AICD submission on Parliamentary inquiry into cyber security

Thursday, 03 September 2026

    Current

    On 28 August 2026, the AICD made a submission to the Parliamentary Select Committee inquiry into cyber security for small to medium sized businesses and organisations (SMBs) and not-for-profit organisations (NFPs).

    On 28 August 2026, the AICD made a submission to the Parliamentary Select Committee inquiry into cyber security for small to medium sized businesses and organisations (SMBs) and not-for-profit organisations (NFPs).

    In our submission, the AICD recognised the significant work already underway through the Australian Cyber Security Strategy, and emphasised the need for practical, risk-based measures that help smaller organisations improve their cyber resilience.

    The AICD's key points were:

    • Accessible and consolidated guidance: We strongly supported the Government's proposed CyberSmart Hub as a central source of practical cyber security guidance for SMBs and NFPs. We recommended that guidance should clearly distinguish between legal obligations, baseline good practice and measures appropriate for higher-risk organisations.
    • CyberSmart program and tailored standards: We supported the development of the CyberSmart program, including a tailored cyber security standard and certification regime for smaller organisations. We emphasised that any standard should be practical, proportionate, affordable and aligned with existing frameworks to avoid unnecessary complexity.
    • Role of technology service providers: We encouraged the Committee to consider the role of managed service providers, managed security service providers and software as a service vendors that support SMBs and NFPs. We suggested exploring standards and certification for these providers to help improve baseline cyber security protections for smaller organisations.
    • Training and awareness: We supported additional cyber security education and awareness initiatives, including targeted training for directors and managers. We recommended that training be practical, sector-specific and supported by a well-resourced awareness campaign.
    • Supply chain participation: We acknowledged the potential value of a CyberSmart certification in helping SMBs and NFPs participate in Government and large corporate supply chains. However, we stressed that certification should be implemented proportionately and accompanied by appropriate support and transition arrangements.
    • Cyber insurance: We highlighted that cyber insurance can be an important component of an organisation's cyber resilience framework, and may encourage stronger security practices. However, affordability, exclusions and minimum-security requirements continue to limit access to insurance for many SMBs and NFPs.
    • No further broad-based regulation: We did not support imposing additional general cyber security or data governance regulation on SMBs and NFPs. In particular, we stated our opposition to removing the small business exemption in the Privacy Act 1988. We consider that education, practical guidance, standards and capability-building measures are more likely to improve the cyber resilience of SMBs and NFPs than additional compliance obligations.

    The AICD looks forward to the findings of the Committee, which are to be presented in a final report by 31 March 2027.

    Latest news

    This is of of your complimentary pieces of content

    This is exclusive content.

    You have reached your limit for guest contents. The content you are trying to access is exclusive for AICD members. Please become a member for unlimited access.