eFlash #459

eFlash #459

eFlash #459
Date: 13-Nov-2020

In this edition:  Exposure Draft of the Security Legislation Amendment (Critical Infrastructure) Bill 2020

1. Exposure Draft of the Security Legislation Amendment (Critical Infrastructure) Bill 2020

On Monday we received notification that the Department of Home Affairs had released this draft legislation, available for review here. The Department is “seeking views” on the document by 27 November.

This represents another ridiculous deadline for a Bill which includes a number of concerning elements and unanswered questions.

The Water Services Sector Group and Water Services Association of Australia coordinated a joint industry submission in September to the last consultation round which included the Queensland, NSW and Victorian Water Directorates. The submission included a number of considered arguments around the classification of organisations which should be captured under the revised Act, how risks should be managed, the importance of state and federal coordination to reduce regulatory burden leading to additional costs and so on.

The WSSG and WSAA convened a videoconference for the water industry yesterday which reiterated that several of the concerns had not been addressed in the exposure draft, and the documents raised new ones. These groups will again be coordinating a sector response and qldwater will be participating.

How Queensland water service providers are likely to be impacted is difficult to say. If adopted, the new provisions will impact all to an extent around potential intervention during cybersecurity events. The organisations which should be watching this carefully are likely:

  • Water utilities under the 100,000 customer connections (i.e. most in Queensland) that will still be subject to the governments step in powers in support of managing a cyber event if the utility was impacted.
  • Utilities with >100,000 connections (already captured under federal legislation and likely to be impacted by new provisions)
  • Water utilities with critical customers – e.g. power stations, ports, defence bases that could be deemed a “System of National Significance” due to their provision of services for other Critical Infrastructure entities. These would be declared by the Minister an bring an extensive list of new regulatory requirements and powers of intervention in the cyber security space.

A number of “town hall” meetings have been scheduled by Home Affairs and WSSG/ WSAA are attempting to organise a water industry-specific session next week. Details will be circulated when available.

qldwater is a business unit of IPWEAQ 

Back to list