The NOCS is not a regulator and does not have regulatory compliance functions.
We understand that impacted organisations will have different levels of experience and knowledge of incident response. We recognise organisations may need different levels of support. We can give tailored support that reflects:
- your situation
- the nature of the incident and
- the actual or potential consequences of the incident.
Our team helps organisations respond in many ways. Our team acts as a central touchpoint between:
- your organisation
- the Australian Government
- state and territory governments and
- industry stakeholders.
This reduces the burden on you and your response teams.
We work closely with your organisation, or its representatives, to understand the potential impacts of an incident. We will connect you with relevant government bodies to support you to understand and manage those impacts. This includes areas specialising in:
- crisis management
- technical response
- legal implications
- public relations and more.
We facilitate meetings with your organisation and relevant stakeholders to address specific consequences arising from the incident. This allows your organisation to concurrently share critical and timely information across government portfolios and industry groups with a relevant interest in the response to an incident.
We will establish working groups where needed to undertake specific lines of effort for consequence management purposes.
We work with your organisation to coordinate on any necessary government communication products about the government’s response to an incident.
Who should engage us and when
Our team can support any organisation experiencing significant cyber security incident that:
- may be of national significance or national interest and
- will benefit from coordination for consequence management.
This includes incidents with impacts on critical infrastructure or government assets or data. This may be across multiple sectors or jurisdictions and have potential to cause significant harm to:
- Australians
- their businesses
- critical infrastructure.
We encourage organisations to engage us as soon as possible. You may reach out even if you are unsure, or do not have all the information yet. Contacting the NOCS does not commit you to ongoing engagement regarding the incident.
We understand that it can often take time to understand the scope of a cyber security incident’s impact. Early engagement helps us assess your incident. It allows us to take immediate steps to prepare for any consequence management coordination and provide you with advice specific to your incident. We may also refer you to more appropriate avenues within government, depending on the situation.
Why you should work with us
Our focus is on timely and efficient information sharing and engagement. This will allow your incident and crisis management teams to focus on other aspects of your response. We can do this by:
- providing a central contact point for government engagement
- providing specific contact points across the Australian Government and state and territory governments as required
- reducing the volume of stakeholder engagements you need to attend
- helping you understand the roles and remits between government departments and agencies
- coordinating requests for information to allow you to consider and respond to a range of questions from many stakeholders
- guiding you through the response process to help sequence your response activities
- leveraging our extensive networks to link you with government and industry stakeholders
- we will also seek your feedback following our coordination and consequence management efforts. This will help improve government’s ability to support impacted organisations in the future.
What we can’t do for you
While we can give you advice on issues you may wish to consider, we will not tell your organisation how you should respond to your incident. This is the responsibility of your organisation.
Our team cannot give technical advice or assistance to respond to the incident. We cannot remediate technical issues or support system recovery efforts. You should contact the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) for technical help.
We cannot report your incident to law enforcement or make a regulatory report on your behalf. For example, a report to the Australian Federal Police, or to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme. Your organisation must take these steps as necessary.
Our team does not hold personal, sensitive, commercial-in-confidence and legally privileged information affected by an incident. We cannot share this kind of information between you and government stakeholders either.
We cannot support every organisation experiencing a cyber security incident. We will discuss with your organisation factors such as the nature, scale or sensitivity of your incident to determine our involvement. If we are unable to give support, we may tell you how to engage with government stakeholders.
The Voluntary Code of Practice for Cyber Incident Response Providers
Under Horizon 1 of the 2023-2030 Australian Cyber Security Strategy, the Australian Government committed to providing business and community leaders with greater confidence when they engage cyber security professionals to support them during a cyber security incident. This includes co-designing a Voluntary Code of Practice for Cyber Incident Response Providers (the Code).
The Code has been co-developed by the National Office of Cyber Security (NOCS) and Australian Signals Directorate (ASD) and has been extensively consulted across industry. The Code aims to provide clarity around expected service quality and professional standards of cyber security incident response providers.
Find out more about The Voluntary Code of Practice for Cyber Incident Response Providers.
MediSecure cyber security incident
The Australian Government has been advised by MediSecure that approximately 12.9 million individuals may have had their personal and health information relating to prescriptions, as well as healthcare provider information exposed by a cyber security incident. Read more on the MediSecure cyber security incident.