Australian Signals Directorate (ASD)
Blog

What Happens When You Report a Cybersecurity Incident to the ASD?

The Australian Cyber Security Centre (ACSC) recently shared a detailed post explaining how the Australian Signals Directorate (ASD) supports organisations that report cyber incidents. This initiative highlights the critical role the ASD plays in helping businesses mitigate and respond to cyber threats effectively.

Why Reporting Cyber Incidents Matters

The ASD encourages businesses to report various types of cyber activity, including data breaches, ransomware attacks, malware infections, phishing attempts, denial-of-service attacks, unauthorised access, and other unusual or malicious cyber behaviours. Reporting these incidents not only helps the affected organisation but also contributes to a stronger national cybersecurity posture.

What Happens After Reporting an Incident

When an organisation reports a cyber incident, the ASD provides a range of support services to help mitigate the impact and prevent further damage. These services include:

  • Incident response advice and remediation strategies.
  • Sending tailored advisories to guide the organisation’s response.
  • Connecting the organisation with relevant government agencies for additional support.
  • Analysing the reported incident to determine whether further action is necessary.

If the incident requires a more in-depth response, the ASD may offer advanced services such as digital forensics, guidance on public communications, assistance with investigations, and collaboration on technical briefings for industry or government stakeholders. The organisation may also be connected to other ASD divisions for further support.

Information Sharing and Privacy Protections

The ASD reassures organisations that any information shared during the reporting process is safeguarded under the limited-use obligation, a provision established by Australia’s first Cyber Security Act. This ensures that any voluntarily shared data, such as incident details or vulnerability information, cannot be used for regulatory or enforcement purposes.

The ASD may request technical details to better understand the incident, including:

  • Malware samples or indicators of compromise.
  • Network traffic logs or packet captures.
  • System documentation or diagrams.
  • Disk images, memory dumps, or other system logs.

Organisations may also be asked about their existing incident response plans, their technical capabilities for investigating and mitigating threats, and their plans for containing or isolating compromised systems.

The Broader Impact of Reporting

While reporting incidents to the ASD is not a substitute for meeting mandatory reporting requirements, it offers significant benefits. The ASD aggregates and analyses the information it receives to build a comprehensive national cyber threat picture. This intelligence informs the development of updated security advice, tools, and techniques to combat evolving threats. Additionally, anonymised details from reported incidents may be used to create public guidance, enhancing cyber resilience across all sectors.

“One of ASD’s strengths is our ability to aggregate and analyse information to produce a national cyber threat picture,” the ASD explained. “By sharing information, organisations help us develop better strategies to prevent and respond to cyber threats, ultimately benefiting the nation as a whole.”

Why Businesses Should Report Cyber Incidents

By reporting cyber incidents to the ASD, businesses not only receive valuable support but also contribute to a safer digital environment for all Australians. This collaboration between organisations and the ASD ensures that the country is better equipped to face emerging cyber threats.

For more information, visit the Australian Cyber Security Centre website and learn how your organisation can benefit from reporting cyber incidents.

 


Siege Cyber logo

Reporting to the ASD is not the same as your legal notification obligations

This is the point most often missed, and it matters because getting it wrong can leave a legal obligation unmet while you believe you have reported.

Reporting a cyber incident to the ASD through ReportCyber is voluntary for most Australian organisations. It gives you access to assistance and feeds the national threat picture, but it does not discharge any other obligation.

Your legal obligations sit elsewhere and run on their own clocks:

  • The Notifiable Data Breaches scheme. If an eligible data breach involving personal information is likely to result in serious harm, you must notify affected individuals and the OAIC. That is a separate report to a separate regulator.
  • APRA CPS 234. If you are an APRA regulated entity, a material information security incident must be notified to APRA within 72 hours, and a material control weakness you cannot remediate in a timely way within 10 business days.
  • Critical infrastructure obligations. Responsible entities for critical infrastructure assets carry their own mandatory reporting obligations with short timeframes under the Security of Critical Infrastructure Act.
  • Contracts. Customer agreements frequently specify notification windows that are shorter than anything in legislation.

The practical implication is that your incident response plan needs a notification matrix rather than a single step. Who must be told, by when, by whom, and what the trigger is for each.

What to have ready before you report

Reporting goes faster and produces more useful assistance when you can answer a few basic questions. Have on hand: when you detected the incident and how; which systems and data are affected, and whether personal information is involved; what you have done so far to contain it; whether you have preserved logs and images; and who is coordinating the response.

Two practical cautions. Preserve evidence before you clean up. Rebuilding a compromised machine before it is imaged destroys the information that would have told you how far the attacker went. Take legal advice early on what is written down, because incident records can end up in front of a regulator or a court.

And decide your materiality thresholds in advance. Every one of the clocks above starts when you become aware, not when you finish investigating, so the judgement about whether this is “material” has to be one your team can make quickly with criteria that already exist.

Siege Cyber builds and tests incident response plans so the first hour of an incident is not spent deciding who to call. Get a Fixed-Price Quote.