Skip to content
arrow_back
search
ISM-1880 policy ASD Information Security Manual (ISM)

Timely Reporting of Cyber Incidents Involving Customer Data

Notify customers and the public promptly about cybersecurity incidents involving their data.

record_voice_over

Plain language

If your business suffers from a cyber attack where customer data is exposed or stolen, this rule means you need to let your customers and the public know about it quickly. This is important because delaying such information can lead to worse outcomes, like financial harm or loss of trust, for both your customers and your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Cyber security incidents that involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
policy ASD Information Security Manual (ISM) ISM-1880
priority_high

Why it matters

Delayed notification of incidents involving customer data can breach expectations, erode public trust, and increase customer fraud and privacy harm.

settings

Operational notes

Define notification triggers and timeframes for incidents involving customer data; maintain customer/public comms templates and up-to-date contact channels to notify promptly.

Mapping detail

Mapping

Direction

Controls