Today

Cyber security incidents are events that compromise the confidentiality, integrity, or availability of information and systems, including threats such as malware, phishing, unauthorised access, and data breaches. All agencies are responsible for identifying, assessing, and promptly reporting these cyber security incidents to NHMRC while continuing to manage them within their own environments.

The Administering Institutions Incident Reporting Process (in the downloads section) establishes a clear and consistent pathway for reporting and managing cyber security incidents between Administering Institutions and NHMRC. It defines notification requirements and coordinated response actions to ensure incidents affecting digital assets are addressed effectively.

This process strengthens collaboration across agencies by providing defined reporting pathways and promoting information sharing. It enables a coordinated, consistent approach to cyber security incident management, helping build a more secure and resilient digital environment.

Information sharing and collaboration process

We encourage colleagues across the Administering Institutions to promptly report cyber security incidents to NHMRC to support effective collaboration and timely containment. All cyber security incident information will be handled with strict confidentiality and shared only with authorised parties on a need-to-know basis.

NHMRC, supported by its Cyber and Research Administration teams, provides oversight, coordination, and escalation where required. Cyber security incidents must be reported as soon as practicable to ensure appropriate and coordinated response actions.

Reporting pathways:

Please include below information in your reporting:

  • cyber security Incident short description
  • date and time detected
  • affected system, service, process, or dataset
  • known or suspected impact
  • whether the incident is ongoing 
  • whether sensitive, personal, or research-related data is impacted
  • Administering Institution contact officer and escalation contact.

Note: Please do not include any sensitive or confidential information in your reporting. 

Downloads

File type
Size