Industry Research and Development (Cyber Security Small Business Program) Instrument 2017

Administered by Department of Industry, Science and Resources

Legislation au F2017L00685 In force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

Issued by the authority of the Minister for Industry, Innovation and Science

Industry Research and Development Act 1986

Industry Research and Development (Cyber Security Small
Business Program) Instrument 2017

Purpose and Operation

Section 33 of the Industry Research and Development Act 1986 (the IR&D Act) provides a mechanism for the Minister to prescribe programs, by disallowable legislative instrument, in relation to industry, innovation, science or research, including in relation to the expenditure of Commonwealth money under such programs.

The statutory framework provided by s33 of the IR&D Act enables a level of flexibility to provide authority for Commonwealth spending activities in relation to industry, innovation, science and research programs. This allows the Government to respond quickly and appropriately to the need to implement innovative ideas and pilot programs on an ongoing basis and as opportunities arise. Prescribing programs in legislative instruments provides transparency and parliamentary oversight of Government programs and spending activities, whilst reducing administrative burden on the Commonwealth.

Once a program is prescribed by the Minister under s33, subsection 34(1) allows the Commonwealth to make, vary or administer arrangements in relation to activities under the prescribed program. Arrangements may include contracts, funding agreements or other arrangements, and may provide for money to be payable by the Commonwealth to one or more third parties. The power conferred on the Commonwealth by subsection 34(1) may be exercised on behalf of the Commonwealth by a Minister or an accountable authority of a non-corporate entity, or by their delegate (under s36).

The purpose of the Industry Research and Development (Cyber Security Small Business Program) Instrument 2017 is to prescribe the Cyber Security Small Business Program (the Program). The Program was one of several measures announced as part of the Australian Government’s Cyber Security Strategy which was released on 20 April 2016.

The Program comprises two grant activities, with a total administered value of $12 million over four years, beginning in the 2016-17 financial year. The activities will support Australian small businesses to test their cyber security, increase awareness of their cyber security risk, and increase their confidence in the credentials of cyber security service providers. The Program will do this by:

a)      Part A—providing CREST Australia New Zealand Ltd (CREST ANZ) a single grant, of up to $2 million over four years, commencing in the 2016-17 financial year, to assist in growing the pool of CREST ANZ approved members and to expand its range of cyber security services; and

b)     Part B—co-funding, through matched grants of up to $2,100, approximately 5,000 small businesses (less than 20 employees) over two years, commencing in the 2018-19 financial year, to have their cyber security tested by CREST ANZ approved service providers.

Funding authorised by this instrument will come from Program 2: Growing Business Investment and Improving Business Capability, Outcome 1: Enabling growth and productivity for globally competitive industries through supporting science and commercialisation, growing business investment and improving business capability and streamlining regulation, as set out in the Portfolio Budget Statements 2016-17, Budget Related Paper No. 1.12, Industry, Innovation and Science Portfolio at page 33.

Merits review will not be applicable in respect of decisions made in relation to the targeted funding for CREST ANZ (Part A) or the grants for small businesses under the Program (Part B). There was no merits review in relation to the provision of the targeted funding to CREST ANZ for CREST ANZ is a not-for-profit organisation providing certification in cyber security for businesses and individuals. It approves organisations to support the delivery of cyber security testing services, certifies individuals to perform a range of cyber security vulnerability and penetration testing services, and promotes the provision of high quality, best practice cyber security services. CREST ANZ is uniquely placed to deliver this service offering. Merits review will not apply to decisions made in relation to grants for small businesses. All businesses falling within the definition of small business will be eligible to receive grant funding subject to the availability of Program funding and the ability of eligible firms to make a matching funding contribution. The Department of Industry, Innovation and Science (the Department) will establish an appropriate review mechanism for the Program.

The Program will be administered by the Department. Spending decisions will be made by the s34 delegate, who will be the General Manager with responsibility for Industry, Structural Adjustment and Science Programmes, AusIndustry – Business Services. The Program will also be administered in accordance with the Commonwealth Grants Rules and Guidelines (https://www.finance.gov.au/sites/default/files/commonwealth-grants-rules-and-guidelines-July2014.pdf).

The Legislative Instrument specifies that the legislative power in respect of which the Instrument is made is the communications power (section 51(v) of the Constitution), which states that the Commonwealth has power to legislate with respect to 'postal, telegraphic, telephonic and other like services'. In that regard, the prescribed program is confined to assisting businesses utilising online communications services such as the internet, web based applications, and mobile devices and technology.

Part A of the Program will provide the cyber security capability required for Australian organisations to test and upgrade their online security, and facilitate the use of online communication services and technologies.

Part B of the Program will provide for Australian small businesses to have their online security tested by a CREST ANZ Approved service provider. This will increase their awareness of their cyber security risks and enable them to more securely utilise online communication services and technologies.

As described above, all aspects of the Program will rely on the development and use of online communication capabilities to help Australian businesses upgrade their online security and increase their confidence in the credentials of cyber security service providers.

Consultation

In accordance with section 17 of the Legislation Act 2003, the Attorney-General’s Department and the Department of Finance have been consulted on this Legislative Instrument. CREST ANZ and the Department of Prime Minister and Cabinet were consulted on the development of the Program. The Legislative Instrument specifies the agreed Program parameters.

Regulatory Impact

Regulatory impacts for measures announced under the Cyber Security Strategy were evaluated by the Office of Best Practice Regulation (OBPR reference: 19611). The regulatory impact for the Program was assessed as low.

Details of the Industry Research and Development (Cyber Security Small Business Program) Instrument 2017

PART 1 PRELIMINARY

Section 1 – Name of Instrument

This section specifies the name of the Legislative Instrument as the Industry Research and Development (Cyber Security Small Business Program) Instrument 2017.

Section 2 – Commencement

This section provides that the Legislative Instrument commences on the day after registration on the Federal Register of Legislation.

Section 3 – Authority

This section sets out the provision of the Industry Research and Development Act 1986 under which the Legislative Instrument is made.

Section 4 – Definitions

This item provides for definitions of terms used in the Legislative Instrument.

Section 5 – Prescribed program

This section prescribes the Cyber Security Small Business Program under which financial assistance will be provided to: assist CREST ANZ to grow the pool of CREST ANZ approved members and to expand its range of cyber security services; and co-fund small businesses to have their cyber security tested by CREST ANZ approved service providers.

Small business is defined as a business employing less than 20 people. This is consistent with the definition applied by the Australian Bureau of Statistics.

The table specifies in column 1 the name of the program, and in column 2 the description and purpose of the program.

Section 6 – Specified legislative power

This section specifies that the legislative power in respect of which the instrument is made is the power of the Parliament to make laws with respect to postal, telegraphic, telephonic, and other like services.

Statement of Compatibility with Human Rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

Industry Research and Development (Cyber Security Small Business Program)
Instrument 2017

This Legislative Instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Overview of the Legislative Instrument

This instrument provides legislative authority to commit Commonwealth funds for the Cyber Security Small Business Program.

Human rights implications

This Legislative Instrument does not engage any of the applicable rights or freedoms.

Conclusion

This Legislative Instrument is compatible with human rights as it does not raise any human rights issues.

 

Senator the Hon Arthur Sinodinos AO

Minister for Industry, Innovation and Science

 

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.