Application of this Part
26 Application of this Part
This Part applies if:
an incident has occurred, is occurring or is imminent; and
the incident is a cyber security incident; and
the incident has had, is having, or could reasonably be expected to have, a direct or indirect impact on a reporting business entity; and
an entity (the extorting entity) makes a demand of the reporting business entity, or any other entity, in order to benefit from the incident or the impact on the reporting business entity; and
the reporting business entity provides, or is aware that another entity has provided on their behalf, a payment or benefit (a ransomware payment) to the extorting entity that is directly related to the demand.
An entity is a reporting business entity if, at the time the ransomware payment is made:
the entity:
is carrying on a business in Australia with an annual turnover for the previous financial year that exceeds the turnover threshold for that year; and
is not a Commonwealth body or a State body; and
is not a responsible entity for a critical infrastructure asset; or
the entity is a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies.
For the purposes of subparagraph (2)(a)(i), the turnover threshold is:
if a business has been carried on for only part of the previous financial year—the amount worked out in the manner prescribed by the rules; or
in any other case—the amount prescribed by, or worked out in the manner prescribed by, the rules.
Presumption
For the purposes of paragraph (1)(b), an incident (other than an incident covered by paragraph 9(2)(a) or (b)) is presumed to be a cyber security incident if:
the incident was probably effected, is probably being effected or could reasonably be expected to be effected, by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
the incident has probably impeded or impaired, or is probably impeding or impairing or could reasonably be expected to impede or impair, the ability of a computer to connect to such a service; or
the incident has probably seriously prejudiced, is probably seriously prejudicing, or could reasonably be expected to prejudice:
the social or economic stability of Australia or its people; or
the defence of Australia; or
national security.
Paragraphs 9(2)(a) and (b) cover incidents involving critical infrastructure assets or the activities of corporations to which paragraph 51(xx) of the Constitution applies.
However, subsection (4) does not make an entity liable to a civil penalty under this Part if the incident:
was not in fact effected by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
did not in fact impede or impair the ability of a computer to connect to such a service; or
did not in fact seriously prejudice:
the social or economic stability of Australia or its people; or
the defence of Australia; or
national security.
The statute text is free to read above. View Pro plans to unlock the case-law research tools for each provision.