Skip to content
arrow_back
search
ISM-1881 policy ASD Information Security Manual (ISM)

Timely Reporting of Cyber Incidents Without Data Breach

Inform customers about cyber incidents quickly if no customer data is involved.

record_voice_over

Plain language

This control is about making sure you tell your customers quickly if something goes wrong with your computer systems, even if their data isn’t at risk. This is important because being transparent can maintain trust and prevent any misunderstandings or rumours about your business.

Framework

ASD Information Security Manual (ISM)

Control effect

Responsive

Classifications

NC, OS, P, S, TS

ISM last updated

Nov 2023

Control Stack last updated

19 Mar 2026

E8 maturity levels

N/A

Official control statement

Cyber security incidents that do not involve customer data are reported to customers and the public in a timely manner after they occur or are discovered.
policy ASD Information Security Manual (ISM) ISM-1881
priority_high

Why it matters

Delays in reporting cyber incidents (without customer data involved) can fuel rumours, harm public trust and drive customer attrition.

settings

Operational notes

Define triggers and timeframes to notify customers and the public of non-data cyber incidents; maintain comms templates, contacts and an approval workflow.

Mapping detail

Mapping

Direction

Controls