ADMIN 26/103
Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 1) 2026
I, Tony Burke, Minister for Home Affairs and Minister for Cyber Security, under section 66 of the Cyber Security Act 2024, appoint Debi Ashenden as a standing member of the Cyber Incident Review Board, on a part-time basis, for the period of 4 years that begins on 1 May 2026.
Dated 28 April 2026
Tony Burke
Minister for Home Affairs
Minister for Cyber Security
Overview
The Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 1) 2026I, enacted by Tony Burke, the Minister for Home Affairs and Minister for Cyber Security, under section 66 of the Cyber Security Act 2024, appoints Debi Ashenden as a standing part-time member of the Cyber Incident Review Board for a four-year term beginning on 1 May 2026. This appointment was made to bolster the capacity of the Cyber Incident Review Board to effectively assess and review cyber incidents, thereby enhancing Australia's cybersecurity posture. The appointment aims to ensure that the Board has a member with the requisite expertise to contribute meaningfully to its mandate of reviewing and providing advice on significant cyber incidents and broader cybersecurity issues.
Scope and Application
The Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 1) 2026 Instrument establishes the appointment of Debi Ashenden as a standing member of the Cyber Incident Review Board under the Cyber Security Act 2024. This Act applies to individuals who are appointed to the Cyber Incident Review Board, which is a body established to provide advice and recommendations to the Minister on matters related to cyber security incidents affecting critical information infrastructure in Australia. The instrument outlines the appointment of Debi Ashenden on a part-time basis for a period of four years starting from 1 May 2026. The appointment is made by the Minister for Home Affairs and Minister for Cyber Security, Tony Burke, under section 66 of the Act. The legislation is specific to the appointment process and the role of the board member, without detailing the broader scope of the Cyber Security Act 2024, which would include its applicability to various entities, industries, and conduct within Australia.
Key Provisions
The Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 1) 2026I, made under section 66 of the Cyber Security Act 2024, appoints Debi Ashenden as a standing member of the Cyber Incident Review Board (section 1). This appointment is made on a part-time basis and will last for a period of four years, starting on 1 May 2026. The primary purpose of this appointment is to provide expertise and oversight in reviewing significant cyber incidents that impact the nation's security.
The Act imposes specific obligations on Debi Ashenden as a standing member of the Cyber Incident Review Board. These include participating in the review of significant cyber incidents, providing expert advice and recommendations to the Board, and ensuring that reviews are conducted in accordance with the legislative requirements and any relevant guidelines. The member must also be available to attend meetings and contribute to the decision-making process in a timely manner.
Failure to comply with the obligations outlined in the Act may result in various consequences. Although specific penalties are not detailed in the notifiable instrument, breaches of statutory duties under the Cyber Security Act 2024 can generally lead to civil or criminal penalties, including fines and imprisonment, depending on the severity of the breach. The maximum penalties for offences under the Act can be significant, reflecting the importance of adhering to the legislative requirements.
The appointment of Debi Ashenden signifies a commitment to enhancing the nation's cyber security posture by ensuring that the Cyber Incident Review Board has the necessary expertise to effectively review and respond to significant cyber incidents. The member's role is critical in providing informed recommendations that help mitigate future risks and improve overall cyber resilience. The detailed provisions in the legislation underscore the importance of rigorous oversight and expert involvement in managing cyber security incidents.