INCIDENT RESPONSE · 12 MIN

A Cyber Incident Response Plan Template Australian Regulators Actually Want

The plan you hand to the auditor is rarely the plan you run during an incident. This is the structure CISOs use to make sure both versions hold up.

Run your first mission free

The seven mandatory sections

  1. Purpose and scope — what the plan covers, what it does not.
  2. Severity rubric — objective triggers, not vibes.
  3. CIRT roles and deputies — every named role has a named backup.
  4. Activation runbook — who calls it, how, and what happens in the first 60 minutes.
  5. Regulator notification matrix — NDB (OAIC), APRA CPS 234, SOCI Act, ASIC, state regulators.
  6. Communications plan — internal, customer, media, board, holding statements.
  7. Post-incident review — blameless review and improvement actions logged.

Severity rubric

Severity levels

  • SEV-1 Critical. Material business impact, regulator clock running, board notified within 4 hours.
  • SEV-2 High. Significant service or data impact, exec leadership engaged, regulator likely within 24 hours.
  • SEV-3 Moderate. Contained operational impact, IT leadership engaged, regulator unlikely.
  • SEV-4 Low. Single-user or contained, handled by service desk under standard playbook.

Australian regulator clocks

  • OAIC (NDB) — assess within 30 days; notify as soon as practicable once an eligible breach is confirmed.
  • APRA CPS 234 — notify within 72 hours of becoming aware of a material information security incident.
  • SOCI Act — 12 hours for critical impact, 72 hours for other impact, to ASD.
  • ASIC continuous disclosure — for listed entities where the incident is materially price-sensitive.

Treat these as parallel, not sequential. A single major incident commonly triggers three or four obligations on different clocks.

FOR CIRT LEADS

Generate a one-page incident response runbook tonight.

FORTE/CYBERx produces a CIRT-ready runbook — first 60 minutes, RACI, regulator notification drafts and comms templates — anchored to NDB, CPS 234 and SOCI obligations.

Start a free mission

The first 60 minutes

Most plans fall apart in the first hour because no-one knows the activation phone tree or who has the authority to invoke the CIRT. The fix is boring: a single laminated wallet card with three numbers, the activation script and the first three decisions the duty exec needs to take. Test it quarterly.

What good post-incident review looks like

  • Timeline reconstructed from logs, not memory
  • Decision points labelled with who decided, what they considered, what they chose
  • Five whys for at least one root cause
  • Improvement actions with owners and due dates, tracked to closure
  • Report to the board within 30 days for SEV-1, 90 days for SEV-2

FAQ

What must an Australian incident response plan contain?

At minimum: a severity rubric, CIRT roles with deputies, an activation runbook, a regulator-notification matrix covering NDB / CPS 234 / SOCI, a comms plan and a post-incident review process. The plan must be tested at least annually — most Australian regulators now expect this in writing.

How often should we test the plan?

At least once a year for a full tabletop, with quarterly functional drills for high-risk scenarios (ransomware, supplier compromise, insider). APRA-regulated entities should treat semi-annual as the floor.

Who chairs the CIRT?

A named executive (usually the CISO or CIO) with a documented deputy. The legal owner of regulator notification is typically the General Counsel or Privacy Officer; the CIRT chair owns operational tempo.

Should the plan be public?

No. The plan often contains sensitive contact trees, escalation thresholds and vendor contracts. Maintain a sanitised summary for customers and insurers and the full plan on access-controlled storage.

Related

Generate the plan you wish you had last Tuesday.

Two free missions. No credit card. CIRT-ready in 60 seconds.