Cyber Incident Review Board: no-fault reviews of major incidents
Part 5 of the Cyber Security Act 2024 sets up an independent board that reviews significant cyber incidents after the response is over and publishes lessons and recommendations. It does not assign blame, but it can compel documents from private entities, so know how a review works before you are asked to take part.
The Cyber Incident Review Board (CIRB) is an independent statutory advisory body created by Part 5 of the Cyber Security Act 2024 (ss 45 to 70). Part 5 commenced at the end of May 2025, alongside the Cyber Security (Cyber Incident Review Board) Rules 2025. On 1 May 2026 the Minister for Cyber Security announced the first Board, chaired by Narelle Devine with six standing members. The Act allows a Chair plus between two and six standing members (s 61), backed by an Expert Panel and a secretariat of Department of Home Affairs staff.
What it reviews. A review can start only on written referral from the Minister, the National Cyber Security Coordinator, an entity affected by the incident, or a Board member (s 46(1)). Three conditions then apply (s 46(2)): the Board must be satisfied the incident, or series of related incidents, meets at least one criterion; the incident and the immediate response must have ended; and the Minister must have approved the terms of reference. The criteria (s 46(3)) are serious prejudice, actual or reasonably expected, to Australia's social or economic stability, defence or national security; novel or complex methods or technologies whose study would significantly improve national preparedness; or being, or being likely to be, of serious concern to the Australian people. Each review is run by a review panel of the Chair, at least one standing member named in the terms of reference, and any Expert Panel members appointed to it (s 46(4)). The Board may discontinue a review at any time but must publish notice within 28 days (s 47).
Information gathering. The Chair first asks in writing for information or documents, and there is no obligation to answer that request (s 48). If a private entity involved in the incident does not provide a relevant document after being asked, the Chair can issue a notice to produce, giving at least 14 days (s 49). Ignoring that notice attracts a civil penalty of 60 penalty units (s 50), but production is not required where it could prejudice national security, defence or international relations, intelligence capabilities, a criminal or civil penalty investigation or proceedings, or the administration of justice. Commonwealth and State bodies cannot be compelled this way, and an entity that is made to copy documents is entitled to reasonable compensation.
Protections for what you hand over. Information given to the Board under ss 48, 49 or 51 can be used for the review, for government incident response and briefing Ministers, and by intelligence agencies, but the Board and anyone it passes the information to must not use it to investigate or enforce a breach of other Commonwealth, State or Territory law by the entity that provided it, except a breach of Part 5 itself or a criminal offence (ss 55 and 56). Handing material to the Board does not waive legal professional privilege (s 57). The information is also not admissible against the providing entity in most civil, regulatory, tribunal and criminal proceedings (s 58), with exceptions for false or misleading information, obstruction, coronial inquiries and Royal Commissions. Privacy Act limits still apply, and information that is already public is not protected.
Reports. The Board prepares a draft report with preliminary findings and proposed recommendations, gives it to the Minister and may share it, or extracts of it, with affected entities for comment within a set period (s 51). Anyone who receives a draft and uses or discloses it beyond preparing a submission, their own information, or with the Chair's consent faces a 60 penalty unit civil penalty (s 59). The final report must be published, and it must not apportion blame, provide a means of working out liability, identify an individual without consent, or invite an adverse inference from the fact that an entity was reviewed (s 52). Sensitive review information, including security, law enforcement, commercially confidential and personal information, is redacted from the public version (s 53) and kept in a protected report given to the Minister and the Prime Minister (s 54).
Practitioner checklist. Build a possible CIRB review into your incident response plan alongside regulator, ASD, OAIC and insurer engagement. Keep a clean, dated incident record (timeline, decisions, logs, external advice) during the response, because a review asks for it only after the response ends, sometimes months later. Route any request or notice to produce through legal counsel, track the deadline, and mark confidential or commercially sensitive material when you hand it over so it can be considered for redaction. Treat any draft report as restricted: share it internally only to prepare your submission. Remember the CIRB protections cover only material given to the Board; they do not replace your mandatory reports or the separate limited-use protection for information given to the National Cyber Security Coordinator.
See also:
Fact source: Cyber Security Act 2024 (Cth), Part 5 (ss 45–63); Home Affairs — The Cyber Incident Review Board.
