We can give you advice on issues you may wish to consider, however we will not tell your organisation how you should respond to your incident. This is the responsibility of your organisation.
Our team cannot give technical advice or assistance to respond to the incident. We cannot remediate technical issues or support system recovery efforts. Contact the Australian Signals Directorate's Australian Cyber Security Centre (ACSC) for technical help.
We cannot report your incident to law enforcement or make a regulatory report on your behalf. For example, a report to the Australian Federal Police, or to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Your organisation must take these steps as necessary.
Our team does not hold personal, sensitive, commercial-in-confidence and legally privileged information affected by an incident. We cannot share this kind of information between you and government stakeholders either.
We cannot support every organisation experiencing a cyber security incident. We will discuss with your organisation factors such as the nature, scale or sensitivity of your incident to determine our involvement. If we are unable to give support, we may tell you how to engage with government stakeholders.
Role and functions of the National Office of Cyber Security
The National Office of Cyber Security (NOCS) is not a regulator and does not perform regulatory or compliance functions. Any information voluntarily provided to the NOCS in relation to a cyber security incident or potential incident will be used in accordance with Limited Use, Part 4 of the Cyber Security Act 2024. Read about Limited Use for the National Cyber Security Coordinator.
National Office of Cyber Security support
The NOCS supports organisations by coordinating whole of government consequence management during cyber security incidents of national significance. This function is led by the National Cyber Security Coordinator and is focused on mitigating impacts rather than providing technical remediation.
Recognising that organisations have varying levels of cyber incident response capability, the NOCS provides tailored, situational support based on:
- the organisation's circumstances,
- the nature and scale of the incident
- the actual or potential consequences.
The NOCS acts as a central coordination point between impacted organisations, Australian Government agencies, state and territory governments, and relevant industry stakeholders. This coordination helps streamline engagement, ensure alignment across jurisdictions, and support timely decision making.
Consequence management and coordination
The NOCS works closely with organisations, or their representatives, to understand the broader implications of a cyber security incident. Where appropriate, the NOCS facilitates connections with relevant government bodies specialising in areas such as:
- crisis and consequence management
- legal and regulatory considerations
- public communications and media engagement
- other non-technical domains relevant to managing impacts.
To reduce the operational burden on impacted organisations, the NOCS may coordinate government communication products relating to the overall response. The NOCS also convenes meetings and, where necessary, establishes targeted working groups to address specific consequences arising from an incident. This approach enables the concurrent sharing of critical and time sensitive information across government portfolios and relevant industry groups.
Through this collaborative model, the NOCS seeks to ensure that:
- responses are effectively coordinated
- information is shared rapidly and appropriately
- impacts on individuals, businesses, and essential services are identified and mitigated as early as possible.
Limitations of National Office of Cyber Security involvement
The NOCS does not provide technical cyber security advice or assistance and does not undertake:
- technical incident response or remediation
- system recovery activities
- the provision of technical support tools or services.
Organisations requiring technical assistance should contact the Australian Signals Directorate's Australian Cyber Security Centre (ACSC), which is responsible for technical cyber incident response support.
The NOCS also:
- does not report cyber security incidents to law enforcement or regulators on behalf of organisations or individuals (for example, reports to the Australian Federal Police or notifications under the Notifiable Data Breaches scheme to the Office of the Australian Information Commissioner remain the responsibility of the affected entity), and
- does not collect, hold, or distribute personal, sensitive, commercial in confidence, or legally privileged information relating to a cyber security incident.
Scope of engagement
The NOCS is not able to support every cyber security incident. As such, engagement is determined through discussion with affected entities or individuals, considering factors such as the nature, scale, sensitivity, and potential national impact of the incident. Where the NOCS is unable to provide direct support, it may offer guidance on how to engage with other relevant government agencies or stakeholders.