HomeBlogIncident Response
Incident Response

Cyber Incident Reporting Deadlines in 2026: Australia, New Zealand, Singapore, Malaysia and the Gulf Compared

Sep 2026 · 10 min read

Poster-style stopwatch surrounded by orbiting red and orange dials of different sizes under an alert burst, on a black background

When a serious cyber incident hits a regional organisation, the first hours are not only about containment. Somewhere, a regulator's clock has started. For a group operating across Australia, Singapore, Malaysia and the Gulf, a single ransomware attack can trigger a financial regulator's one-hour window, a critical infrastructure regulator's twelve-hour window and several seventy-two-hour privacy windows, each with a different trigger, a different recipient and a different form. This article brings those deadlines together as they stand in September 2026, explains why the triggers matter as much as the hours, and sets out how to run incident notification as a tested process rather than a scramble.

The shortest clocks: financial regulators and critical infrastructure

Isometric illustration of several clocks of different sizes on floating tiles, each linked to a regulator building, around a central incident alarm hub
One incident can start several clocks, each with its own trigger and recipient.
Jurisdiction and regulatorWho it applies toDeadlineSource
Singapore: MASBanks and other financial institutions under MAS technology risk management noticesWithin 1 hour of discovering a relevant incident; root cause and impact report within 14 daysMAS TRM framework page
Singapore: CSAOwners of critical information infrastructurePrescribed incidents within 2 hours of becoming awareCSA announcement
Qatar: NCSAEntities under the National Information Assurance StandardCritical incidents within 2 hours under NIAS v2.1Qatar NIAS page
Malaysia: NACSANational critical information infrastructure entities under Act 854Immediately; further particulars within 6 hours; full details within 14 daysMalaysia country guide
Australia: SOCI ActCritical infrastructure assets12 hours for a significant impact; 72 hours for a relevant impactCISC guidance
UAE (ADGM): FSRAADGM authorised personsImmediately, and no later than 24 hours after becoming aware of a material cyber incidentADGM FSRA page
Australia: APRA CPS 230APRA-regulated entities24 hours if a critical operation is disrupted beyond tolerance; 72 hours for a material operational risk incidentCPS 230 page
Fiji: Reserve BankLicensed financial institutionsMaterial cyber incidents within 24 hoursFiji country guide
Tonga: CERT TongaDesignated critical infrastructure operators, once the Cybersecurity Act 2025 commencesWithin 24 hoursTonga country guide

These are the windows that decide how an incident response plan must be built. A one-hour or two-hour clock cannot be met by a process that waits for a forensic firm to confirm the scope. It needs pre-agreed thresholds, a named decision maker on call, and a notification template that can be sent with what is known at the time.

The seventy-two-hour tier

JurisdictionObligationDeadline
Australia: APRA CPS 234Material information security incident, or one notified to another regulator72 hours; material control weakness within 10 business days
Australia: Cyber Security Act 2024Ransomware or cyber extortion payment made by or on behalf of a reporting business72 hours after the payment, to ASD
UAE (DIFC): DFSAMaterial cyber incident for authorised firms72 hours
New Zealand: RBNZMaterial cyber incidents under the cyber resilience guidance and data collection72 hours
Pakistan: PISF 2026Critical infrastructure incidents; other incidentsDetailed report within 72 hours; other incidents within 120 hours
Saudi Arabia: PDPLPersonal data breach, under Article 24 of the Implementing Regulation72 hours
Bahrain: PDPLPersonal data breach, under Ministerial Order 43/202272 hours
Oman: PDPLPersonal data breach, under the Executive Regulation72 hours
UAE (ADGM): Data Protection RegulationsPersonal data breach, section 3272 hours from awareness
Malaysia: PDPA as amendedPersonal data breach72 hours to the Commissioner; 7 days to affected individuals

Seventy-two hours has become the regional default for privacy breaches and for many prudential regimes, but the similarity is misleading. The clocks start at different moments: some from awareness, some from discovery, some from the point at which the organisation has assessed the breach as notifiable. A plan that treats them as one deadline will miss at least one.

Clocks measured in days, and the proposals coming

  • Australia, Notifiable Data Breaches. Entities must notify the OAIC and affected individuals as soon as practicable after forming the view that an eligible data breach has occurred, and must complete an assessment of a suspected breach within 30 days.
  • Singapore, PDPA. A notifiable data breach must be reported to the PDPC within three calendar days of the organisation assessing that it is notifiable.
  • New Zealand, Privacy Act 2020. Notifiable privacy breaches must be reported to the Privacy Commissioner as soon as practicable.
  • New Zealand, proposed critical infrastructure regime. The February 2026 discussion document proposes an early warning to the NCSC within 24 hours and a full report within 72 hours for significant incidents. These are proposals only, and no bill has been introduced yet.
  • Papua New Guinea, draft Cybersecurity Bill 2026. Proposes incident notification within 24 hours for designated critical infrastructure.

Triggers matter more than hours

Most missed notifications are not late in hours. They are missed because nobody recognised that the trigger had been met. Four words cause most of the trouble:

  1. Material. APRA, the DFSA and the RBNZ tie their clocks to material incidents, and none defines materiality precisely. Your own documented criteria are what a regulator will test.
  2. Aware. Several regimes run from awareness, or from having information that reasonably suggests an incident. That can be earlier than confirmation, and a regulator will reconstruct when you should have known.
  3. Relevant or prescribed. MAS and CSA each publish what counts. A system outage with no data loss can still be reportable.
  4. Notified elsewhere. APRA's CPS 234 clock is triggered if the incident has been notified to any other regulator, so notifying one regulator can start another's clock.

The practical fix is a notification matrix, kept current, that lists for each entity and jurisdiction the trigger, the recipient, the channel, the deadline and the content required, and that is exercised at least once a year.

Building one notification process for many regulators

Isometric illustration of an incident response room with a matrix board of colour-coded tiles linking to several regulator buildings
A notification matrix maps each trigger to its recipient, channel and deadline before an incident, not during one.
  • Map entities to regimes. A group can hold an APRA licence, a SOCI asset, a Singapore banking licence and Saudi personal data in different subsidiaries. Map each legal entity, not the group.
  • Pre-approve thresholds. Decide in advance which incident categories are presumed material, and who can declare an incident notifiable at 3am.
  • Draft the notices now. Keep a template for each regulator, filled with fixed details, so the first notice goes out with what is known and follow-ups add detail.
  • Track each clock as an indicator. Record when each clock started and when each notice was sent, so the board and the regulator can see the process working.
  • Exercise it. Run at least one scenario a year that triggers several regimes at once, and record the times achieved.

How GRCLens tracks the clocks

GRCLens carries these obligations inside each framework catalogue, so the MAS one-hour rule sits in the MAS TRM framework, the SOCI windows in AESCSF and SOCI, and the privacy clocks in the relevant data protection frameworks. Reporting clocks are tracked as key risk indicators, incident records hold the timestamps a regulator will ask for, and because the frameworks share one control model, an incident logged once shows every obligation it triggered.

Frequently asked questions

What is the fastest cyber incident reporting deadline in the region?

MAS requires banks and other financial institutions in Singapore to notify it within one hour of discovering a relevant incident. CSA's critical information infrastructure rule and Qatar's NIAS critical incident rule both allow two hours.

How fast must an Australian critical infrastructure operator report a cyber incident?

Within 12 hours to ASD's ACSC for an incident with a significant impact, and within 72 hours for a relevant impact, under the SOCI Act.

Is 72 hours the standard for data breach notification?

For many privacy laws in the region, yes, including Saudi Arabia, Bahrain, Oman, ADGM and Malaysia. Australia and New Zealand instead require notification as soon as practicable, and Singapore within three days of assessment.

Do we need to report a ransomware payment in Australia?

Yes, if you are a reporting business under the Cyber Security Act 2024. The report goes to ASD within 72 hours of making the payment or becoming aware it was made.

How Security Solution Consultants can help

Security Solution Consultants builds incident notification matrices and runs multi-regulator incident exercises for organisations operating across Australia, New Zealand, Singapore, Malaysia and the Gulf. See our enterprise risk management advisory and our guide to notifiable data breaches in Australia. GRCLens then holds the matrix, the incident records and the clocks, so the evidence of a timely notification exists before anyone asks for it. Request a demonstration.

This article is general information, not legal advice. Regulations change, so confirm current requirements with the relevant regulator before relying on them. Questions?info@grclens.net.

← All articles