
When a serious cyber incident hits a regional organisation, the first hours are not only about containment. Somewhere, a regulator's clock has started. For a group operating across Australia, Singapore, Malaysia and the Gulf, a single ransomware attack can trigger a financial regulator's one-hour window, a critical infrastructure regulator's twelve-hour window and several seventy-two-hour privacy windows, each with a different trigger, a different recipient and a different form. This article brings those deadlines together as they stand in September 2026, explains why the triggers matter as much as the hours, and sets out how to run incident notification as a tested process rather than a scramble.
The shortest clocks: financial regulators and critical infrastructure

| Jurisdiction and regulator | Who it applies to | Deadline | Source |
|---|---|---|---|
| Singapore: MAS | Banks and other financial institutions under MAS technology risk management notices | Within 1 hour of discovering a relevant incident; root cause and impact report within 14 days | MAS TRM framework page |
| Singapore: CSA | Owners of critical information infrastructure | Prescribed incidents within 2 hours of becoming aware | CSA announcement |
| Qatar: NCSA | Entities under the National Information Assurance Standard | Critical incidents within 2 hours under NIAS v2.1 | Qatar NIAS page |
| Malaysia: NACSA | National critical information infrastructure entities under Act 854 | Immediately; further particulars within 6 hours; full details within 14 days | Malaysia country guide |
| Australia: SOCI Act | Critical infrastructure assets | 12 hours for a significant impact; 72 hours for a relevant impact | CISC guidance |
| UAE (ADGM): FSRA | ADGM authorised persons | Immediately, and no later than 24 hours after becoming aware of a material cyber incident | ADGM FSRA page |
| Australia: APRA CPS 230 | APRA-regulated entities | 24 hours if a critical operation is disrupted beyond tolerance; 72 hours for a material operational risk incident | CPS 230 page |
| Fiji: Reserve Bank | Licensed financial institutions | Material cyber incidents within 24 hours | Fiji country guide |
| Tonga: CERT Tonga | Designated critical infrastructure operators, once the Cybersecurity Act 2025 commences | Within 24 hours | Tonga country guide |
These are the windows that decide how an incident response plan must be built. A one-hour or two-hour clock cannot be met by a process that waits for a forensic firm to confirm the scope. It needs pre-agreed thresholds, a named decision maker on call, and a notification template that can be sent with what is known at the time.
The seventy-two-hour tier
| Jurisdiction | Obligation | Deadline |
|---|---|---|
| Australia: APRA CPS 234 | Material information security incident, or one notified to another regulator | 72 hours; material control weakness within 10 business days |
| Australia: Cyber Security Act 2024 | Ransomware or cyber extortion payment made by or on behalf of a reporting business | 72 hours after the payment, to ASD |
| UAE (DIFC): DFSA | Material cyber incident for authorised firms | 72 hours |
| New Zealand: RBNZ | Material cyber incidents under the cyber resilience guidance and data collection | 72 hours |
| Pakistan: PISF 2026 | Critical infrastructure incidents; other incidents | Detailed report within 72 hours; other incidents within 120 hours |
| Saudi Arabia: PDPL | Personal data breach, under Article 24 of the Implementing Regulation | 72 hours |
| Bahrain: PDPL | Personal data breach, under Ministerial Order 43/2022 | 72 hours |
| Oman: PDPL | Personal data breach, under the Executive Regulation | 72 hours |
| UAE (ADGM): Data Protection Regulations | Personal data breach, section 32 | 72 hours from awareness |
| Malaysia: PDPA as amended | Personal data breach | 72 hours to the Commissioner; 7 days to affected individuals |
Seventy-two hours has become the regional default for privacy breaches and for many prudential regimes, but the similarity is misleading. The clocks start at different moments: some from awareness, some from discovery, some from the point at which the organisation has assessed the breach as notifiable. A plan that treats them as one deadline will miss at least one.
Clocks measured in days, and the proposals coming
- Australia, Notifiable Data Breaches. Entities must notify the OAIC and affected individuals as soon as practicable after forming the view that an eligible data breach has occurred, and must complete an assessment of a suspected breach within 30 days.
- Singapore, PDPA. A notifiable data breach must be reported to the PDPC within three calendar days of the organisation assessing that it is notifiable.
- New Zealand, Privacy Act 2020. Notifiable privacy breaches must be reported to the Privacy Commissioner as soon as practicable.
- New Zealand, proposed critical infrastructure regime. The February 2026 discussion document proposes an early warning to the NCSC within 24 hours and a full report within 72 hours for significant incidents. These are proposals only, and no bill has been introduced yet.
- Papua New Guinea, draft Cybersecurity Bill 2026. Proposes incident notification within 24 hours for designated critical infrastructure.
Triggers matter more than hours
Most missed notifications are not late in hours. They are missed because nobody recognised that the trigger had been met. Four words cause most of the trouble:
- Material. APRA, the DFSA and the RBNZ tie their clocks to material incidents, and none defines materiality precisely. Your own documented criteria are what a regulator will test.
- Aware. Several regimes run from awareness, or from having information that reasonably suggests an incident. That can be earlier than confirmation, and a regulator will reconstruct when you should have known.
- Relevant or prescribed. MAS and CSA each publish what counts. A system outage with no data loss can still be reportable.
- Notified elsewhere. APRA's CPS 234 clock is triggered if the incident has been notified to any other regulator, so notifying one regulator can start another's clock.
The practical fix is a notification matrix, kept current, that lists for each entity and jurisdiction the trigger, the recipient, the channel, the deadline and the content required, and that is exercised at least once a year.
Building one notification process for many regulators

- Map entities to regimes. A group can hold an APRA licence, a SOCI asset, a Singapore banking licence and Saudi personal data in different subsidiaries. Map each legal entity, not the group.
- Pre-approve thresholds. Decide in advance which incident categories are presumed material, and who can declare an incident notifiable at 3am.
- Draft the notices now. Keep a template for each regulator, filled with fixed details, so the first notice goes out with what is known and follow-ups add detail.
- Track each clock as an indicator. Record when each clock started and when each notice was sent, so the board and the regulator can see the process working.
- Exercise it. Run at least one scenario a year that triggers several regimes at once, and record the times achieved.
How GRCLens tracks the clocks
GRCLens carries these obligations inside each framework catalogue, so the MAS one-hour rule sits in the MAS TRM framework, the SOCI windows in AESCSF and SOCI, and the privacy clocks in the relevant data protection frameworks. Reporting clocks are tracked as key risk indicators, incident records hold the timestamps a regulator will ask for, and because the frameworks share one control model, an incident logged once shows every obligation it triggered.
Frequently asked questions
What is the fastest cyber incident reporting deadline in the region?
MAS requires banks and other financial institutions in Singapore to notify it within one hour of discovering a relevant incident. CSA's critical information infrastructure rule and Qatar's NIAS critical incident rule both allow two hours.
How fast must an Australian critical infrastructure operator report a cyber incident?
Within 12 hours to ASD's ACSC for an incident with a significant impact, and within 72 hours for a relevant impact, under the SOCI Act.
Is 72 hours the standard for data breach notification?
For many privacy laws in the region, yes, including Saudi Arabia, Bahrain, Oman, ADGM and Malaysia. Australia and New Zealand instead require notification as soon as practicable, and Singapore within three days of assessment.
Do we need to report a ransomware payment in Australia?
Yes, if you are a reporting business under the Cyber Security Act 2024. The report goes to ASD within 72 hours of making the payment or becoming aware it was made.
How Security Solution Consultants can help
Security Solution Consultants builds incident notification matrices and runs multi-regulator incident exercises for organisations operating across Australia, New Zealand, Singapore, Malaysia and the Gulf. See our enterprise risk management advisory and our guide to notifiable data breaches in Australia. GRCLens then holds the matrix, the incident records and the clocks, so the evidence of a timely notification exists before anyone asks for it. Request a demonstration.
Keep reading

Autonomous Fleets Meet Critical Infrastructure Law: SOCI, New Zealand and the Gulf
Once an autonomous fleet moves freight or carries the public at scale, its operator starts to look like a critical infrastructure operator. What the SOCI Act, New Zealand's proposed regime and the Gulf rules ask for, and how to evidence it.

Running Post-Quantum Readiness as a GRC Programme: Inventory, KRIs and Regulator Dates
Post-quantum migration fails the same way most multi-year security programmes fail: an inventory nobody maintains, risks nobody scores, and dates nobody tracks. How to run it as a governed programme instead.

Governing AI Agents Under ISO/IEC 42001: Registers, Impact Assessments and Evidence
ISO/IEC 42001 was published before most organisations ran AI agents, but its structure fits them well. How to extend an AI management system to agents: the register, the impact assessment trigger, the life cycle controls and the evidence.