ADMIN 26/102
Cyber Security (Chair of the Cyber Incident Review Board) Appointment 2026
I, Tony Burke, Minister for Home Affairs and Minister for Cyber Security, under section 64 of the Cyber Security Act 2024, appoint Narelle Devine as the Chair of the Cyber Incident Review Board, on a part‑time basis, for the period of 4 years that begins on 1 May 2026.
Dated 28 April 2026
Tony Burke
Minister for Home Affairs
Minister for Cyber Security
Overview
The Cyber Security (Chair of the Cyber Incident Review Board) Appointment 2026I, enacted under the Cyber Security Act 2024, addresses the need for an experienced and authoritative figure to lead the Cyber Incident Review Board. This body is essential for enhancing Australia's capability to manage and respond to significant cyber incidents effectively. The appointment of Narelle Devine as the Chair, on a part-time basis for a four-year term starting on 1 May 2026, is authorised by Tony Burke, the Minister for Home Affairs and Minister for Cyber Security, under section 64 of the Act. The policy objective of this legislation is to ensure the Cyber Incident Review Board has a skilled and dedicated leader to guide its reviews and recommendations, thereby bolstering the nation's cyber resilience and response mechanisms.
Scope and Application
The Cyber Security (Chair of the Cyber Incident Review Board) Appointment 2026I, made under section 64 of the Cyber Security Act 2024 by Tony Burke, Minister for Home Affairs and Minister for Cyber Security, appoints Narelle Devine as the Chair of the Cyber Incident Review Board, on a part-time basis, for a period of four years commencing on 1 May 2026. This appointment applies to Narelle Devine, an individual who will hold the position of Chair within the Cyber Incident Review Board, an entity responsible for overseeing and reviewing significant cyber incidents impacting Australia. The appointment is made at the Commonwealth level, thereby establishing a national framework for the oversight and review of cyber incidents. The legislation does not specify exclusions or exemptions, but it does establish a defined role within the federal structure, and its application is restricted to the scope of the Cyber Incident Review Board’s responsibilities under the Cyber Security Act 2024. Any further application or restrictions of this appointment may be detailed in subordinate instruments, although the primary focus remains on the governance and review of cyber incidents at a national level.
Key Provisions
The Notifiable Instrument F2026N00304, issued under the authority of the Cyber Security Act 2024, appoints Narelle Devine as the Chair of the Cyber Incident Review Board (CIRB) effective from 1 May 2026. This appointment (section 1) is made by Tony Burke, who serves as both the Minister for Home Affairs and the Minister for Cyber Security. The role is specified as part-time, and the term of appointment lasts for four years. This appointment is crucial for ensuring that the CIRB has a qualified and experienced leader to guide its activities and fulfil its statutory functions.
Under this legislation, Narelle Devine assumes the responsibilities and duties as the Chair of the CIRB. The CIRB, as a body governed by this Act, is tasked with reviewing significant cyber incidents affecting Australia, providing recommendations for improvements in cyber security measures, and ensuring that lessons learned from these incidents are implemented. As Chair, Narelle Devine will be responsible for overseeing the CIRB's operations, leading its reviews, and ensuring that the Board adheres to its legislative mandate. This includes managing the CIRB’s resources and personnel, facilitating effective communication and collaboration among its members, and ensuring that the Board’s findings and recommendations are communicated to relevant stakeholders.
The legislation does not explicitly outline offences or penalties for breaches within this specific appointment instrument. However, any failure to comply with the statutory duties and responsibilities of the CIRB, or any maladministration or misconduct by its Chair, could potentially lead to legal and administrative consequences under the broader provisions of the Cyber Security Act 2024. These could include disciplinary actions, potential removal from office, or other legal remedies available under Australian law for breaches of public office duties. While the maximum penalties are not detailed within this instrument, they would be governed by the general legal framework applicable to public officers and the specific provisions of the Act.