Pending approval — not yet published
This document is in the review and approval workflow and is not yet available to staff. It will appear in the WMS library once it has been approved.
← Back to Document LibraryCyber Incident Response Procedure
Contents & downloads
Nomenclature
| Term | Definition |
|---|---|
| ACSC | Australian Cyber Security Centre — the operational arm of the Australian Signals Directorate (ASD). |
| APP | Australian Privacy Principles — the principles set out in Schedule 1 of the Privacy Act 1988 (Cth) governing the handling of personal information. |
| ASD | Australian Signals Directorate — the Commonwealth agency receiving ransomware payment reports under the Cyber Security Act 2024 (Cth) Part 3 and operating the ReportCyber portal. |
| BEC | Business Email Compromise — an attack in which a threat actor impersonates a legitimate party to fraudulently induce a payment, fund transfer or data disclosure. |
| CISO | Chief Information Security Officer — at Westlink, this role is performed by the Security Officer (QHSE Manager) reporting to the CEO. |
| Containment | Action taken to limit the scope, severity or duration of a cyber security incident before eradication is possible. |
| CSA | Cyber Security Act 2024 (Cth) — the Commonwealth Act under which ransomware payment reporting (Part 3) and limited use protections operate. |
| Cyber Security Incident | An occurrence that actually or potentially jeopardises the confidentiality, integrity or availability of an information asset, ICT system, or the information processed, stored or transmitted by it. |
| DISP | Defence Industry Security Program — administered by the Defence Industry Security Office; governs security obligations for industry entities handling Defence information. |
| DISO | Defence Industry Security Office — the Defence body to which DISP members report security incidents involving Defence classified or controlled information. |
| Eligible Data Breach | A data breach that meets the threshold for notification under the Privacy Act 1988 (Cth) Part IIIC — unauthorised access, disclosure or loss of personal information likely to result in serious harm and where serious harm has not been prevented by remedial action. |
| Eradication | Removal of the components of a cyber security incident (e.g. malware, attacker accounts, unauthorised changes) from affected systems. |
| E8 | Essential Eight — the ACSC’s prioritised mitigation strategies. Westlink targets Maturity Level 2 (ML2) per TEC-POL-001. |
| ICT | Information and Communications Technology. |
| Indicator of Compromise (IoC) | Forensic artefact (file hash, IP address, domain, registry key, behaviour pattern) suggesting that a system or network has been compromised. |
| ISM | Australian Government Information Security Manual — published by the Australian Signals Directorate as the authoritative cyber security framework for Australian Government and DISP entities. |
| JOSCAR | Joint Supply Chain Accreditation Register — the pre-qualification scheme operated by Hellios for defence, aerospace and security supply chains. |
| MSP | Managed Service Provider — at Westlink, Becloudsmart provides M365 tenant security operations and Tier-2 incident support. |
| NDB | Notifiable Data Breach — the scheme under the Privacy Act 1988 (Cth) Part IIIC requiring notification of eligible data breaches to affected individuals and the Office of the Australian Information Commissioner. |
| NIST IR | United States National Institute of Standards and Technology — Incident Response framework (SP 800-61 r2). The lifecycle (Prepare → Detect & Analyse → Contain → Eradicate → Recover → Lessons Learned) is industry standard and underpins this procedure. |
| OAIC | Office of the Australian Information Commissioner — the regulator administering the Privacy Act 1988 (Cth) and the NDB scheme. |
| OSINT | Open-source intelligence — publicly available information used to identify, characterise or attribute cyber threats. |
| Personal Information | Information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in s.6 of the Privacy Act 1988 (Cth). |
| PSPF | Protective Security Policy Framework — administered by the Department of Home Affairs; governs protective security obligations applicable to Australian Government entities and (via DISP) industry entities handling Defence information. |
| Ransomware | Malicious software that denies access to data, systems or services, typically by encryption, with the demand of a payment (ransom) for restoration. Includes data-theft extortion (without encryption) under CSA Part 3 reporting scope. |
| ReportCyber | The ACSC online portal at cyber.gov.au/report — used for general cyber security incident reports and for mandatory ransomware payment reports under the Cyber Security Act 2024 (Cth) Part 3. |
| Security Officer | At Westlink, the QHSE Manager performs the Security Officer role per the DISP member declaration and TEC-POL-001. Responsibilities include day-to-day information security management, incident response coordination, DISP reporting and security clearance administration. |
| Threat Actor | An individual or group that conducts, supports or sponsors actions targeting information systems or data. |
Purpose
This procedure sets out the process Westlink Logistics applies to detect, classify, respond to, report and recover from cyber security incidents. It operationalises TEC-POL-001 Information Security Policy and the security incident commitments contained in QHSE-POL-001 Chain of Responsibility, GOV-POL-015 Privacy Policy and GOV-POL-001 Quality Policy.
The procedure addresses the statutory and contractual obligations that apply to Westlink as a DISP entity, a JOSCAR-registered supplier to the Australian defence sector, and a reporting business entity under the Cyber Security Act 2024 (Cth) Part 3.
Scope
This procedure applies to all Westlink directors, officers, workers, contractors, subcontractors, consultants, and third parties who access, process, store or transmit information on behalf of Westlink Logistics.
It covers cyber security incidents affecting any Westlink information asset, including:
-
Westlink’s Microsoft 365 tenant (Entra ID, Exchange Online, SharePoint Online, OneDrive for Business, Teams, Intune-managed endpoints);
-
Cloud services contracted by Westlink (including services provided through the managed service provider, Becloudsmart);
-
Endpoint devices owned, leased or managed by Westlink, including BYOD endpoints enrolled for conditional access;
-
Information held by third-party providers under Westlink contracts (logistics platforms, payroll, finance, JOSCAR portal credentials);
-
Defence classified or controlled information handled under DISP up to the OFFICIAL:Sensitive ceiling; and
-
Personal information protected under the Privacy Act 1988 (Cth).
This procedure complements QHSE-PRO-001 Hazard and Incident Reporting and Investigation Procedure (which covers WHS, environmental and quality incidents) and refers to QHSE-PRO-001 for the general incident-investigation methodology where a cyber incident also has a WHS or environmental dimension.
Responsibilities
CEO
The Chief Executive Officer is responsible for:
-
Approving classification of cyber security incidents at Severity 1 (Critical) and authorising public communications;
-
Making the decision to pay or not pay a ransom or extortion demand, and where payment occurs, ensuring the Security Officer reports the payment to the Australian Signals Directorate within 72 hours per Cyber Security Act 2024 (Cth) Part 3;
-
Authorising external regulator notifications (OAIC, DISO, sector regulators) where the Security Officer has assessed the incident as meeting a notification threshold;
-
Receiving the post-incident report and approving lessons-learned actions; and
-
Convening the Incident Response Team for Severity 1 (Critical) and Severity 2 (Major) incidents.
Security Officer (QHSE Manager)
The Security Officer is responsible for:
-
Acting as the single point of accountability for cyber incident response coordination during an active incident;
-
Assessing reported events to determine whether they constitute a cyber security incident and classifying the severity per the matrix in §6;
-
Activating the response lifecycle in §7 and confirming containment, eradication and recovery milestones;
-
Determining whether external notification thresholds are met (CSA Part 3, OAIC NDB, DISP) per §8;
-
Lodging the ReportCyber notification for general cyber security incidents and mandatory ransomware payment reports;
-
Coordinating with the Privacy Officer on Notifiable Data Breach assessment and OAIC notification under Privacy Act 1988 (Cth) Part IIIC;
-
Notifying the Defence Industry Security Office for any incident affecting Defence classified information per DISP requirements;
-
Maintaining the Cyber Incident Register and ensuring records are retained per §11;
-
Reporting cyber incident metrics to the Management Review meeting at least annually; and
-
Updating the JOSCAR-AU questionnaire response on Q2.11.12 (incident management) and Q2.11.5.4 (security roles) at the next review where the incident materially affects the response capability.
Managed Service Provider (Becloudsmart)
The MSP, under its services contract with Westlink, is responsible for:
-
Operating tenant-level security monitoring and forwarding actionable alerts to the Security Officer;
-
Providing Tier-2 cyber incident response support including forensic preservation, log retrieval, account containment, and tenant-level eradication actions on direction from the Security Officer;
-
Preserving evidence (sign-in logs, audit logs, mailbox content, endpoint telemetry) for the period required to support investigation and any regulator notification;
-
Co-ordinating with Microsoft and other cloud vendors on incidents originating in tenant or vendor-side controls;
-
Implementing eradication and recovery actions directed by the Security Officer within agreed Service Level commitments; and
-
Participating in the post-incident review and capturing technical lessons-learned actions in the MSP service improvement register.
Privacy Officer
The Privacy Officer (currently the QHSE Manager — same individual as the Security Officer; role described separately for clarity) is responsible for:
-
Receiving notifications of suspected eligible data breaches from the Security Officer or any worker;
-
Completing the Privacy Act 1988 (Cth) Part IIIC eligible-data-breach assessment within 30 days of becoming aware of the suspected breach;
-
Where an eligible data breach is confirmed, preparing the statement required by s.26WK of the Privacy Act and notifying the OAIC and affected individuals as soon as practicable;
-
Maintaining the Notifiable Data Breach record per the Privacy Act 1988 (Cth); and
-
Coordinating with the OAIC on any subsequent regulator inquiries.
Workers, Contractors and Visitors
All workers, contractors and visitors are responsible for:
-
Reporting any suspected cyber security incident immediately to their supervisor and to the Security Officer using the channels listed in §5.1;
-
Not attempting to remediate, investigate or analyse a suspected incident outside the direction of the Security Officer (preserving evidence is essential);
-
Cooperating fully with the Incident Response Team during containment, eradication and recovery; and
-
Completing cyber security awareness training annually and on commencement.
Cyber Incident Definitions and Categories
A cyber security incident is any occurrence that actually or potentially jeopardises the confidentiality, integrity or availability of a Westlink information asset, ICT system, or the information processed, stored or transmitted by it. A cyber security event is an observed occurrence that may indicate a possible incident — events that meet the criteria in §6 become incidents.
| Category | Description | Typical Indicators |
|---|---|---|
| Malware / Ransomware | Malicious software installed on a Westlink endpoint, server or cloud workload. Includes ransomware (encryption + extortion) and information-theft malware. | Endpoint protection alert; encrypted file extensions; ransom note; outbound C2 traffic; sudden mass file modification. |
| Business Email Compromise (BEC) | Threat actor impersonates a Westlink officer, supplier or customer to induce fraudulent payment, fund transfer or data disclosure. | Spoofed display name; mailbox rule auto-forwarding to external; impossible-travel sign-in; unusual reply-to. |
| Phishing / Credential Theft | Worker presented with a credential capture page or attachment-based credential theft attempt; possibly successful. | Reported by worker; impossible-travel sign-in; MFA fatigue prompts; unauthorised mailbox access. |
| Account Compromise | Unauthorised access to a Westlink account (Entra ID, M365, third-party SaaS, JOSCAR portal). | Sign-in from unusual location; new MFA method registered; mailbox rule added; conditional access bypass. |
| Data Breach / Disclosure | Personal, OFFICIAL:Sensitive, or commercial-in-confidence information accessed, disclosed, modified or destroyed without authorisation. | Worker report of mis-sent email; cloud storage shared externally; lost or stolen device with corporate data. |
| Insider Threat | Westlink worker or contractor accesses, exfiltrates or misuses information outside legitimate authorisation. | Unusual download volume; access to records outside role; departure-window data access. |
| Denial of Service | Disruption of access to a Westlink service or system due to malicious activity. | Service unavailability concurrent with traffic anomaly; vendor notification. |
| Physical-Cyber Convergence | Loss, theft or unauthorised physical access to a Westlink endpoint, removable media or paper-based OFFICIAL:Sensitive information. | Lost laptop or phone; stolen USB drive; unattended printed material. |
| Supply-Chain / Third-Party | Compromise of a Westlink supplier, vendor or customer whose access or data flows touch Westlink systems or information. | Vendor breach notification; downstream credential reuse; vendor-distributed malware. |
| Other | Any other event meeting the cyber security incident definition that does not fit the above categories. | Assessed case-by-case by the Security Officer. |
Detection and Reporting
Reporting Channels
Any suspected cyber security incident or event must be reported immediately, regardless of suspected severity or confidence level. Reporting channels (in order of preference) are:
-
Telephone the Security Officer directly (preferred for urgent or high-confidence incidents);
-
Email security@westlinklogistics.com — monitored by the Security Officer during business hours;
-
Microsoft Teams direct message to the Security Officer;
-
Escalate to the CEO directly where the Security Officer is unavailable or the suspected incident involves the Security Officer; and
-
Outside business hours, use the after-hours number listed in the staff handbook and contact the MSP duty technician for tenant-level emergency response.
Workers must NOT attempt to investigate, contain or remediate the incident on their own initiative — preservation of evidence and avoidance of inadvertent secondary impact require coordinated response. The Security Officer directs all response activity.
Detection Sources
Cyber security incidents are detected through multiple sources, each of which feeds the Security Officer for assessment:
-
Worker reports per the channels above (the most common detection source);
-
Microsoft Defender for Endpoint and Microsoft Defender for Office 365 alerts forwarded by the MSP;
-
Microsoft Entra ID risky sign-in and identity protection alerts;
-
Microsoft Purview audit log and data loss prevention alerts;
-
MSP tenant security operations alerts and weekly security posture reports;
-
ACSC Partnership Program notifications and threat intelligence advisories;
-
Vendor security advisories (Microsoft, software vendors, JOSCAR portal operator, third-party SaaS providers);
-
Customer or supplier notifications of a breach affecting Westlink data; and
-
OSINT, leaked-credentials services, and breach-disclosure feeds monitored by the MSP.
Initial Triage
On receipt of a report, the Security Officer:
-
Acknowledges the report to the reporter within 1 business hour during business hours, and within 4 hours outside business hours;
-
Opens a Cyber Incident Register entry capturing reporter, date and time, source, observed indicators, and initial scope;
-
Determines whether the event constitutes a cyber security incident per §4 and, if so, classifies severity per §6;
-
Where the event does not constitute an incident, records the closure rationale and informs the reporter (but retains the event record for trend analysis);
-
Notifies the MSP and convenes the Incident Response Team if the assessed severity is 1 (Critical) or 2 (Major); and
-
Notifies the CEO if assessed severity is 1 (Critical), if a ransomware demand is involved, or if Defence classified information is in scope.
Severity Classification
The Security Officer assigns each incident a severity in the matrix below. Severity may be revised up or down as the incident scope becomes clearer; the highest severity reached is recorded in the post-incident report.
| Severity | Description | Examples | Convene Incident Response Team | CEO notification |
|---|---|---|---|---|
| 1 — Critical | Significant ongoing impact on Westlink’s ability to operate; loss of confidentiality, integrity or availability of a key system or significant volume of OFFICIAL:Sensitive or personal information; ransom or extortion demand; threat actor with active access. | Active ransomware encryption; confirmed exfiltration of OFFICIAL:Sensitive; Tier-1 vendor breach with credential reuse; large-volume eligible data breach. | Yes — within 2 hours | Immediately |
| 2 — Major | Material risk of harm to Westlink, individuals, or clients; localised loss of confidentiality, integrity or availability; suspected account compromise affecting privileged or high-value account; possible eligible data breach. | Confirmed BEC with funds at risk; single account compromise with mailbox access; lost laptop containing OFFICIAL:Sensitive information; suspected supply-chain compromise. | Yes — within 1 business day | Within 1 business day |
| 3 — Minor | Limited or contained impact; no evidence of secondary impact; standard remediation suffices. | Phishing attempt blocked by mail filtering; single endpoint malware quarantined by EDR with no spread; isolated mis-sent email containing low-sensitivity information. | No — Security Officer leads response | Weekly summary |
| 4 — Event / False Positive | Reported event that on assessment does not constitute a cyber security incident. | Routine spam; phishing simulation; benign vendor activity misidentified as suspicious. | No — closure recorded | Weekly summary |
Where severity is uncertain, the Security Officer assigns the higher of the candidate severities and reassesses at the next decision point. Over-classification has no operational penalty; under-classification can delay statutory notification.
Response Lifecycle
Westlink applies the NIST SP 800-61 r2 incident response lifecycle, aligned with ISO/IEC 27035:2023 and the ACSC incident response guidance: Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Post-Incident Activity.
Preparation
Preparation activities are conducted on an ongoing basis outside any active incident, and include: maintaining the Cyber Incident Register; testing detection and reporting channels; running the annual tabletop exercise per §12; maintaining contact details for the MSP, the OAIC, DISO, ASD/ACSC, the Federal Police, and key vendors; pre-staging the ReportCyber portal account; maintaining current backups tested per E8 ML2 backup controls; and confirming that worker awareness training in §12 is current.
Detection and Analysis
The Security Officer, supported by the MSP, performs the following analysis steps:
-
Confirm the incident definition is met and assign severity;
-
Identify the scope of compromise — affected accounts, endpoints, systems, data, third parties;
-
Preserve evidence — capture sign-in logs, audit logs, mailbox content, endpoint forensic images, and any ransom note or threat-actor communication before containment alters state;
-
Identify indicators of compromise and check for lateral spread or wider compromise;
-
Where Defence classified information may be in scope, isolate the affected system from further analysis pending DISO consultation; and
-
Record the analysis outcome in the Cyber Incident Register.
Containment
Containment objectives are to limit the spread, severity and duration of the incident. Containment actions are directed by the Security Officer and executed by the MSP under the services contract. Typical containment actions include:
-
Disable compromised accounts in Entra ID; revoke active sessions; reset credentials; force re-registration of MFA methods;
-
Quarantine compromised endpoints from the corporate network and from the M365 tenant via Intune compliance and Microsoft Defender for Endpoint;
-
Remove malicious mailbox rules and quarantine mail items flagged by Defender for Office 365;
-
Block external IPs, domains, and email senders associated with the incident at the M365 boundary;
-
Notify third parties whose systems or accounts may be affected, with sufficient information for them to contain on their side;
-
For ransomware: disconnect affected systems from the network but do not power off (preserves volatile evidence); and
-
Record each containment action with timestamp and operator in the Cyber Incident Register.
Short-term containment focuses on stopping the bleeding; long-term containment (e.g. rebuilding compromised systems before eradication is complete) is decided in consultation with the MSP and may overlap with eradication and recovery.
Eradication
Eradication removes the components of the incident from the environment and restores assured trust in affected systems. Eradication actions include:
-
Remove malware, attacker-installed software, and unauthorised configuration changes;
-
Identify and close the vulnerability used for initial access (patching, configuration hardening, control gap closure);
-
Rebuild compromised endpoints from known-good Intune-managed baseline images rather than relying on in-place clean-up;
-
Validate that all attacker-controlled accounts (including service principals and OAuth grants) have been removed; and
-
Confirm via re-scanning and log review that indicators of compromise are no longer present.
Recovery
Recovery returns affected systems and services to normal operation, including restoring data where loss has occurred. Recovery actions include:
-
Restore data from validated backups where loss or corruption has occurred (Essential Eight backup controls);
-
Re-enable user accounts in stages, validating MFA registration and conditional access compliance for each;
-
Monitor recovered systems with elevated logging and detection for at least 30 days to identify any persistence or recurrence;
-
Validate restoration of business processes with the operations team; and
-
Confirm with the MSP that tenant-level security controls remain effective post-recovery.
Post-Incident Activity
Within 14 calendar days of declaration of recovery, the Security Officer convenes a post-incident review with the MSP, the CEO, and any other relevant participants. The review produces a Post-Incident Report covering:
-
Incident timeline (detection → containment → eradication → recovery);
-
Root cause and contributing factors;
-
Impact assessment (operational, financial, regulatory, reputational, defence-related);
-
Effectiveness of the response, including what worked, what was constrained, and what gaps were identified;
-
Lessons learned and corrective actions, each with owner and due date; and
-
Recommendations for control improvements (preventive, detective, responsive).
Corrective actions arising from the report are tracked in the Cyber Incident Register and reviewed at Management Review per QHSE-MAN-001 §9. Recurrence or trend signals trigger a control effectiveness review per TEC-POL-001.
External Notification Pathways
Cyber security incidents may trigger multiple parallel notification obligations. The Security Officer assesses each incident against the pathways below and ensures statutory deadlines are met. Where multiple pathways apply, all are discharged independently — discharge of one does not satisfy another.
ReportCyber — ASD Notification
The Australian Signals Directorate operates the ReportCyber portal (cyber.gov.au/report) for both voluntary general incident reports and mandatory ransomware payment reports under the Cyber Security Act 2024 (Cth) Part 3.
Voluntary general incident report (recommended)
Westlink reports significant cyber security incidents to ASD/ACSC via ReportCyber as soon as practicable after containment, to access ACSC analytical support, threat intelligence and the limited use protections available under the Cyber Security Act 2024 (Cth). General reports are voluntary.
Mandatory ransomware payment report (Cyber Security Act 2024 Part 3)
Where Westlink makes (or where Westlink’s payment is made on Westlink’s behalf) a ransomware or cyber extortion payment, the Security Officer must lodge a report with the Australian Signals Directorate within 72 hours of the payment being made. The report must include the matters prescribed under the Cyber Security Act 2024 (Cth) Part 3 and the supporting regulations, including:
-
Details of the impacted entity and contact officer;
-
Description of the cyber security incident giving rise to the payment;
-
Details of the extorting entity (if known);
-
Description of the demand, including the demanded amount and the cryptocurrency or payment mechanism;
-
Details of the payment, including amount, date and recipient wallet or account; and
-
Any communications between the impacted entity and the extorting entity.
Failure to report within the 72-hour window exposes the body corporate to a civil penalty currently calibrated at 60 penalty units × 5 (s.4AA, Crimes Act 1914) — approximately $99,000 at current penalty unit value as of November 2024.
The decision to make or not make a ransom payment is taken by the CEO. Where the CEO authorises payment, the Security Officer initiates the ReportCyber lodgement within 24 hours of the payment to provide buffer against the 72-hour deadline.
OAIC — Notifiable Data Breach
Where the Security Officer assesses (in consultation with the Privacy Officer) that an incident may have caused unauthorised access to, disclosure of, or loss of personal information held by Westlink, the Privacy Act 1988 (Cth) Part IIIC Notifiable Data Breaches scheme applies.
-
Westlink has 30 days from awareness of a suspected eligible data breach to assess whether the breach is in fact an eligible data breach;
-
Where assessment confirms an eligible data breach, the Privacy Officer prepares the statement required by s.26WK and notifies the OAIC and the affected individuals as soon as practicable;
-
Where the breach is not assessed as eligible (e.g. remediation has prevented the likelihood of serious harm), the assessment outcome and rationale are recorded in the Notifiable Data Breach record and retained per §11; and
-
Where the breach affects fewer than 100 individuals but involves Defence personnel, the Privacy Officer also notifies DISO per §8.3 in addition to the OAIC.
Westlink’s eligible-data-breach assessment, statement and notification process is set out in GOV-PRO-006 Data Breach Response and Cross-Border Disclosure Procedure, which operationalises GOV-POL-015 Privacy Policy, and uses the OAIC’s published Notifiable Data Breach scheme guidance.
DISO — Defence Industry Security Office
Westlink, as a DISP entity, must report security incidents involving Defence classified or controlled information to the Defence Industry Security Office. The Security Officer (in the DISP-recognised CSO/SO role) notifies DISO via the DISP member portal and supplements with telephone contact for Major or Critical incidents.
-
Initial notification within 24 hours of becoming aware of the incident;
-
Confirmed information (scope, classification of information affected, containment status) within 5 business days;
-
Post-incident report shared with DISO within 30 days of recovery; and
-
DISO’s directions on containment, recovery and lessons-learned are reflected in the Westlink Post-Incident Report.
DISP membership-level changes (e.g. requirement to upgrade or where DISO determines membership should be reviewed) are managed under DSPF-C16.1-ongoing-* in consultation with the Defence Industry Security Branch.
Other Regulators and Stakeholders
Depending on the incident profile, additional notifications may be required:
-
Australian Federal Police — where the incident may constitute an offence under Part 10.7 of the Criminal Code Act 1995 (Cth) (computer offences) or other Commonwealth offences;
-
JOSCAR portal operator (Hellios) — where Westlink JOSCAR portal credentials are compromised or where the incident materially affects Westlink’s compliance posture against the JOSCAR information security questions (Q2.11.*);
-
Customers and contracting agencies — per the security incident notification clauses in the relevant contract (Defence, government, primes);
-
Insurers — per the cyber insurance policy notification clauses; and
-
Affected suppliers and third parties whose systems, accounts or data flows may be at risk.
Internal Escalation and Communications
Internal escalation is governed by severity (per §6) and incident sensitivity. The principles are: keep the CEO informed at decision points; keep affected business functions informed of operational impact; and limit detailed technical information to those with a need to know.
| Stakeholder | Severity 1 | Severity 2 | Severity 3 | Severity 4 |
|---|---|---|---|---|
| CEO | Immediately and at each milestone | Within 1 business day; at each milestone | Weekly summary | Weekly summary |
| Operations Manager | Immediately if operations affected | Within 1 business day if operations affected | When operationally relevant | Not required |
| Finance Manager | Immediately if funds at risk | Within 1 business day if funds at risk | When financially relevant | Not required |
| Privacy Officer | Immediately if personal info in scope | Within 1 business day if personal info in scope | Within 5 business days if personal info in scope | Not required |
| MSP technical lead | Immediately | Within 4 hours | Within 1 business day | Not required |
| Affected workers | On-need-to-know — directed by Security Officer | On-need-to-know | On-need-to-know | Not required |
| Board | Via CEO — at CEO discretion | Via CEO — at CEO discretion | Not required | Not required |
Public or media communications are coordinated by the CEO. All workers and contractors must direct any external query about a cyber incident to the CEO and must not discuss incident details outside the response team without CEO authorisation.
Limited Use Protections (Cyber Security Act 2024 Part 4)
Information voluntarily provided to the National Cyber Security Coordinator and the Australian Signals Directorate under the Cyber Security Act 2024 (Cth) Part 4 attracts limited use protections — the information cannot be used by specified Commonwealth bodies for regulatory or enforcement actions against the disclosing entity in respect of the incident reported.
Westlink benefits from these protections when reporting through ReportCyber (general voluntary report) and when engaging the National Cyber Security Coordinator during active incident response. The protections do NOT extend to obligations owed to other regulators (e.g. OAIC under the Privacy Act), to the courts, or to contracting agencies; Westlink continues to meet those obligations independently.
Records and Retention
All cyber incident records are maintained by the Security Officer in the Cyber Incident Register, hosted in the WMS SharePoint site with access restricted to the CEO, the Security Officer, the Privacy Officer (where applicable) and DISO auditors on request. Retention periods are set out in §13 Records below.
Training, Exercises and Awareness
Westlink maintains a cyber security awareness and exercise programme to underpin this procedure:
-
All workers complete cyber security awareness training on commencement and annually thereafter. The training covers phishing recognition, password / MFA hygiene, classification handling, incident reporting channels, and the worker’s role under this procedure.
-
The Security Officer and MSP technical lead complete additional incident response training, with refresh aligned to material changes in the ISM or ACSC guidance.
-
An annual tabletop exercise is conducted by the Security Officer using a scenario drawn from current threat intelligence — ransomware, BEC, supply-chain compromise, or insider threat. The exercise involves the CEO, the MSP, the Privacy Officer and at least one operations representative. Findings are recorded and corrective actions tracked in the Cyber Incident Register.
-
Phishing simulations are conducted by the MSP at least quarterly; failure rates and re-test outcomes are reported to the Management Review.
-
Lessons-learned actions from real incidents and exercises feed into refresher training content and into the next year’s tabletop scenario design.
Review Schedule
This procedure is reviewed annually as part of the Management Review cycle, or when significant changes occur to the threat environment, the ISM, PSPF, DISP requirements, the Cyber Security Act 2024 (Cth), the Privacy Act 1988 (Cth), or following a Severity 1 (Critical) cyber security incident.
Applicable Standards and Legislation
This procedure operates within the framework of the following external standards, legislation and reference materials. Where a statutory provision applies, the statutory definition and obligations prevail over any narrative description in this procedure.
-
Cyber Security Act 2024 (Cth) — No. 98, 2024 — Part 3 (ss.26–32 mandatory ransomware payment reporting within 72 hours to ASD via ReportCyber; s.26 reporting business entity threshold $3M turnover; s.27 reporting obligation; s.30 civil penalty 60 penalty units)
-
Privacy Act 1988 (Cth) — APPs 1–13, Part IIIC (NDB scheme), s.26WK–WR
-
OAIC Data Breach Preparation and Response guidance
-
OAIC Guide to Securing Personal Information (2024)
-
Australian Government Information Security Manual (ISM) — ACSC — Controls 0120–0143 (cyber security incident response), Control 0123 (ACSC reporting)
-
Protective Security Policy Framework (PSPF) — Policy 8 (sensitive information handling), Policy 17 (security incident reporting)
-
Defence Security Principles Framework (DSPF) 2022 — Principle 5 (incident reporting), Principle 6 (personnel security incidents)
-
Defence Industry Security Program (DISP) — Security Governance Framework — Membership obligations, security incident reporting
-
JOSCAR — Joint Supply Chain Accreditation Register — Supply chain assurance requirements across security, governance, privacy, ethics
-
ISO/IEC 27001:2022 Information Security Management Systems — Requirements — cl. 6.1 (risk assessment), cl. 8.2 (risk treatment), A.5.26 (incident response)
-
ISO/IEC 27035-1:2023 Information Security Incident Management — Principles and Process — Incident classification, response phases, evidence handling
-
ISO 22301:2019 Business Continuity Management Systems — Requirements — cl. 8.4 (business continuity plans), cl. 8.5 (exercising and testing)
-
Criminal Code Act 1995 (Cth) — Division 70 (bribery of foreign officials), Division 91 (espionage), Division 141–142 (bribery of Commonwealth officials)
Compliance coverage — cited by 29 requirements across 6 frameworks
Cyber Security Act 2024 (Cth)(4)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| CSA-RR-01 | Cyber Security Act 2024 s.26 (reporting business entity definition) | Partial | Low | §External Notification PathwaysTEC-PRO-001 §External Notification — Mandatory ransomware payment report sets the 72-hour ASD notification path under CSA 2024 Part 3 including penalty unit calibration and CEO authorisation flow. |
| CSA-RR-02 | Cyber Security Act 2024 s.27 (mandatory ransomware payment report) | Full | §External Notification PathwaysTEC-PRO-001 §External Notification — Mandatory ransomware payment report sets the 72-hour ASD notification path under CSA 2024 Part 3 including penalty unit calibration and CEO authorisation flow. | |
| CSA-RR-03 | Cyber Security Act 2024 s.27 — interaction with NDB and DSPF P16 | Gap | High | §External Notification PathwaysTEC-PRO-001 §External Notification — Mandatory ransomware payment report sets the 72-hour ASD notification path under CSA 2024 Part 3 including penalty unit calibration and CEO authorisation flow. |
| CSA-LU-01 | Cyber Security Act 2024 Part 4 (ss.33-44) | Referenced-only | §Limited Use ProtectionsTEC-PRO-001 §Limited Use Protections describes the Cyber Security Act 2024 (Cth) Part 4 protections that apply to information voluntarily disclosed to the National Cyber Security Coordinator and ASD. |
DSPF Principle 16 / Control 16.1 / Annex A(4)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| DSPF-C16.1-ongoing-02 | C16.1-ongoing-02 | Partial | §External Notification PathwaysTEC-PRO-001 §External Notification — ReportCyber covers voluntary general incident reports to ASD/ACSC and the resulting limited use protections. | |
| DSPF-C16.1-cso-01 | C16.1-cso-01 | Full | §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Security Officer (QHSE Manager) the cyber incident response coordination role. | |
| DSPF-C16.1-so-01 | C16.1-so-01 | Partial | §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Security Officer (QHSE Manager) the cyber incident response coordination role. | |
| DSPF-A16.1-entry-gov-04 | A16.1-entry-gov-04 | Full | §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Security Officer (QHSE Manager) the cyber incident response coordination role. |
Essential Eight Maturity Model — Maturity Level Two(12)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| E8-ML2-MFA-17 | ML2-MFA-17 | Full | §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity. | |
| E8-ML2-MFA-18 | ML2-MFA-18 | Partial | High | §External Notification PathwaysTEC-PRO-001 §External Notification — ReportCyber covers voluntary general incident reports to ASD/ACSC and the resulting limited use protections. |
| E8-ML2-MFA-19 | ML2-MFA-19 | Full | §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity. | |
| E8-ML2-RAP-18 | ML2-RAP-18 | Full | §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity. | |
| E8-ML2-RAP-19 | ML2-RAP-19 | Partial | High | §External Notification PathwaysTEC-PRO-001 §External Notification — ReportCyber covers voluntary general incident reports to ASD/ACSC and the resulting limited use protections. |
| E8-ML2-RAP-20 | ML2-RAP-20 | Full | §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity. | |
| E8-ML2-AC-12 | ML2-AC-12 | Full | §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity. | |
| E8-ML2-AC-13 | ML2-AC-13 | Partial | High | §External Notification PathwaysTEC-PRO-001 §External Notification — ReportCyber covers voluntary general incident reports to ASD/ACSC and the resulting limited use protections. |
| E8-ML2-AC-14 | ML2-AC-14 | Full | §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle: Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity. | |
| E8-ML2-UAH-20 | ML2-UAH-20 | Full | §Detection and ReportingTEC-PRO-001 §Detection and Reporting lists detection sources (worker reports, Defender alerts, Entra ID risky sign-in, MSP SOC, ACSC threat intel). | |
| E8-ML2-UAH-21 | ML2-UAH-21 | Partial | High | §External Notification PathwaysTEC-PRO-001 §External Notification — ReportCyber covers voluntary general incident reports to ASD/ACSC and the resulting limited use protections. |
| E8-ML2-UAH-22 | ML2-UAH-22 | Full | §Response LifecycleTEC-PRO-001 §Response Lifecycle applies the NIST SP 800-61 r2 / ISO 27035 lifecycle (Detection & Analysis → Containment → Eradication → Recovery → Post-Incident Activity) — the documented enactment of the incident response plan. |
ISO 9001:2015(2)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| ISO9001-2015-7.5.3.2-01 | 7.5.3.2 | Partial | Low | §Records and RetentionTEC-PRO-001 §Records and Retention establishes the Cyber Incident Register and the retention periods (permanent for ransomware payment reports, NDB statements, DISO notifications). |
| ISO9001-2015-7.5.3.2-02 | 7.5.3.2 | Full | §Records and RetentionTEC-PRO-001 §Records and Retention establishes the Cyber Incident Register and the retention periods (permanent for ransomware payment reports, NDB statements, DISO notifications). |
JOSCAR-AU 2026(3)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| JOSCAR-Q2.9.13 | Q2.9.13 | Partial | Medium | §ResponsibilitiesTEC-PRO-001 §Responsibilities defines MSP (Becloudsmart) cyber response duties including evidence preservation and Tier-2 support. |
| JOSCAR-Q2.11.5.4 | Q2.11.5.4 | Full | §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Security Officer (QHSE Manager) the cyber incident response coordination role. | |
| JOSCAR-Q2.11.12 | Q2.11.12 | Full | §PurposeTEC-PRO-001 §Purpose operationalises TEC-POL-001 information security commitments. |
Privacy Act 1988 (Cth) — Australian Privacy Principles + Notifiable Data Breaches(4)
| Requirement | Clause | Coverage | Severity | Notes |
|---|---|---|---|---|
| PRV-APP11-03 | APP 11 / OAIC Guide | Partial | High | §External Notification PathwaysTEC-PRO-001 §External Notification — OAIC NDB sets the 30-day eligible-data-breach assessment and the s.26WK statement path under Privacy Act 1988 (Cth) Part IIIC. |
| PRV-NDB-01 | s.26WE — eligible data breach | Full | §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Privacy Officer the NDB assessment role per Privacy Act 1988 (Cth) Part IIIC. | |
| PRV-NDB-02 | s.26WH, s.26WK, s.26WL — assessment, statement and notification | Full | §ResponsibilitiesTEC-PRO-001 §Responsibilities assigns the Privacy Officer the NDB assessment role per Privacy Act 1988 (Cth) Part IIIC. | |
| PRV-NDB-03 | s.26WK(3), OAIC guidance — data breach response plan | Full | §External Notification PathwaysTEC-PRO-001 §External Notification — OAIC NDB sets the 30-day eligible-data-breach assessment and the s.26WK statement path under Privacy Act 1988 (Cth) Part IIIC. |
Declared compliance references (29)
CSA-LU-01CSA-RR-01CSA-RR-02CSA-RR-03DSPF-A16.1-entry-gov-04DSPF-C16.1-cso-01DSPF-C16.1-ongoing-02DSPF-C16.1-so-01E8-ML2-AC-12E8-ML2-AC-13E8-ML2-AC-14E8-ML2-MFA-17E8-ML2-MFA-18E8-ML2-MFA-19E8-ML2-RAP-18E8-ML2-RAP-19E8-ML2-RAP-20E8-ML2-UAH-20E8-ML2-UAH-21E8-ML2-UAH-22ISO9001-2015-7.5.3.2-01ISO9001-2015-7.5.3.2-02JOSCAR-Q2.11.12JOSCAR-Q2.11.5.4JOSCAR-Q2.9.13PRV-APP11-03PRV-NDB-01PRV-NDB-02PRV-NDB-03
Document Revision Summary
| Rev | Issued | Document Ref | Document Title | Author | Approved |
|---|---|---|---|---|---|
| 1 | 27/05/2026 | TEC-PRO-001 | Cyber Incident Response Procedure | FTM (CF) | CEO (JDG) |
Document Revision Details
| Rev | Purpose of revision and changes made |
|---|---|
| 1 | Initial release. Operationalises TEC-POL-001 rev 3 commitments. Closes Framing B Phase 3 audit finding F61 (Cyber Security Act 2024 (Cth) Part 3 ransomware payment operational pathway). Establishes single procedure for cyber incident detection, response, internal escalation, external notification (ASD/ReportCyber, OAIC NDB, DISO) and post-incident review. |