DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/Cyber Security Act
Australia & NZ compliance

Cyber Security Act 2024

Australia's first standalone cyber security legislation, introducing mandatory ransomware payment reporting, security standards for smart devices, a Cyber Incident Review Board, and a limited use obligation that protects information shared with ASD during cyber incidents.

See where NodeZero applies

What is the Cyber Security Act?

The Cyber Security Act 2024 is Australia's first standalone cyber security legislation, passed in November 2024 as part of the Government's 2023-2030 Australian Cyber Security Strategy. The Act introduces four key measures: mandatory reporting of ransomware payments within 72 hours, security standards for internet-connected (smart) devices, a Cyber Incident Review Board to conduct no-fault post-incident reviews, and a limited use obligation that restricts how the Australian Signals Directorate can use information voluntarily shared during cyber incidents.

The Act complements rather than replaces the SOCI Act and Privacy Act. Where SOCI targets critical infrastructure operators and the Privacy Act governs personal information, the Cyber Security Act has broader reach -- the ransomware reporting obligation, for example, applies to any organisation with annual turnover exceeding $3 million that makes a ransomware payment. The limited use obligation is designed to encourage organisations to share incident information with ASD without fear that it will be used against them in regulatory proceedings.

Department of Home Affairs -- Cyber Security Legislation

Where NodeZero applies

NodeZero's primary contribution to Cyber Security Act compliance is preventive: by identifying and remediating the attack paths that ransomware operators exploit, you reduce the likelihood of ever triggering the ransomware payment reporting obligation. Autonomous penetration testing discovers weak credentials, unpatched systems, lateral movement paths, and privilege escalation opportunities -- the same techniques used in real ransomware campaigns. For the Act's other measures (smart device standards, the Cyber Incident Review Board, and the limited use obligation), we map what sits outside pentesting scope so your compliance posture addresses the full legislation.

Cyber Security Act 2024

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Please note the following require separate evidence: Smart device security standards, Cyber Incident Review Board and Limited use obligation.

Showing coverage grouped by compliance category.

Ransomware payment reporting

Preventive coverage. NodeZero identifies and closes the attack paths ransomware operators exploit, reducing the likelihood of ever triggering the reporting obligation.

AD Password AuditCore

Weak and reused credentials are a leading initial-access vector for ransomware — audit them before attackers find them, reducing the likelihood of ever triggering the s 27(1) reporting obligation.

Internal pentestingCore

Proves end-to-end attack paths — initial access → lateral movement → domain compromise — the same techniques ransomware operators use — so you can close them before any s 26(1) trigger condition, including the s 26(1)(e) ransomware payment, ever applies.

Phishing Impact TestingCore

Phishing is a leading ransomware initial-access vector alongside weak credentials — Phishing Impact consumes credentials your own phishing tool captures and proves what each one can reach: data, admin, cloud pivot, privilege escalation, domain compromise, so that route closes before it feeds a s 26(1)(e) ransomware payment.

Endpoint Security EffectivenessCore

Ransomware relies on EDR evasion and OS credential dumping to reach the encryption stage — Endpoint Security Effectiveness runs those exact techniques against real hosts, with per-host block/allow outcomes across 40+ EDR vendors, direct evidence of whether the controls meant to stop ransomware actually do before a s 26(1)(e) payment is ever made.

Vulnerability Management HubCore

Closing an attack path only reduces the reporting obligation if the fix actually held — the Vulnerability Management Hub tracks every proven weakness through an Open → Mitigated → Regressed lifecycle, and Quick Verify re-runs the exact attack path to confirm closure (internal environments), the remediation record that shows a s 26(1)(e)-bound trigger was genuinely closed, not just marked done.

Rapid ResponsePro & Elite

SOCI responsible entities carry the reporting obligation regardless of turnover. Rapid Response helps close the newly-disclosed-CVE window before an exploit drives ransomware into the environment.

Segmentation testingCore

Validating segmentation ahead of time limits incident impact — the containment that keeps you from having to characterise that impact in a s 27(2)(c) report at all.

Advanced Data PilferingElite only

Modern ransomware is double-extortion — exfiltrate, then encrypt. Advanced Data Pilfering autonomously proves which sensitive data an attacker could reach and take, and emulates stealthy exfiltration to test whether your defences would notice — direct evidence of the incident impact a s 27(2)(c) report must characterise, distinct from the containment evidence segmentation testing provides.

NodeZero TripwiresPro & Elite

Tripwires drop decoy credentials and honeytokens during a test, so any interaction is a high-fidelity signal — validating whether your SOC would spot an intruder moving toward your crown jewels, before real ransomware ever reaches the extortion stage.

5 controls mapped
Cyber Security Act kit

See every control mapped to NodeZero

The full control-by-control coverage map — every Cyber Security Actrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

The ransomware payment reporting obligation applies to all reporting business entities — organisations carrying on a business in Australia with annual turnover above the $3 million threshold, or responsible entities for a critical infrastructure asset to which Part 2B of the SOCI Act applies — that make, or authorise, a ransomware payment in connection with a cyber security incident. Reports must be submitted to the Australian Signals Directorate within 72 hours of making or becoming aware of the payment. Failure to report can attract civil penalties.

The smart device security standards apply to manufacturers and suppliers of internet-connected devices sold in Australia. The standards are aligned with international frameworks (including ETSI EN 303 645) and are expected to set baseline security requirements for IoT devices -- including no default passwords, vulnerability disclosure policies, and defined support periods.

The Cyber Incident Review Board can conduct no-fault reviews of significant cyber incidents, providing learnings to the broader community without attributing blame. The limited use obligation applies to information voluntarily provided to ASD during cyber incidents, preventing its use for enforcement purposes by other Commonwealth agencies. If your organisation operates in Australia and could face a ransomware incident, manufactures or supplies smart devices, or may share incident information with ASD, the Cyber Security Act applies to you.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.