Skip to content
arrow_back
search
E8-AC-ML2.9 bolt ASD Essential Eight

Cyber security incidents are reported promptly to CISO

Report security incidents quickly to the security chief or their team.

record_voice_over

Plain language

If a cyber security incident happens, it's important to let the person in charge of security know as soon as possible. This helps the organisation respond quickly to limit the damage and prevent further issues from developing. Without this control, an incident might go unnoticed, leading to severe consequences like data breaches or loss of trust.

Framework

ASD Essential Eight

Control effect

Responsive

E8 mitigation strategy

Application control

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered.
bolt ASD Essential Eight E8-AC-ML2.9
priority_high

Why it matters

Delayed incident reporting risks escalating breaches, potentially compromising sensitive data and damaging organisational reputation.

settings

Operational notes

Document and publicise an incident reporting workflow with CISO/delegate contact paths, and run periodic drills to ensure incidents are reported immediately on discovery.

Mapping detail

Mapping

Direction

Controls