ADMIN 26/108
Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 6) 2026
I, Tony Burke, Minister for Home Affairs and Minister for Cyber Security, under section 66 of the Cyber Security Act 2024, appoint Nathan Morelli as a standing member of the Cyber Incident Review Board, on a part-time basis, for the period of 4 years that begins on 1 May 2026.
Dated 28 April 2026
Tony Burke
Minister for Home Affairs
Minister for Cyber Security
Overview
The Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 6) 2026I is a notifiable instrument issued under the authority of the Cyber Security Act 2024. This legislation was enacted by the Australian Parliament to address the growing need for robust cyber security measures and to enhance the nation's capability to respond effectively to cyber incidents. The Act aims to establish a structured framework for the review and management of cyber incidents, ensuring that the nation can respond swiftly and efficiently to threats that may compromise the security of its digital infrastructure. By appointing Nathan Morelli as a standing member of the Cyber Incident Review Board, the government underscores its commitment to bolstering the board's expertise and capacity to assess and mitigate cyber risks.
The policy objective of this appointment, as outlined in the notifiable instrument, is to strengthen the Cyber Incident Review Board's operational effectiveness by incorporating additional expertise in the field of cyber security. This strategic move is intended to enhance the board's ability to review incidents, provide recommendations, and contribute to the overall resilience of Australia's cyber defences. The appointment is made on a part-time basis for a period of four years, reflecting a long-term commitment to maintaining a skilled and experienced body capable of addressing the evolving landscape of cyber threats.
Scope and Application
The Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 6) 2026 applies to the appointment of Nathan Morelli as a standing member of the Cyber Incident Review Board. This appointment is made under section 66 of the Cyber Security Act 2024 by Tony Burke, the Minister for Home Affairs and Minister for Cyber Security. The Board is a statutory body that reviews significant cyber security incidents and advises on measures to mitigate future incidents. The appointment is made on a part-time basis and will last for a period of four years, commencing on 1 May 2026. The Act applies to the Commonwealth of Australia, and there are no stated exclusions, exemptions, or thresholds that impact this particular appointment. The scope of the Board’s activities and its authority to review incidents are defined by the overarching Cyber Security Act 2024, which may be extended or restricted through subordinate instruments.
Key Provisions
The primary operative section of the ADMIN 26/108 Cyber Security (Member of the Cyber Incident Review Board) Appointment (No. 6) 2026I instrument is section 2, which appoints Nathan Morelli as a standing member of the Cyber Incident Review Board. This appointment is made on a part-time basis and is effective from 1 May 2026, continuing for a period of four years. The instrument provides clarity on the tenure and role of the appointed member, ensuring that the functions of the Board are fulfilled in accordance with the Cyber Security Act 2024.
In accordance with the instrument, Nathan Morelli, as a standing member of the Cyber Incident Review Board, is expected to participate in the review and analysis of cyber incidents that may impact national security. This includes contributing to the Board's deliberations, investigations, and recommendations aimed at enhancing Australia's cyber resilience. The instrument outlines that the appointment is made by Tony Burke, the Minister for Home Affairs and Minister for Cyber Security, under the authority granted by section 66 of the Cyber Security Act 2024.
The Act imposes several obligations on Nathan Morelli as a standing member. These include maintaining confidentiality in relation to sensitive information encountered during the course of their duties, adhering to the Board's protocols and procedures, and actively participating in scheduled meetings and reviews. Morelli is also required to act impartially and with integrity, ensuring that their decisions and recommendations are based on thorough analysis and evidence. The obligations extend to upholding the principles of accountability and transparency in all activities undertaken as part of their role.
Failure to comply with the requirements of the Cyber Security Act 2024 or the specific duties outlined in the appointment instrument may result in civil or criminal penalties. Breaches of confidentiality and misuse of sensitive information, for example, could lead to legal action under the Act. The potential penalties for such breaches can include fines and imprisonment, with the severity of the penalty depending on the nature and extent of the breach. Specifically, the Act provides for maximum penalties, including substantial fines and up to two years imprisonment, for those found guilty of serious breaches related to the handling of sensitive cyber security information.