
What Happens When You Report a Cybersecurity Incident to the ASD?
Reporting to the ASD is not the same as your legal notification obligations
This is the point most often missed, and it matters because getting it wrong can leave a legal obligation unmet while you believe you have reported.
Reporting a cyber incident to the ASD through ReportCyber is voluntary for most Australian organisations. It gives you access to assistance and feeds the national threat picture, but it does not discharge any other obligation.
Your legal obligations sit elsewhere and run on their own clocks:
- The Notifiable Data Breaches scheme. If an eligible data breach involving personal information is likely to result in serious harm, you must notify affected individuals and the OAIC. That is a separate report to a separate regulator.
- APRA CPS 234. If you are an APRA regulated entity, a material information security incident must be notified to APRA within 72 hours, and a material control weakness you cannot remediate in a timely way within 10 business days.
- Critical infrastructure obligations. Responsible entities for critical infrastructure assets carry their own mandatory reporting obligations with short timeframes under the Security of Critical Infrastructure Act.
- Contracts. Customer agreements frequently specify notification windows that are shorter than anything in legislation.
The practical implication is that your incident response plan needs a notification matrix rather than a single step. Who must be told, by when, by whom, and what the trigger is for each.
What to have ready before you report
Reporting goes faster and produces more useful assistance when you can answer a few basic questions. Have on hand: when you detected the incident and how; which systems and data are affected, and whether personal information is involved; what you have done so far to contain it; whether you have preserved logs and images; and who is coordinating the response.
Two practical cautions. Preserve evidence before you clean up. Rebuilding a compromised machine before it is imaged destroys the information that would have told you how far the attacker went. Take legal advice early on what is written down, because incident records can end up in front of a regulator or a court.
And decide your materiality thresholds in advance. Every one of the clocks above starts when you become aware, not when you finish investigating, so the judgement about whether this is “material” has to be one your team can make quickly with criteria that already exist.
Siege Cyber builds and tests incident response plans so the first hour of an incident is not spent deciding who to call. Get a Fixed-Price Quote.
