Loading

Maritime

​Cyber incident affecting a maritime asset

You must report a cyber security incident to both the Australian Cyber Security Centre (ACSC) and the Department of Home Affairs.

You can report the incident on the ACSC website. There, you can give consent to share your report with Home Affairs. If you do not give consent, you must submit a separate maritime security incident report form. You must select the ‘Cyber’ incident category.

Report a maritime security incident​

You must report any maritime security incident to the department under Part 9 of the Maritime Transport and Offshore Facilities Security Act 2003.

Maritime industry participants must report incidents as soon as possible, and within 24 hours of first becoming aware of them.

Reports must be in writing. The easiest way is to complete the Maritime Security Incident Report Form​. This form includes all required information.

You may make an initial report by calling 1300 791 581. However, a written report must be submitted within 24 hours.

Alternatively, reports can be submitted by email to transport.security@homeaffairs.gov.au.

What the report must include

Your report should include as much detail as you know at the time.

If you learn more required information later, you must provide it in writing as soon as possible.

All reporting requirements are set out in the Maritime Transport and Offshore Facilities Security (Incident Reporting) Instrument 2026.

If your report does not include all required information, the law treats it as not reported under subsection 182(3) of the Maritime Transport and Offshore Facilities Security Act 2003.

Just culture approach

We use a ‘just culture’ approach to encourage reporting. This generally means no enforcement action will be taken if:

  • you voluntarily self-report the incident
  • you confirm you’ve taken steps to prevent it happening again (if asked)
  • the incident was not caused by reckless behaviour.

For more information, see the Industry Guidance.