Skip to content
arrow_back
search
E8-RA-ML2.11 bolt ASD Essential Eight

Report cyber incidents to the CISO promptly

Report security incidents to the security officer quickly after finding them.

record_voice_over

Plain language

This control means that whenever there's a suspected cyber security incident, such as a data breach or hacking attempt, it needs to be reported to the Chief Information Security Officer (CISO) or their delegate immediately. This matters because quick reporting allows the organisation to respond swiftly, minimising potential damage and costs.

Framework

ASD Essential Eight

Control effect

Responsive

E8 mitigation strategy

Restrict administrative privileges

Classifications

N/A

Official last update

N/A

Control Stack last updated

19 Mar 2026

E8 maturity levels

ML2

Official control statement

Cyber security incidents are reported to the Chief Information Security Officer, or one of their delegates, as soon as possible after they occur or are discovered.
bolt ASD Essential Eight E8-RA-ML2.11
priority_high

Why it matters

Failure to promptly report incidents to the CISO can delay crisis management, worsening data breaches and increasing recovery costs.

settings

Operational notes

Escalate suspected cyber security incidents to the CISO (or delegate) via the defined process immediately upon discovery, and record time and details.

Mapping detail

Mapping

Direction

Controls