Regulatory hubSix chapters · sourced

Privacy, cyber, and AI regulation for Australian operators

The Real Bytes index of every Australian regulatory page we publish. Organised into four reading lanes: Privacy, AI governance, Cyber, and what boards ask us next. Each item has a status indicator and a one-line description so you can scan the whole picture in under a minute.

Need the dates rather than the obligations? Open the regulatory calendar for a chronological view of every commencement and consultation we track.

All in one place

Nine pages, four reading lanes

Sourced and dated

Each page references primary regulators

Operationally grounded

Tied to Microsoft 365 and field controls

Editorially reviewed
Last reviewed31 Aug 2026
Sources verified31 Aug 2026
Cyber

ASD, the Cyber Security Act, and the insurance market.

The technical baseline most Australian businesses are already working through. ASD is evolving Essential Eight into a successor framework while the Cyber Security Act 2024 has introduced new reporting obligations, and the insurance market has hardened proposal form requirements.

For APRA-regulated entities

CPS 230 is the resilience standard. CPS 234 is still the cyber one.

APRA Prudential Standard CPS 230 Operational Risk Management commenced on 1 July 2025 for most regulated entities, and applied to smaller entities from 1 July 2026, so it now covers the whole regulated population. It consolidates five prior standards covering operational risk, business continuity and outsourcing, and makes boards accountable for critical operations, tolerance levels, continuity testing and the material service provider register.

For boards

What boards and executive teams ask us next.

Once a board is aware of the regulatory picture, the next questions are operational. How is this reported? Who is accountable? What does our incident response actually look like? Three pages cover the practical follow-up work.

The pages above are the framing

Real Bytes does the operational work behind each one.

Privacy Act readiness, Voluntary AI Safety Standard alignment, Cyber Security Act 2024 reporting playbooks, Essential Eight maturity uplift, and the quarterly board reporting cadence that pulls it all together. If you are not sure where to start, we will walk a board or executive team through the picture in a single session.

This page is general information drawn from publicly available Australian government and legal sources. It is not legal advice. For decisions affecting your business, refer to the linked primary sources or seek qualified advice.