Multiple regulators, one incident: insurers flag the compliance gap

A closing federal consultation has drawn out the structural tensions behind Australia's cyber framework

Multiple regulators, one incident: insurers flag the compliance gap

Cyber

By Roxanne Libatique

General insurers are navigating an expanding web of cyber obligations from multiple regulators simultaneously – and a federal consultation closing July 31 has put that tension on the public record.

The Insurance Council of Australia (ICA) lodged its submission on July 28 with the Department of Home Affairs, responding to the second tranche of proposed amendments to the Security of Critical Infrastructure Act 2018 (SOCI Act). The consultation opened July 3, 2026, and closes July 31. The reforms respond to an independent review delivered by Dr. Jill Slay AM in January 2026, with the intent to reduce complexity, enhance accountability, and modernise the legislative framework. The ICA represents members accounting for approximately 90% of gross written premium by general insurers and reinsurers, writing around 90 million policies a year and paying $58.9 billion in claims in 2025.

Incident response: reporting to everyone at once

The submission’s most operationally significant concern is what happens to an insurer actively managing a cyber incident. At that moment, members may be simultaneously required to notify the Australian Cyber Security Centre (ACSC), the Australian Prudential Regulation Authority (APRA), the Office of the Australian Information Commissioner (OAIC), the Australian Securities and Investments Commission (ASIC), law enforcement, and, in some cases, international regulators – each under different incident definitions, timeframes, and information requirements.

According to the ICA, “the burden is heightened during incident response, when entities must also manage parallel government and prudential information requests and investigative processes, sometimes across multiple jurisdictions.” The scale of the problem is growing. In FY2024-25, the ACSC responded to over 1,200 cyber security incidents, an 11% increase from the prior year. The average cost of a cybercrime report for businesses rose 50% to $80,850, while large businesses experienced a 219% rise in losses.

The exemptions question

The financial services sector has largely been exempt from certain SOCI obligations, including Critical Infrastructure Risk Management Program (CIRMP) requirements, on the basis that comparable obligations already exist under APRA’s prudential framework – principally CPS 234 and CPS 230. CPS 230, which came into force on July 1, 2025, brought a more structured approach to managing operational risk, business continuity, and service provider arrangements across all APRA-regulated entities.

The ICA supports preserving these exemptions but draws a firm line: relief should apply only where a genuine legislative or regulatory equivalent exists – not where an entity merely holds industry certifications or adopts voluntary standards. If existing exemptions were revoked rather than preserved or grandfathered, insurers currently relying on their APRA frameworks to satisfy SOCI obligations would need to establish separate CIRMP programs outside those frameworks – duplicating governance and reporting structures that already exist under prudential regulation. The ICA has asked the government to clarify which outcome the proposed framework intends.

Cloud dependency and concentration risk

APRA has flagged that many institutions rely on the same providers, making the financial system vulnerable to a single point of failure, and that third parties can be used as a backdoor to execute a cyberattack. Under CPS 230’s material service provider data collection, some of the largest entities APRA supervises have around 150 material service providers on average supporting their critical operations. The ICA supports Measure 8’s proposed extension of SOCI obligations to data hosts, arguing it is more efficient than relying on individual entities to notify third parties of their own SOCI status. The submission also calls for reforms to enable responsible entities to request continuous monitoring reports and real-time testing results from suppliers, rather than relying on annual compliance snapshots.

AI: a definitional gap with commercial consequences

The ICA has asked government to clarify whether AI model failure or manipulation constitutes a “cyber security incident” under the SOCI Act, requesting examples or case studies to establish whether the ambiguity lies in the definition itself or its interpretation. The question arrives as two of Australia’s key financial regulators have made AI governance a present-day enforcement priority. In an April 30, 2026, letter to all APRA-regulated entities, APRA warned that governance, risk management, assurance, and operational resilience practices are not keeping pace with the scale, speed, and complexity of AI adoption. APRA also warned that frontier AI models are expected to further increase the probability, speed, and scale of cyberattacks.

ASIC followed on May 8 with its own open letter to all Australian financial services licence (AFSL) holders – a category that includes insurers. ASIC told licensees and directors that frontier AI models are accelerating both capability and accessibility, lowering the barrier to sophisticated cyber activity, increasing the speed and scale of attacks, and enabling new forms of exploitation that were previously out of reach for most actors. ASIC commissioner Simone Constant emphasised that cyber resilience must be treated as a core licensing obligation, not simply an IT issue.

The ASIC letter arrived within a fortnight of a $2.5 million enforcement outcome against FIIG Securities for cyber security failures under general AFSL obligations – a signal that regulators are prepared to act under existing frameworks without waiting for new ones. For insurers, the combined effect is a regulatory environment where AI-related failures may trigger obligations under the SOCI Act, CPS 230, AFSL licensing conditions, and privacy law – simultaneously, and under definitions that do not yet align.

Enforcement safeguards and the limits of candour

On Measure 15, the ICA raises a concern about proposals to allow annual CIRMP compliance reports to be used as enforcement evidence. Under the current framework, admissibility restrictions allow boards to submit frank assessments of CIRMP effectiveness – including incidents and identified deficiencies – without those reports becoming evidence in civil penalty proceedings. That protection is not incidental: it is what makes genuinely candid board-level reporting possible.

If the safeguard is removed too broadly, the practical consequence is not better compliance – it is more guarded reporting. A board that knows its frank self-assessment of a deficiency could be used against it in a civil penalty proceeding has reason to moderate what it discloses. That outcome would undermine the regulatory purpose the reform is intended to serve. The ICA’s position is that any removal of the protection should be limited to serious or repeated non-compliance, or where a report is materially false, misleading, or incomplete – preserving the incentive for honest disclosure in all other cases.

The enhanced CIRMP Rules took effect June 10, 2026, as part of the first tranche of SOCI Act reforms. The second tranche remains subject to consultation until July 31, with legislative timing yet to be confirmed.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!