Skip to main content
Home Legal
Australia Cybersecurity and Technology

Australia Cybersecurity and Technology

Version 1.0 · Effective 22 August 2026

Our security posture measured against the frameworks Australian buyers actually ask about — the Essential Eight, the ISM, the SOCI Act — and the reporting obligations that come with them.

Global Essential Eight SOCI Act 2018 ACSC Cyber Security Act 2024

1. The framework

  • Privacy Act 1988 (Cth), APP 11 — take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure; and destroy or de-identify it when no longer needed.
  • Notifiable Data Breaches scheme, Part IIIC — assessment and notification, dealt with at Australia Privacy and Data Protection s.7.
  • ACSC Essential Eight — the Australian Signals Directorate's baseline mitigation strategies, with maturity levels 0 to 3.
  • Information Security Manual (ISM) — the ASD's controls catalogue, applied where we supply government.
  • Security of Critical Infrastructure Act 2018 (Cth) — obligations attaching to responsible entities for critical infrastructure assets, and the mandatory cyber incident reporting regime.
  • Cyber Security Act 2024 (Cth) — including the ransomware payment reporting obligation and the limited-use protections for information given to the National Cyber Security Coordinator.
  • Telecommunications Act 1997, Part 14 — security obligations where a deployment touches a carrier or carriage service provider network.

2. Essential Eight posture

Mitigation strategyOur implementationTarget maturity
Application controlAllow-listing on production and edge compute; signed binaries only[ML]
Patch applicationsContinuous dependency scanning; critical patches within 48 hours of vendor release for internet-facing systems[ML]
Configure Microsoft Office macro settingsNot applicable to the platform; enforced on the corporate estate[ML]
User application hardeningBrowser hardening on the corporate estate; no Flash, Java or unsigned plugins[ML]
Restrict administrative privilegesJust-in-time, time-bounded, approved elevation; quarterly recertification; no standing production admin[ML]
Patch operating systemsAutomated patching with 48-hour critical SLA on internet-facing hosts; signed OTA for edge devices[ML]
Multi-factor authenticationMandatory on every administrative, search-privileged and engineering account. Cannot be disabled[ML]
Regular backupsEncrypted, access-controlled, restore-tested at least annually, retained per the Data Retention Schedule[ML]

Assessed maturity levels are published and dated at Compliance and Security Updates. We publish the assessed level, including where it is below target, rather than a claim of "Essential Eight aligned" that carries no information.

3. Controls

The technical controls are common to both jurisdictions and are described in detail at India Cybersecurity and Technology, sections 4 and 5 — identity and access, encryption in transit and at rest, separate encrypted storage and independent keying for biometric templates, tenant and control-plane segregation, append-only audit logging with anomaly detection, signed firmware and verified boot at the edge, secure development lifecycle, annual third-party penetration testing, and personnel vetting and training.

Australian-specific additions:

  • Data residency. Customer Data from Australian deployments is hosted in an Australian region by default. Where an agency requires it, we will contract to keep specified data classes onshore for their full lifecycle including backup.
  • Personnel. Where a contract requires it, personnel with access to a customer's environment hold the security clearance level the agency specifies. Clearance-holding staff are named to the agency.
  • ISM mapping. On request we provide a control mapping to the ISM at the required classification, with any control we do not meet listed rather than omitted.
  • IRAP. Current IRAP assessment status is stated at Compliance and Security Updates. Where an assessment has not been completed we say so.

4. Incident reporting obligations

TriggerReport toDeadline
Eligible data breachOAIC and affected individualsAs soon as practicable after assessment; assessment within 30 days
Critical cyber security incident with significant impact on a critical infrastructure asset (SOCI s.30BC)Australian Signals Directorate12 hours of becoming aware
Other cyber security incident with relevant impact (SOCI s.30BD)Australian Signals Directorate72 hours of becoming aware
Ransomware or cyber extortion payment (Cyber Security Act 2024)Department of Home Affairs / ASD72 hours of payment or of becoming aware a payment was made
Any reportable incident affecting our systemsCERT-In (India)6 hours — see India Cybersecurity and Technology
Incident affecting Customer DataThe affected customer72 hours, without undue delay

These clocks run concurrently. The shortest one governs our first action, and no other obligation is deferred because an earlier report is still being prepared.

5. Critical infrastructure

Where a customer is a responsible entity for a critical infrastructure asset under the SOCI Act — in sectors including energy, transport, water, health, communications, financial services, defence industry and data storage or processing — DECTIFY may form part of that asset's supply chain.

In that case we will, on the customer's request and where recorded on the Order Form:

  • Support the customer's Critical Infrastructure Risk Management Program, including the supply chain hazard vector.
  • Provide the information the customer needs for the Register of Critical Infrastructure Assets.
  • Report incidents to the customer within the timeframes that let it meet its own 12-hour and 72-hour obligations — in practice, immediately on classification.
  • Cooperate with a government assistance measure or an information-gathering direction under Part 3A of the Act.
  • Accept enhanced obligations where the asset is declared a System of National Significance.

DECTIFY is not itself currently a responsible entity for a declared critical infrastructure asset. If that changes we will publish it at Compliance and Security Updates.

6. Certification and assurance

Current status of ISO/IEC 27001, SOC 2, IRAP assessment and Essential Eight maturity assessment is published and dated at Compliance and Security Updates. Reports are available to customers and prospective customers under NDA. We distinguish clearly between certified, assessed, and aligned, and we do not use the third word to imply either of the first two.

7. Supply chain

Sub-processors are listed at Sub-processors and bound by Vendor Terms, which flow down incident notification fast enough to let us meet the 12-hour SOCI clock. Third-party and open source components are at Third-Party Terms.

8. Reporting something to us

Security issues: security@dectify.in. Researchers should read Vulnerability Disclosure Policy first — it sets out the safe harbour and its scope.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India