Industry Research and Development (Cyber Security Small Business Program) Instrument 2017

Administered by Department of Industry, Science and Resources

Legislation au F2017L00685 In force Legislative Instrument

Legislation content

EXPLANATORY STATEMENT

Issued by the authority of the Minister for Industry, Innovation and Science

Industry Research and Development Act 1986

Industry Research and Development (Cyber Security Small
Business Program) Instrument 2017

Purpose and Operation

Section 33 of the Industry Research and Development Act 1986 (the IR&D Act) provides a mechanism for the Minister to prescribe programs, by disallowable legislative instrument, in relation to industry, innovation, science or research, including in relation to the expenditure of Commonwealth money under such programs.

The statutory framework provided by s33 of the IR&D Act enables a level of flexibility to provide authority for Commonwealth spending activities in relation to industry, innovation, science and research programs. This allows the Government to respond quickly and appropriately to the need to implement innovative ideas and pilot programs on an ongoing basis and as opportunities arise. Prescribing programs in legislative instruments provides transparency and parliamentary oversight of Government programs and spending activities, whilst reducing administrative burden on the Commonwealth.

Once a program is prescribed by the Minister under s33, subsection 34(1) allows the Commonwealth to make, vary or administer arrangements in relation to activities under the prescribed program. Arrangements may include contracts, funding agreements or other arrangements, and may provide for money to be payable by the Commonwealth to one or more third parties. The power conferred on the Commonwealth by subsection 34(1) may be exercised on behalf of the Commonwealth by a Minister or an accountable authority of a non-corporate entity, or by their delegate (under s36).

The purpose of the Industry Research and Development (Cyber Security Small Business Program) Instrument 2017 is to prescribe the Cyber Security Small Business Program (the Program). The Program was one of several measures announced as part of the Australian Government’s Cyber Security Strategy which was released on 20 April 2016.

The Program comprises two grant activities, with a total administered value of $12 million over four years, beginning in the 2016-17 financial year. The activities will support Australian small businesses to test their cyber security, increase awareness of their cyber security risk, and increase their confidence in the credentials of cyber security service providers. The Program will do this by:

a)      Part A—providing CREST Australia New Zealand Ltd (CREST ANZ) a single grant, of up to $2 million over four years, commencing in the 2016-17 financial year, to assist in growing the pool of CREST ANZ approved members and to expand its range of cyber security services; and

b)     Part B—co-funding, through matched grants of up to $2,100, approximately 5,000 small businesses (less than 20 employees) over two years, commencing in the 2018-19 financial year, to have their cyber security tested by CREST ANZ approved service providers.

Funding authorised by this instrument will come from Program 2: Growing Business Investment and Improving Business Capability, Outcome 1: Enabling growth and productivity for globally competitive industries through supporting science and commercialisation, growing business investment and improving business capability and streamlining regulation, as set out in the Portfolio Budget Statements 2016-17, Budget Related Paper No. 1.12, Industry, Innovation and Science Portfolio at page 33.

Merits review will not be applicable in respect of decisions made in relation to the targeted funding for CREST ANZ (Part A) or the grants for small businesses under the Program (Part B). There was no merits review in relation to the provision of the targeted funding to CREST ANZ for CREST ANZ is a not-for-profit organisation providing certification in cyber security for businesses and individuals. It approves organisations to support the delivery of cyber security testing services, certifies individuals to perform a range of cyber security vulnerability and penetration testing services, and promotes the provision of high quality, best practice cyber security services. CREST ANZ is uniquely placed to deliver this service offering. Merits review will not apply to decisions made in relation to grants for small businesses. All businesses falling within the definition of small business will be eligible to receive grant funding subject to the availability of Program funding and the ability of eligible firms to make a matching funding contribution. The Department of Industry, Innovation and Science (the Department) will establish an appropriate review mechanism for the Program.

The Program will be administered by the Department. Spending decisions will be made by the s34 delegate, who will be the General Manager with responsibility for Industry, Structural Adjustment and Science Programmes, AusIndustry – Business Services. The Program will also be administered in accordance with the Commonwealth Grants Rules and Guidelines (https://www.finance.gov.au/sites/default/files/commonwealth-grants-rules-and-guidelines-July2014.pdf).

The Legislative Instrument specifies that the legislative power in respect of which the Instrument is made is the communications power (section 51(v) of the Constitution), which states that the Commonwealth has power to legislate with respect to 'postal, telegraphic, telephonic and other like services'. In that regard, the prescribed program is confined to assisting businesses utilising online communications services such as the internet, web based applications, and mobile devices and technology.

Part A of the Program will provide the cyber security capability required for Australian organisations to test and upgrade their online security, and facilitate the use of online communication services and technologies.

Part B of the Program will provide for Australian small businesses to have their online security tested by a CREST ANZ Approved service provider. This will increase their awareness of their cyber security risks and enable them to more securely utilise online communication services and technologies.

As described above, all aspects of the Program will rely on the development and use of online communication capabilities to help Australian businesses upgrade their online security and increase their confidence in the credentials of cyber security service providers.

Consultation

In accordance with section 17 of the Legislation Act 2003, the Attorney-General’s Department and the Department of Finance have been consulted on this Legislative Instrument. CREST ANZ and the Department of Prime Minister and Cabinet were consulted on the development of the Program. The Legislative Instrument specifies the agreed Program parameters.

Regulatory Impact

Regulatory impacts for measures announced under the Cyber Security Strategy were evaluated by the Office of Best Practice Regulation (OBPR reference: 19611). The regulatory impact for the Program was assessed as low.

Details of the Industry Research and Development (Cyber Security Small Business Program) Instrument 2017

PART 1 PRELIMINARY

Section 1 – Name of Instrument

This section specifies the name of the Legislative Instrument as the Industry Research and Development (Cyber Security Small Business Program) Instrument 2017.

Section 2 – Commencement

This section provides that the Legislative Instrument commences on the day after registration on the Federal Register of Legislation.

Section 3 – Authority

This section sets out the provision of the Industry Research and Development Act 1986 under which the Legislative Instrument is made.

Section 4 – Definitions

This item provides for definitions of terms used in the Legislative Instrument.

Section 5 – Prescribed program

This section prescribes the Cyber Security Small Business Program under which financial assistance will be provided to: assist CREST ANZ to grow the pool of CREST ANZ approved members and to expand its range of cyber security services; and co-fund small businesses to have their cyber security tested by CREST ANZ approved service providers.

Small business is defined as a business employing less than 20 people. This is consistent with the definition applied by the Australian Bureau of Statistics.

The table specifies in column 1 the name of the program, and in column 2 the description and purpose of the program.

Section 6 – Specified legislative power

This section specifies that the legislative power in respect of which the instrument is made is the power of the Parliament to make laws with respect to postal, telegraphic, telephonic, and other like services.

Statement of Compatibility with Human Rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

Industry Research and Development (Cyber Security Small Business Program)
Instrument 2017

This Legislative Instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Overview of the Legislative Instrument

This instrument provides legislative authority to commit Commonwealth funds for the Cyber Security Small Business Program.

Human rights implications

This Legislative Instrument does not engage any of the applicable rights or freedoms.

Conclusion

This Legislative Instrument is compatible with human rights as it does not raise any human rights issues.

 

Senator the Hon Arthur Sinodinos AO

Minister for Industry, Innovation and Science

 

Overview

The Industry Research and Development (Cyber Security Small Business Program) Instrument 2017 was enacted to establish a legislative framework for the Cyber Security Small Business Program under the Industry Research and Development Act 1986. This instrument was introduced by the Minister for Industry, Innovation and Science to address the growing need for enhanced cybersecurity measures among small businesses in Australia. The primary policy objective of this legislation is to support Australian small businesses in testing and improving their cybersecurity practices, thereby increasing their resilience against cyber threats and promoting the secure use of online communication services. By providing grants and co-funding opportunities, the Instrument aims to bolster the capacity of CREST Australia New Zealand Ltd, a not-for-profit organisation focused on certifying cyber security services, and to facilitate small businesses in engaging with approved cybersecurity service providers for testing and risk assessment. The instrument was developed to ensure transparency and parliamentary oversight of government spending while providing flexibility in implementing innovative cybersecurity initiatives. The Cyber Security Small Business Program is designed to enhance the cybersecurity capabilities of small businesses, enabling them to better protect their online assets and data. Through this program, the Australian Government seeks to foster a more secure digital environment for businesses, which is critical in an increasingly interconnected world. The initiative is part of broader measures outlined in the Australian Government’s Cyber Security Strategy, reflecting the government's commitment to addressing cyber threats through targeted support for small businesses.

Scope and Application

The Industry Research and Development (Cyber Security Small Business Program) Instrument 2017, issued under the authority of the Minister for Industry, Innovation and Science, establishes a legislative framework for the Cyber Security Small Business Program. This program is designed to support Australian small businesses, defined as entities with fewer than 20 employees, in enhancing their cybersecurity measures. The Program is part of the Australian Government's broader Cyber Security Strategy, aiming to bolster the cyber resilience of small businesses through testing and awareness initiatives. The Program comprises two main grant activities, with a total value of $12 million over four years. The first part provides funding to CREST Australia New Zealand Ltd (CREST ANZ) to expand its services and membership base, while the second part co-funds approximately 5,000 small businesses for cybersecurity testing by CREST ANZ-approved providers. The Commonwealth's legislative power to enact this instrument derives from the authority to make laws concerning postal, telegraphic, telephonic, and other similar services, underpinning the program's focus on online communications services and technologies. The instrument specifies that no merits review applies to decisions related to the grants, and the Department of Industry, Innovation and Science is responsible for administering the program.

Key Provisions

The Industry Research and Development (Cyber Security Small Business Program) Instrument 2017 prescribes the Cyber Security Small Business Program under Section 5 of the Instrument. This Program is divided into two parts: Part A, which provides a grant to CREST Australia New Zealand Ltd (CREST ANZ) to grow the pool of its approved members and expand its range of cyber security services; and Part B, which provides matched grants to approximately 5,000 small businesses to have their cyber security tested by CREST ANZ approved service providers. The Instrument provides the legal basis for the Commonwealth to allocate funds to these activities under Section 33 of the Industry Research and Development Act 1986 (IR&D Act). The obligations imposed by this Instrument on the Commonwealth, CREST ANZ, and the small businesses involve the provision and receipt of financial assistance under the Program. The Commonwealth is obligated to commit funds as specified in the Instrument, and these funds will be used to support CREST ANZ and small businesses in enhancing their cyber security capabilities. CREST ANZ must use the funds provided under Part A of the Program to grow its membership and expand its cyber security services. Small businesses receiving grants under Part B must use the funds for the purpose of having their cyber security tested by CREST ANZ approved service providers and must meet any matching funding requirements stipulated in the grants. There are no specific offences, penalties, or consequences for breach outlined in the Instrument itself. However, the IR&D Act and the Commonwealth Grants Rules and Guidelines provide the overarching legal framework under which the Program operates. Breaches of these broader legal frameworks, such as misuse of funds or failure to comply with grant conditions, could result in civil or criminal penalties. The specific penalties would depend on the nature and severity of the breach, but they could include financial penalties, recovery of funds, or other administrative or legal consequences. The legislative power underpinning this Instrument is the Commonwealth's authority to legislate with respect to postal, telegraphic, telephonic, and other like services as provided under Section 51(v) of the Constitution. This power allows the Commonwealth to implement the Program, which aims to assist businesses in enhancing their online security capabilities and utilising online communication services more securely. The Instrument specifies that the Program is confined to assisting businesses that use online communication services, such as the internet, web-based applications, and mobile devices and technology.

Legal classification tags

Area of Law
Technology Law
Instrument
Legislative Instrument
Concepts
Definitions & Interpretation
Regulatory Standards
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.