Limited use: telling the National Cyber Security Coordinator
Part 4 of the Cyber Security Act 2024. What you voluntarily tell the National Cyber Security Coordinator about a cyber incident can be used to help you and to manage national risk, but not to investigate or penalise you for civil or regulatory breaches. It does not replace any report you are legally required to make.
Part 4 of the Cyber Security Act 2024 has been in force since 30 November 2024. It lets an organisation hit by a cyber security incident give information to the National Cyber Security Coordinator (NCSC), the official who leads the whole-of-government response to significant incidents, and it limits what the Coordinator and anyone they pass it to may do with that information. The point is to make it safer to talk to government early in an incident. Sharing under Part 4 is voluntary: there is no obligation to answer a request from the Coordinator.
Who and when. Section 35 covers an incident that has happened, is happening or is imminent, that is a cyber security incident, and that affects an entity carrying on business in Australia or a responsible entity for a critical infrastructure asset under the SOCI Act. The entity, or someone acting for it such as an incident response firm or law firm, may share information at any point in the response if the incident is, or could reasonably be expected to be, a significant cyber security incident. Section 34 defines significant as a material risk of serious prejudice to Australia's social or economic stability, defence or national security, or an incident that is, or could be expected to be, of serious concern to the Australian people. If you are not sure the incident qualifies, section 36 lets the Coordinator use what you give to work that out, and section 39 applies a narrower set of permitted uses when it turns out not to be significant.
What the information can be used for. For a significant incident, section 38 allows the Coordinator to record, use or disclose the information only to help you and those acting for you respond to, mitigate or resolve the incident, or for a permitted cyber security purpose under section 10. Those purposes include incident-response functions of Commonwealth and consenting State bodies, briefing Ministers, managing material risks to national stability, defence, security or critical infrastructure assets, intelligence agency functions and the functions of Commonwealth enforcement bodies. For incidents that are not significant, section 39 limits use to pointing you to other help, coordinating a whole-of-government response where needed, and briefing Ministers.
What it cannot be used for. The Coordinator, and any other entity, Commonwealth body or State body that receives the information from the Coordinator, must not use it to investigate or enforce a contravention by you of any Commonwealth, State or Territory law. There are two carve-outs: breaches of Part 4 itself, and criminal offences. Section 42 adds that the information is not admissible against you in most civil penalty, criminal and tribunal proceedings, again with exceptions such as giving false or misleading information under this Act. Section 41 says sharing does not by itself waive legal professional privilege. Coronial inquiries and Royal Commissions are outside sections 41 and 42. A recipient that misuses confidential, commercially sensitive or unconsented sensitive personal information can face a civil penalty of 60 penalty units under section 40; Commonwealth officers face Criminal Code offences instead.
The limits on the protection. Limited use is not immunity. It does not cover information you give to the Commonwealth to meet a legal requirement, which the Act lists as ransomware payment reports under Part 3, SOCI Part 2B incident reports, Telecommunications Act requirements and any law added by the rules. It does not cover information you give the Coordinator outside Part 4, or information already lawfully public. The same facts obtained another way, for example through a regulator's own notice, can still be used. Sharing with the Coordinator also does not satisfy any reporting duty: you still have to make your SOCI report on its 12 or 72 hour clock, notify the OAIC and affected people under the NDB scheme, and lodge a ransomware payment report within 72 hours where that applies. ASD has its own, parallel limited-use rule in Division 1A of Part 6 of the Intelligence Services Act 2001, so reports to ASD's ACSC rely on that, not on Part 4.
Using it well. Put the Coordinator, the ASD ACSC hotline (1300 CYBER1) and your regulators as separate rows in the incident communications plan, and record which channel each piece of information went through, because the protection depends on the channel. Decide in advance who may share on the organisation's behalf, and authorise your incident response and legal providers in writing so their disclosures count as made for you. Keep a log of what was shared, when and why. Brief the board that limited use helps with early cooperation but does not stop regulators using their own powers. Cross-links: soci-clock, ndb-clock, ransomware-payment-reporting, data-breach-response-plan, incident-response, asd.
See also:
Fact source: Cyber Security Act 2024 (Cth), Part 4 (ss 33–43) and ss 10–11; Home Affairs — Cyber Security Act overview.
