Security Consultants Australia
      • Defence Industry Security Consulting
      • Government Security Consulting
      • Healthcare & Hospitals Security Consulting
      • Corrections and Detention
      • Maritime Security Consultant
      • Aged Care Facilities
      • Mining, Oil & Gas
      • Public Venues & Events
      • Rail
      • School and Education Security Consultant
      • Telecommunications Security Consultant
      • Utilities
      • Places of Faith and Worship
    • advice-colleagues-communication-newIndustries
  • Services
      • Cybersecurity Consultants
      • Protective Security
      • Business Resilience
      • Building Security Consultants
      • Security Audits
      • Cyber Audits
      • Data
      • Pandemic Planning
      • Azure
      • Electronic Security
      • IT Disaster Recovery Planning
      • Business Continuity Consultants
      • Identity Theft Consultant​
      • Security Consultants
      • Security Camera and CCTV Consultant
      • ISO
      • Duress Alarms
      • Cloud
      • AWS
      • Awareness Training
      • Penetration Testing
      • Security Risk Assessment Consultants
      • Managed Security Service Provider
      • Protection against Vehicles as a Weapon
    • training-1Services
  • Locations
    • Security Consultant Melbourne
    • Security Consultant Sydney
    • Security Consultant Brisbane
    • Security Consultant Adelaide
    • Security Consultant Canberra
    • Security Consultant Perth
  • Resources
    • menumanagers-dealing-customer-agreTraining
    • working-together-newJoin The Tribe
    • Webinars_3-1.jpgUpcoming and Past Events
    • hacking-detected-shutterstock_newResources
  • Articles
  • About
    • About Us
      We are an Australian owned and operated security company specialising in risk, cybersecurity, protective security, crisis and business continuity management services.
    • frequently-asked-questions-smallFAQ’s
    • bg-menu-government-institutionsConsultant Registration
  • Contact Us
Contact Us

Amendment to Security Legislation – Bill 2021

You are here: Home / Security News / Amendment to Security Legislation – Bill 2021

Recently, the Security of Critical Infrastructure Act 2018 was amended in the House of Representatives. This article will discuss and explain the Security Legislation Amendment (Critical Infrastructure) Bill 2021 which was passed and came into effect on the 2nd December 2021.

The Purpose Of The Amendment

The main goal of the amendment was to strengthen the existing structure and strategies for managing risks (mainly cyber-related), which may target critical infrastructure. For this express purpose, The Bill added new definitions and obligations for critical infrastructure assets.

Main Points of Interest In Bill 2021

Firstly, The Bill has added a new definition for critical infrastructure sectors. The previous Act (Security of Critical Infrastructure Act 2018) covered only certain assets in four main sectors, which were the gas, electricity, water, and maritime ports sectors. Now the amendments have extended these sectors to cover eleven sectors which are regarded as critical. The eleven new sectors are:

  1. Data storage or processing
  2. Communications
  3. Defense industry
  4. Energy
  5. Financial services and markets
  6. Food and grocery
  7. Health care and medical
  8. Higher education and research
  9. Space technology
  10. Transport
  11. Water and sewerage

Furthermore, the cyber incident reporting that was mentioned in part 3A of The Act has been amended, and now introduces new obligations for reporting any cyber incidents that target or affect the critical infrastructure asset. These obligations force a responsible entity to report any kind of cybersecurity incident within:

  • 12 hours, if the impact of the incident is considered to be significant; or
  • 72 hours, if the impact of the incident isn’t considered to be significant.

The term ‘significant’ is defined by the ability of an incident to materially impact the availability of vital products or services.

Any failure to comply with these obligations will result in a fine of 50 penalty points (AU$11,000), and in some cases might even be 250 penalty points (AU$55,000) if it is a corporation.

The third and final point of interest gives the government more power and authority, something they call “government assistance”. This gives the Australian government power to intervene in the matters and decisions of any private company that is operating a critical infrastructure asset and might be under attack by a cybersecurity incident. These powers are only to be used as a last resort, and only when the entity responsible for the asset is unwilling or unable to take the appropriate actions to defend against the incident.

These powers are represented by three main directives:

  • Information-gathering requests – where the government will ask the entity to provide any necessary information to respond to the incident.
  • Action requests – where the government can order the entity to do a specific act, or to refrain from doing it.
  • Intervention requests – where the Australian Signals Directorate may intervene take whatever action is required, such as accessing or modifying any type of hardware that has been targeted by the incident and, in some cases, may even require them to take over the entire operation of the asset.

Next Steps

Since there are now several new sectors involved in the classification of a critical infrastructure, you should check if your organisation is an entity covered by The Act. If so, changes may need to be made to regulations within your organisation.

If your organisation is already an entity handling a critical infrastructure, then you need to modify and revise your response procedures for cyber-attacks and incidents, and ensure they meet the new criteria of mandatory reporting obligations, which is something we offer in our services.

If you are not sure whether your organisation is considered a critical infrastructure, contact us to for assistance.

Author: Mahdi Kobeissi, Cyber Security Consultant

Tweet
Share

Security News

Looking for a security partner? Get in touch with Agilient.

Looking for practical and cost-effective security and risk solutions for your government department, agency or company? Speak with Australia’s leading senior security, risk and resilience experts.


Looking for a pandemic planning partner? Get in touch with Agilient.

Looking for practical and cost-effective risk management solutions for your government department, agency or company? Speak with Australia’s leading senior risk and emergency management experts.



Footer

Agilient is a proud member of

Ai Group Defence Council
Australian Industry & Defence Network
Australian Security Industry Association
Sydney Aerospace & Defence Interest Group

Company and Licensing Details:

ABN: 37 157 911 441
NSW Security Master Licence # 410783087
ACT Security Master Licence # 17502184
Vic Security Registration # 878-460-40S
Qld Security Firm Licence # 3834422

Join The Tribe

Sign up to receive our regular Agilient newsletter including the latest security, risk and resilience updates

Sign up now

Copyright © 2025 Agilient – Level 14, 275 Alfred St, North Sydney NSW 2060 Australia – 1300 341 692

Our Services

Security Consultant

Security Consultant Sydney

Security Consultant Melbourne

Security Consultant Canberra
Security Consultant Perth

Security Consultant Adelaide

Security Consultant Brisbane