Australia Cybersecurity and Technology
Our security posture measured against the frameworks Australian buyers actually ask about — the Essential Eight, the ISM, the SOCI Act — and the reporting obligations that come with them.
1. The framework
- Privacy Act 1988 (Cth), APP 11 — take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure; and destroy or de-identify it when no longer needed.
- Notifiable Data Breaches scheme, Part IIIC — assessment and notification, dealt with at Australia Privacy and Data Protection s.7.
- ACSC Essential Eight — the Australian Signals Directorate's baseline mitigation strategies, with maturity levels 0 to 3.
- Information Security Manual (ISM) — the ASD's controls catalogue, applied where we supply government.
- Security of Critical Infrastructure Act 2018 (Cth) — obligations attaching to responsible entities for critical infrastructure assets, and the mandatory cyber incident reporting regime.
- Cyber Security Act 2024 (Cth) — including the ransomware payment reporting obligation and the limited-use protections for information given to the National Cyber Security Coordinator.
- Telecommunications Act 1997, Part 14 — security obligations where a deployment touches a carrier or carriage service provider network.
2. Essential Eight posture
| Mitigation strategy | Our implementation | Target maturity |
|---|---|---|
| Application control | Allow-listing on production and edge compute; signed binaries only | [ML] |
| Patch applications | Continuous dependency scanning; critical patches within 48 hours of vendor release for internet-facing systems | [ML] |
| Configure Microsoft Office macro settings | Not applicable to the platform; enforced on the corporate estate | [ML] |
| User application hardening | Browser hardening on the corporate estate; no Flash, Java or unsigned plugins | [ML] |
| Restrict administrative privileges | Just-in-time, time-bounded, approved elevation; quarterly recertification; no standing production admin | [ML] |
| Patch operating systems | Automated patching with 48-hour critical SLA on internet-facing hosts; signed OTA for edge devices | [ML] |
| Multi-factor authentication | Mandatory on every administrative, search-privileged and engineering account. Cannot be disabled | [ML] |
| Regular backups | Encrypted, access-controlled, restore-tested at least annually, retained per the Data Retention Schedule | [ML] |
Assessed maturity levels are published and dated at Compliance and Security Updates. We publish the assessed level, including where it is below target, rather than a claim of "Essential Eight aligned" that carries no information.
3. Controls
The technical controls are common to both jurisdictions and are described in detail at India Cybersecurity and Technology, sections 4 and 5 — identity and access, encryption in transit and at rest, separate encrypted storage and independent keying for biometric templates, tenant and control-plane segregation, append-only audit logging with anomaly detection, signed firmware and verified boot at the edge, secure development lifecycle, annual third-party penetration testing, and personnel vetting and training.
Australian-specific additions:
- Data residency. Customer Data from Australian deployments is hosted in an Australian region by default. Where an agency requires it, we will contract to keep specified data classes onshore for their full lifecycle including backup.
- Personnel. Where a contract requires it, personnel with access to a customer's environment hold the security clearance level the agency specifies. Clearance-holding staff are named to the agency.
- ISM mapping. On request we provide a control mapping to the ISM at the required classification, with any control we do not meet listed rather than omitted.
- IRAP. Current IRAP assessment status is stated at Compliance and Security Updates. Where an assessment has not been completed we say so.
4. Incident reporting obligations
| Trigger | Report to | Deadline |
|---|---|---|
| Eligible data breach | OAIC and affected individuals | As soon as practicable after assessment; assessment within 30 days |
| Critical cyber security incident with significant impact on a critical infrastructure asset (SOCI s.30BC) | Australian Signals Directorate | 12 hours of becoming aware |
| Other cyber security incident with relevant impact (SOCI s.30BD) | Australian Signals Directorate | 72 hours of becoming aware |
| Ransomware or cyber extortion payment (Cyber Security Act 2024) | Department of Home Affairs / ASD | 72 hours of payment or of becoming aware a payment was made |
| Any reportable incident affecting our systems | CERT-In (India) | 6 hours — see India Cybersecurity and Technology |
| Incident affecting Customer Data | The affected customer | 72 hours, without undue delay |
These clocks run concurrently. The shortest one governs our first action, and no other obligation is deferred because an earlier report is still being prepared.
5. Critical infrastructure
Where a customer is a responsible entity for a critical infrastructure asset under the SOCI Act — in sectors including energy, transport, water, health, communications, financial services, defence industry and data storage or processing — DECTIFY may form part of that asset's supply chain.
In that case we will, on the customer's request and where recorded on the Order Form:
- Support the customer's Critical Infrastructure Risk Management Program, including the supply chain hazard vector.
- Provide the information the customer needs for the Register of Critical Infrastructure Assets.
- Report incidents to the customer within the timeframes that let it meet its own 12-hour and 72-hour obligations — in practice, immediately on classification.
- Cooperate with a government assistance measure or an information-gathering direction under Part 3A of the Act.
- Accept enhanced obligations where the asset is declared a System of National Significance.
DECTIFY is not itself currently a responsible entity for a declared critical infrastructure asset. If that changes we will publish it at Compliance and Security Updates.
6. Certification and assurance
Current status of ISO/IEC 27001, SOC 2, IRAP assessment and Essential Eight maturity assessment is published and dated at Compliance and Security Updates. Reports are available to customers and prospective customers under NDA. We distinguish clearly between certified, assessed, and aligned, and we do not use the third word to imply either of the first two.
7. Supply chain
Sub-processors are listed at Sub-processors and bound by Vendor Terms, which flow down incident notification fast enough to let us meet the 12-hour SOCI clock. Third-party and open source components are at Third-Party Terms.
8. Reporting something to us
Security issues: security@dectify.in. Researchers should read Vulnerability Disclosure Policy first — it sets out the safe harbour and its scope.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India