Law / Kiribati

Cybersecurity Act 2026, Duty to Report a Cybersecurity Incident

Cybersecurity Act 2026 (Act No. 7 of 2026), s. 21 (Part VI)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

Commencement not set.

A vulnerability and incident reporting rule binding public and private bodies.

As of 19 September 2026.

What it requires

  • This duty does not yet bind: the Cybersecurity Act 2026 commences only on a date the Minister may by notice appoint under section 2, and no commencement date has been identified.
  • It reaches you only once the Minister has designated your physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure under section 12; see this jurisdiction's companion critical-infrastructure operator-obligations row for the designation criteria.
  • When you are the subject of a cybersecurity incident or threat of one, gather information about it, assess the risk to your critical infrastructure, customers, suppliers and other stakeholders, take appropriate preventative, mitigating and remedial measures to limit that risk, and report all material information about a significant cybersecurity incident to the National CERT and any relevant Sectoral CERT within 24 hours after you detect it, in the form or manner the CERT prescribes.
  • Provide any further information the National CERT or a Sectoral CERT requests about the incident, and allow either CERT to access your network and information infrastructure to analyse the incident, detect other threats, identify vulnerabilities, and advise on preventative, mitigating or remedial measures.

If you get it wrong

Criminal exposureYes

Private right of actionNo

Criminal exposure note

Section 25(1) makes it an offence for an operator of critical infrastructure to fail to carry out its obligations under Parts IV or V without a granted exemption or modification from the DTO under section 23, which reaches the section 21 reporting duty as one of Part VI's obligations. Section 25(2) sets the operative penalty: a fine not exceeding $100,000 for a first offence or $200,000 for a subsequent offence, and a further fine not exceeding $200 for each day a continuing offence persists. The Act's own Explanatory Memorandum states a lower penalty for the identical offence ($10,000, $20,000 and $100 respectively), a discrepancy that is not resolved here.

Penalty structure

Section 25(2)'s own operative text sets a graduated fixed structure: a fine not exceeding $100,000 for a first offence, not exceeding $200,000 for a subsequent offence (recorded here as fixed_cap), and a further fine not exceeding $200 for each day a continuing offence persists. The Act does not define the currency the bare "$" denotes; Kiribati's legal tender is the Australian dollar (ISO 4217: AUD). The Act's own Explanatory Memorandum states a different, lower set of figures for the same offence: $10,000, $20,000 and $100 per continuing day, exactly one-tenth the operative section's figures; both are recorded here, and which one governs is not resolved.

Rule
Fixed only
As of
19 September 2026
Currency
AUD
Fixed cap
200,000

Who enforces it

Enforcement body

The National CERT and any relevant Sectoral CERT, which receive the section 21 report and may request further information or access to the operator's network and information infrastructure; a failure to report is enforced through the same section 25 offence as this jurisdiction's companion critical-infrastructure operator-obligations row, whose own text names a failure of obligations under "Parts IV or V" rather than the Part VI reporting duty it appears intended to enforce.

Settledness

As of
19 September 2026
Open questions
  • Has the Minister issued the section 2 commencement notice bringing the Cybersecurity Act 2026 into force, and if so, on what date?
  • Which infrastructure assets, networks or information systems, if any, has the Minister designated as critical infrastructure under section 12, since the reporting duty binds only an operator so designated?
  • How does the National CERT classify a cybersecurity incident as "significant" for the purpose of triggering the section 21(1)(d) reporting duty, and has it prescribed the "form or manner" the subsection contemplates?

What it reaches

Obligation class

Reporting, Security

Applicability criteria

The Act itself is not yet in force: section 2 makes commencement conditional on a date the Minister proclaims by notice, so this criterion cannot yet be satisfied by anyone.

As of
19 September 2026
Combinator
All of
Criteria
The Minister, on the advice of the Director of the Digital Transformation Office, has designated your physical, electronic or virtual infrastructure asset, network or information system as critical infrastructure under section 12 of the Cybersecurity Act 2026.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Section 21 requires an operator of critical infrastructure that is the subject of a cybersecurity incident or threat of one to gather information about it, including its nature and impact, and to assess the risk it poses to the critical infrastructure, customers, suppliers and other stakeholders.

The operator must take appropriate preventative, mitigating and remedial measures to limit that risk, and must report all material information about a significant cybersecurity incident to the National CERT and any relevant Sectoral CERT within 24 hours after the incident is detected, in a form or manner the CERT may prescribe.

The operator must provide any further information the National CERT or a Sectoral CERT requests about the incident, and must allow either CERT to access its network and information infrastructure to analyse the incident, detect other potential threats, identify vulnerabilities, and advise on preventative, mitigating or remedial measures.

A failure to report is enforced through the same section 25 offence as this jurisdiction's companion critical-infrastructure operator-obligations row, punishable on summary conviction by a fine of up to $100,000 for a first offence, up to $200,000 for a subsequent offence, and up to $200 for each day a continuing offence persists, though the Act's own Explanatory Memorandum states a materially lower set of figures for the identical offence.

When LexLint raises it

  • operates_essential_service
  • provides_financial_services
  • provides_telecom_services
  • handles_health_records

Read the law

Official Act text (Cybersecurity Act 2026, Act No. 7 of 2026)
published by the Ministry of Information, Communications and Transport (mict.gov.ki)

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app