EXPLANATORY STATEMENT
Issued by the authority of the Secretary of the Department of Home Affairs
Maritime Transport and Offshore Facilities Security Act 2003
Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2026
Legislative authority
The Maritime Transport and Offshore Facilities Security Act 2003 (the Act) establishes a regulatory framework to safeguard against unlawful interference with maritime transport and offshore facilities. The Act also serves to prevent the use of maritime transport in connection with serious crime. To achieve these purposes, the Act establishes minimum security requirements for civil maritime entities in Australia by imposing obligations on persons engaged in civil maritime related activities. These obligations include the reporting of any aviation security incidents or cyber security incidents to the Department of Home Affairs and the Australian Signals Directorate (ASD).
The Act is the legislative authority for reporting incidents. Specifically, Part 9 of the Act establishes the requirement to report maritime transport or offshore facility security incidents, including cyber security incidents. Within Part 9, subsection 182(1) of the Act provides that the Secretary may, by legislative instrument, specify the information that must be included in a report required by Part 9 of the Act and the way in which the report must be made.
Subsection 33(3) of the Acts Interpretation Act 1901 provides that, where an Act confers a power to make, grant or issue any instrument of a legislative or administrative character (including rules, regulations or by-laws), the power shall be construed as including a power exercisable in the like manner and subject to the like conditions (if any) to repeal, rescind, revoke, amend or vary any such instrument.
Background
Part 9 of the Act establishes the requirement to report maritime security incidents and cyber security incidents.
Section 170(1) defines a maritime transport or offshore facility security incident as both a
threat of unlawful interference with maritime transport or offshore facilities and an unlawful interference with maritime transport or offshore facilities.
Section 10B defines a cyber security incident to mean one or more acts, events or circumstances involving unauthorised access to, or modification of computer data or a computer program, or unauthorised impairment of electronic communication to or from a computer, or unauthorised impairment of the availability, reliability, security or operation of a computer, computer data or a computer program.
Reporting obligations for port operators
Subsection 171(4) provides that port operators must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of a maritime asset to the Secretary of the Department of Home Affairs (the Secretary) and the ASD within 12 hours after becoming aware of the incident.
Subsection 171(5) provides that port operators must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of a maritime asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.
Subsection 177(1) provides that port operators must report maritime transport or offshore facility security incidents, other than a cyber security incident, in accordance with section 177. In particular, paragraph 177(2)(a) provides that a maritime transport or offshore facility security incident that relates to the port of the port operator must be reported to the Secretary.
Reporting obligations for ship masters
Subsection 172(4) provides that a ship master must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of a maritime asset to the Secretary and the ASD within 12 hours after becoming aware of the incident.
Subsection 172(5) provides that a ship master must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of a maritime asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.
Subsection 178(1) provides that a ship master must report maritime transport or offshore facility security incidents, other than a cyber security incident in accordance with section 178. In particular, paragraph 178(2)(a) provides that a maritime transport or offshore facility security incident that relates to a ship of the ship operator must be reported to the Secretary.
Reporting obligations for ship operators
Subsection 173(4) provides that a ship operator must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of a maritime asset to the Secretary and the ASD within 12 hours after becoming aware of the incident.
Subsection 173(5) provides that a ship operator must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of a maritime asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.
Subsection 179(1) provides that a ship master must report maritime transport or offshore facility security incidents, other than a cyber security incident in accordance with section 179. In particular, paragraph 179(2)(a) provides that a maritime transport or offshore facility security incident that relates to a security regulated ship of the ship operator must be reported to the Secretary.
Reporting obligations for offshore facility operators
Subsection 174A(4) provides that an offshore facility operator must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of a maritime asset to the Secretary and the ASD within 12 hours after becoming aware of the incident.
Subsection 174A(5) provides that an offshore facility operator must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of a maritime asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.
Subsection 179A(1) provides that an offshore facility operator must report maritime transport or offshore facility security incidents, other than a cyber security incident in accordance with section 179A. Paragraph 179A(2)(a) provides that a maritime transport or offshore facility security incident that relates to a security regulated offshore facility of the offshore facility operator must be reported to the Secretary.
Reporting obligations for port facility operators
Subsection 174(4) provides that a port facility operator must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of a maritime asset to the Secretary and the ASD within 12 hours after becoming aware of the incident.
Subsection 174(5) provides that a port facility operator must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of a maritime asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.
Subsection 180(1) provides that a port facility operator must report maritime transport or offshore facility security incidents, other than a cyber security incident in accordance with section 180. In particular, paragraph 180(2)(a) provides that a maritime transport or offshore facility security incident that relates to the port facility of the port facility operator must be reported to the Secretary.
Reporting obligations for persons with incident reporting responsibilities
Subsection 175(3A) provides that other persons with incident reporting responsibilities must report a cyber security incident that has had, is having, or is likely to have a significant impact on the availability of a maritime asset to the Secretary and the ASD within 12 hours after becoming aware of the incident.
Subsection 175(3B) provides that other persons with incident reporting responsibilities must report a cyber security incident that has had, is having, or is likely to have a relevant impact on the availability of a maritime asset to the Secretary and the ASD within 72 hours after becoming aware of the incident.
Subsection 181(1) provides that other persons with incident reporting responsibilities must report maritime transport or offshore facility security incidents, other than a cyber security incident in accordance with section 181. In particular, paragraph 181(2) provides that a maritime transport or offshore facility security incident must be reported to the Secretary.
Form and information requirements of security incident and cyber security incident reports
Section 182 outlines how reports are to be made. Subsection 182(1) provides that the Secretary may, by legislative instrument, specify the information that must be included in a report required by Part 9 of the Act and the way in which the report must be made.
Subsection 182(3) provides that if a report is made under Part 9 of the Act and the report does not comply with the requirements of the legislative instrument made under subsection 182(1), then that report is taken not to have been made.
Purpose and effect
The Transport Security Amendment (Security of Australia’s Transport Sector) Act 2025 (the TSA Act) commenced on 28 March 2025. The TSA Act introduced the requirement for certain persons engaged in maritime-related activities to report cyber security incidents that have had, are having, or are likely to have a significant or relevant impact on a maritime asset. Industry participants are required to submit reports to the Department of Home Affairs and the ASD within specific timeframes from when they become aware of the incident.
The purpose of the Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2026 (the Instrument) is to introduce new requirements and methods of incident reporting for cyber security incidents, while substantially replicating the existing requirements and methods of incident reporting for other maritime transport or offshore facility security incidents.
The updated incident reporting requirements clarify the processes by which industry participants must submit maritime transport or offshore facility security incident reports and cyber security incident reports. The Instrument prescribes the information that must be included in reports to enable industry participants to comply effectively with the obligations imposed by the Act. The Instrument also ensures that the government receives reports in a form that is suitable for the intended purpose of gaining visibility of relevant incidents that have impacted the security or reliable operations of the transport sector. The reports assist the government in gaining greater insight into the threat landscape faced by the transport sector.
The Instrument repeals and replaces the Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2018. The instrument was made by a delegate of the Secretary of the Department of Home Affairs.
Consultation
The Department has consulted with industry on cyber security incident reporting since 2024. Industry has been generally supportive and noted the benefit of reducing duplication of legislative requirements and reporting processes. Between May and July 2024, the Department of Home Affairs consulted industry regarding the reforms in the Transport Security Amendment (Security of Australia's Transport Sector) Act 2025. Most industry participants supported the proposal to incorporate cyber security incidents within the definition of unlawful interference and provided input into how the new reporting requirements could work in practice.
The Parliamentary Joint Committee on Intelligence and Security’s report on the Transport Security Amendment (Security of Australia’s Transport Sector) Act 2025 recommended that the Department identify and address any duplication of reporting requirements and facilitate coordinated and efficient reporting. To reduce legislative duplication and minimise administrative burden, the Department will establish processes to allow industry to satisfy its regulatory obligation to report to the ASD across multiple frameworks by making one cyber incident report to ASD. Following further consultation with industry in March 2026 on exposure drafts of the Instrument, industry remains supportive.
At the time of writing, the Australian Government is also developing a Single Reporting Portal for cyber security incidents, which once in operation, should allow for greater sharing of information made through a single report.
Details and operations
Details of the Instrument are set out in Attachment A.
The Instrument is a Disallowable Legislative Instrument under section 42 of the Legislation Act 2003.
The Instrument commences on 27 March 2026.
Other matters
A Statement of Compatibility with Human Rights has been prepared in relation to the instrument and is at Attachment B.
Attachment A
Details of the Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2026
Section 1 Name
Section 1 provides that the name of the instrument is the Maritime Transport and Offshore Facilities (Incident Reporting) Instrument 2026 (the Instrument).
Section 2 Commencement
Section 2 provides that the Instrument commences on the later of the day after it is registered, and commencement of Part 1 of Schedule 1 to the Transport Security Amendment (Security of Australia’s Transport Sector) Act 2025. The effect of this is where that Part commences at a later timethe Instrument commences immediately after the commencement of that Part.
Section 3 Authority
Section 3 provides that the authority to make the Instrument is subsection 182(1) of the Maritime Transport and Offshore Facilities Security Act 2003 (the Act).
Section 4 Definitions
Section 4 provides the meaning for defined terms used in the Instrument.
The note at the start of section 4 provides that certain definitions used in the Instrument, being the definitions of ‘cyber security incident’, ‘ISSC’, ‘maritime industry participant’, ‘maritime transport or offshore facility incident’, ‘offshore facility’, ‘relevant impact’, ‘significant impact’, ‘ship’, and ‘unlawful interference with maritime transport or offshore facilities’ are defined in the Act.
The term Act means the Maritime Transport and Offshore Facilities Act 2003.
The term cyber security incident report means a report required to be made to the Secretary under Part 9 of the Act for a cyber security incident.
The term Department means the Department of Home Affairs.
The term industry participant means a maritime industry participant.
The term relevant cyber security incident means a cyber security incident that has a relevant impact.
The term security incident means a maritime transport or offshore facility security incident.
The term security incident report means a report required to be made to the Secretary under Part 9 of the Act for a security incident.
The term significant cyber security incident means a cyber security incident that has a significant impact.
The term unlawful interference means unlawful interference with maritime transport or offshore facilities.
Section 5 Schedules
Section 5 provides that each instrument that is specified in a Schedule to the Instrument is amended or repealed as set out in the applicable items in the Schedule concerned and that any other item in a Schedule to the Instrument has effect according to its terms.
Section 6 Information that must be included in a security incident report
Section 6 sets out the manner in which a security incident report is to be made. In doing so, it substantially replicates section 6 of the Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2018 (the Previous Instrument).
Subsection 6(1) provides that this section specifies, for the purposes of paragraph 182(1)(a) of the Act, the information that must be included in a security incident report.
Subsection 6(2) prescribes the information that must be included in a security incident report. This includes:
- the name, contact number, and email address of the person making the report;
- the title or position held by the person making the report;
- the name of the employer of the person making the report (where applicable);
- the date of the report;
- the date and time the security incident commenced;
- the date and time the security incident ceased;
- the location of the security incident (including, where applicable, the name and address of the location where the security incident occurred);
- the industry participant or participants to whom the security incident relates;
- the industry participant or participants who are affected as a result of the security incident;
- whether the report is a result of a routine security inspection;
- a detailed description of the security incident, including an indication as to whether the incident was a threat of unlawful interference or an unlawful interference; and
- the steps the industry participant has taken, or is in the process of taking, to ensure the security incident does not occur again; and
- information set out in subsections (3), (4), (5), (6), (7) or (8), where those subsections apply.
The note clarifies the compliance position where an industry participant does not have the required information at the time of reporting under subsection 6(2). It draws the reader’s attention to subsection 7(2), which sets out requirements in relation to providing further information.
Subsection 6(3) prescribes the information that must be included in a report if the security incident was a threat of unlawful interference. This includes:
- the name and contact details of the person who received the threat;
- the details of the threat;
- whether the threat is assessed as genuine or as a hoax and how that assessment was made; and
- whether the person who made the threat attempted, is in the process of committing, completed, or failed in the act of unlawful interference.
Subsection 6(4) prescribes the information that must be included if the security incident involves or involved a ship. This includes:
- the name of the ship and its flag;
- the size and type of ship;
- the IMO and ISSC numbers; and
- if applicable, the type of cargo on board.
Subsection 6(5) prescribes the information that must be included if the security incident involved an offshore facility, a building or other infrastructure. This information includes a building number or other identifier that could sufficiently identify the building or other infrastructure.
Subsection 6(6) prescribes the information that must be provided where the security incident has previously been reported to the Secretary. This includes the approximate time and date of the earlier report, and the name or position of the person, or the name of the area within the Department, to whom the incident was reported to.
Subsection 6(7) prescribes the information that must be included if the security incident has been previously reported to the police, an industry participant, or any other body. This includes the approximate time and date of the report, and the name and contact information of the person the incident was reported to or a relevant engagement identifier such as a case number, incident report number or other relevant identifier.
Subsection 6(8) prescribes the information that must be included if the security incident has been brought to the attention of an industry participant by a third party. This includes a statement indicating that the report is being made because of a notification from a third party, and the name of that third party, as well as the name of their employer where applicable.
The purpose of section 6 of the Instrument is to ensure the information contained in any security incident reports assists the Department of Home Affairs (the Department) to capture and efficiently monitor maritime transport or offshore facility security incidents.
Section 7 Way in which a security incident report is to be made
Section 7 substantially replicates section 7 of the Previous Instrument and sets out the manner in which a security incident report is to be made.
Subsection 7(1) specifies that once a security incident is identified, a security incident report must be made to the Secretary no later than 24 hours after the industry participant first becomes are of the incident.
Subsection 7(2) specifies that if an industry participant does not have any or part of the information required by section 6 for the making of a security incident report, but later attains it, this information must be passed on to the Secretary, and this must be done no later than 24 hours after obtaining the information.
The purpose of subsection 7(2) is to ensure that the Secretary cannot penalise an industry participant for failing to include information in a security incident report that was not known to them at the time of the initial report. The provision also recognises the need for that information to be provided to the Secretary promptly once that information becomes available.
Subsection 7(3) specifies that a security incident report can be made either orally via the phone on 1300 791 581, online via the Department’s security incident reporting form at https://www.homeaffairs.gov.au/help-and-support/departmental-forms/online-forms/maritime-security-incident-report-form or by email to transport.security@homeaffairs.gov.au.
Subsection 7(4) specifies that if a security incident report is made orally, the report must also be made in writing through the online form in paragraph 3(b) or by email in paragraph 3(c) within 24 hours after the security incident report is made orally, and must contain the information required under section 6.
Section 8 Notification of a cyber security incident report
Subsection 8(1) specifies, for the purposes of paragraph 182(1) of the Act, the requirements that a cyber security incident report must satisfy.
Subsection 8(2) sets out the information that must be included in a cyber security incident report:
- the name, contact number, and email address of the person making the report;
- the name of the employer of the person making the report;
- the state or territory and postcode of the employer of the person making the report;
- the date and time the incident was identified;
- whether the incident is ongoing;
- the nature or type of cyber security incident that is occurring or has occurred; and
- a detailed description of the cyber security incident that is occurring or has occurred.
The note clarifies the compliance position where an industry participant does not have the required information at the time of reporting under subsection 8(2). It draws the reader’s attention to subsection 9(4), which sets out requirements in relation to providing further information in the way that subsection specifies.
Section 9 Way in which a cyber security incident report is made
Subsection 9(1) provides that a cyber security incident report must be submitted online via the Australian Cyber Security Centre’s portal at https://www.cyber.gov.au/report-and-recover/report.
Subsection 9(2) provides that where a cyber security incident report is made using the method set out in subsection (1), and consent is not given to share the report with the Secretary, the information must be submitted to the Secretary online via the Department’s form available at https://www.homeaffairs.gov.au/help-and-support/departmental-forms/online-forms/maritime-security-incident-report-form
Subsection 9(3) provides that where information is submitted to the Secretary using the method in subsection (2), it must be provided as soon as possible and, in any event, within 12 hours of the industry participant becoming aware of a significant cyber security incident, or within 72 hours of becoming aware of a relevant cyber security incident, as prescribed by the Act.
Subsection 9(4) provides that if, at the time of making a cyber security incident report, the industry participant does not possess some or all of the information required under section 8 but subsequently obtains that information, the industry participant must provide it using one of the methods set out in subsection (1) as soon as possible, and no later than 24 hours after obtaining it.
Subsection 9(5) provides that if information is given for the purposes of subsection (4) and consent is not given to share that information with the Secretary, the information must be submitted to the Secretary using the method in subsection (2) as soon as possible, and no later than 24 hours after it is obtained.
10 Reporting requirements—incidents occurring before commencement
Section 10 provides that the Instrument applies to reports made in accordance with Division 4 of Part 9 of the Act on or after its commencement. It also applies to any additional information that must be provided to the Secretary in relation to a Division 4 report made before the Instrument commences.
The effect of this provision is that industry participants who reported a security incident (including cyber security incidents) according to the Previous Instrument will be able to provide further information in relation to that incident using the new general reporting procedures outlined in this Instrument. This preserves continuity and negates any need for industry participants to make new reports according to the Instrument for an incident that has already been reported on - for example, where the incident was a cyber security incident.
Schedule 1 Repeals
Item 1 of Schedule 1 to the 2026 Instrument has the effect of repealing the Previous Instrument, Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2018.
ATTACHMENT B
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011
Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2026
The Disallowable Legislative Instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.
Overview of the Disallowable Legislative Instrument
The Maritime Transport and Offshore Facilities Security Act 2003 (the Act) establishes a legislative framework that contains obligations aimed at protecting civil maritime transport and offshore facilities and to prevent the use of maritime transport in connection with serious crime. To achieve these purposes, the Act establishes minimum security requirements for civil maritime entities in Australia by imposing obligations on persons engaged in civil maritime related activities. The Transport Security Amendment (Security of Australia’s Transport Sector) Act 2025 (the TSA Act) commenced on 28 March 2025. The TSA Act introduced into the Act the requirement for certain persons engaged in maritime-related activities to report cyber security incidents that have had, are having, or are likely to have a significant or relevant impact on a maritime asset.
Part 9, Division 5 of the Act sets out the requirements for the form, content, and manner in which maritime security and cyber security incident reports must be made. It provides that the Secretary of the Department of Home Affairs (Home Affairs), through a legislative instrument, may specify the precise information that maritime industry participants must include in their reports, as well as the approved methods for submitting them. This ensures that reporting obligations remain clear, consistent, and responsive to operational and security needs.
Timely and accurate reporting of security incidents is essential to maintaining the safety, resilience, and integrity of Australia’s maritime transport and offshore facility sectors. Incident reporting enables the early identification of emerging threats, supports coordinated responses across government and industry, and ensures that lessons learned from previous incidents can be applied to strengthen security arrangements. In recent years, rapid technological advancements and the increasing use of digital systems across maritime operations have created new avenues for unlawful interference and security threats. Cyber incidents in particular now pose significant risks to the continuity, safety, and operational control of maritime infrastructure.
The Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2026 (MTOFSI) repeals and replaces the Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2018. It introduces new requirements and methods of incident reporting for cyber security incidents, while substantially replicating the existing requirements and methods of incident reporting for maritime transport or offshore facility security incidents. The MTOFSI specifies the information that must be included when maritime industry participants report maritime security incidents and cyber security incidents under Part 9 of the Act and sets out the approved methods for making those reports. The MTOFSI provides clarity for industry participants in meeting their reporting obligations under the Act, while also ensuring operational relevance in the information provided to the Home Affairs.
Updating the incident reporting framework through this instrument ensures that it remains responsive to modern security environments, captures both physical and cyber threats, and continues to provide government and industry with the information needed to protect maritime transport and offshore facilities.
Human rights implications
The MTOFSI may engage the right to privacy in Article 17 of the International Covenant on Civil and Political Rights (ICCPR).
Article 17 of the ICCPR provides:
1. No one shall be subjected to arbitrary or unlawful interference with his privacy, family, home or correspondence, nor to unlawful attacks on his honour and reputation.
2. Everyone has the right to the protection of the law against such interference or attacks.
Pursuant to Article 17(1) of the ICCPR, any interference with an individual’s privacy must have a lawful basis. Interference with privacy may be permissible provided that it is authorised by law and is not arbitrary. For an interference with the right to privacy not to be arbitrary, the interference must be for a reason consistent with the provisions, aims and objectives of the ICCPR and be reasonable in the particular circumstances. The United Nations Human Rights Committee has interpreted ‘reasonableness’ in this context to mean that ‘any interference with privacy must be proportional to the end sought and be necessary in the circumstances of any given case’. The term unlawful means that no interference can take place except as authorised under domestic law.
The MTOFSI may engage the right to privacy as it specifies information that must be included in security incident reports and cyber security incident reports and may involve (where applicable) the collection, use and disclosure of personal information. This includes the name, contact number, and email address of the person making the report. For security incident reports, it may also include the name and contact details of a person who received a threat of unlawful interference and where applicable, the names of the person to whom an incident has been previously reported, including police officers, or third parties (including employers of third parties) who have informed the reporter of the incident.
In such instances, any limitation on the right to privacy is for the legitimate objective of protecting Australia’s national security. The measure is rationally connected to that objective because these reports will help Australia to identify and mitigate security and cyber security risks that are a threat to Australia’s national security through the disruption of operations in the maritime sector. The reports also allow for the provision of technical assistance for cyber security incidents from the Australian Government, with consent, which can contribute to containing and limiting the consequences of cyber security incidents.
The reporting requirements in the MTOFSI are lawful, as they are authorised by subsection 182(1) of the Act. Any limitation on the right to privacy by the MTOFSI is also not arbitrary, as to the extent that personal information may be included in security or cyber security incident reports it is rationally connected to the objective of protecting Australia’s national security and is subject to the below safeguards.
The requirements in the MTOFSI ensure that any limitation on the right to privacy is no more restrictive than necessary. The use and disclosure of information recorded, made or used under the MTOFSI will be restricted to purposes authorised under the Act and the Australian Border Force Act 2015 (ABF Act). It is a criminal offence to use or disclose protected information other than as authorised under Part 6 of the ABF Act.
Reports are required to be made to Home Affairs and the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) within specific timeframes from when the industry participant (IP) becomes aware of the incident. Cyber security incident reports are to be made online through the ACSC’s reporting portal. If the IP reporting the incident does not consent to sharing the cyber security incident report with Home Affairs, a separate report must be submitted to Home Affairs online within the specified timeframe. Non-cyber security incidents must be reported to Home Affairs orally via telephone, online via the Home Affairs website or by email.
All information collected on ASD’s ACSC’s portal is subject to the limited use provisions in the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024. The limited use obligation intends to provide additional assurance that cyber security information voluntarily shared with ASD’s ACSC, or that is acquired or prepared by ASD’s ACSC with the consent of an impacted entity, is protected. Information protected by the limited use obligation cannot be used for regulatory action or admitted as evidence in civil or criminal proceedings against the impacted entity, except in certain circumstances. It is automatically applied and encourages proactive, timely and voluntary information sharing relating to cyber security incidents with the Australian Government.
The Australian Government is developing a Single Reporting Portal for cyber security incidents, which once in operation, will allow for greater sharing of information made through a single report.
Any limitation on the right to privacy that may arise through this measure is proportionate, as the information collected is subject to safeguards including through the ABF Act (that it may only be used to pursue the prevention, or minimisation, of the consequences of unlawful interference with the operation of maritime and offshore facilities) and the Privacy Act 1998 (Privacy Act), and is the least restrictive option available to allow the government to assist an affected IP with its response and recovery.
Specific safeguards in the Privacy Act and the Australian Privacy Principles (APPs) contained in Schedule 1 to that Act, apply when collecting personal information for a security incident report under the MTOFSI. Under APP 3, only information reasonably necessary for maritime or offshore security functions may be collected. APP 5 requires notifying individuals of the collection purpose unless an exemption such as the law‑enforcement exception applies. APP 6 restricts further use or disclosure unless as required by the Act’s reporting obligations in sections 101 and 102. APP 11 requires protecting security incident information from misuse, interference, loss, and unauthorised access, modification or disclosure.
Collecting personal information through a security or cyber security incident report is a necessary component of enabling government support throughout an IP’s response or recovery phase. It also contributes to the legitimate objective of preserving national security and the economic prosperity of Australia by minimising and mitigating the consequences of security and cyber security incidents on the maritime and offshore facility sectors.
The information to be provided by an IP will be a high-level report of the incident within a specified period. Any personal information collected is consistent with the provisions, aims and objectives of the ICCPR and is reasonable in the circumstance of a security incident.
Any personal information included as part of the security incident report will only be in relation to the incident itself. This engagement is both necessary and proportionate to allow Home Affairs, or the ASD’s ACSC to appropriately understand and respond to a security incident.
Where the instrument requires the collection of personal information, such as the contact details of the person making the report or of individuals involved in a threat, these requirements are reasonable, necessary, and proportionate to the objective of maintaining maritime security and effectively managing transport‑related risks. The information required is limited to what is operationally necessary to identify, assess, and respond to incidents that may affect maritime transport or offshore facilities.
Conclusion
The MTOFSI is compatible with human rights because to the extent that it may limit human rights, those limitations are reasonable, necessary and proportionate to achieving a legitimate objective.
Matthew Pedler
Delegate of the Secretary of the Department of Home Affairs