Complex Regimes – Regulatory Overlap in Australia’s Cloud Services Sector

Susanne Lloyd-Jones et al.

Bond Law Review2025https://doi.org/10.53300/001c.140703article
ABDC B
Weight
0.50

Abstract

Robust cyber security protection is essential to cloud services and government and private sector customers. In Australia, cloud services have undergone a significant regulatory reset, in part due to reforms to the critical infrastructure (‘CI’) legislative framework, including amendments to the Security of Critical Infrastructure Act 2018 (Cth) (‘SOCI Act’). Shifts in industry practice, such as the increased uptake of cloud services by businesses and government agencies and the advent of new security threats, have accentuated these changes. While Australian governments and regulators have implemented numerous legislative, policy, and guidance instruments to bolster cyber security measures, many of these attempts are not well-aligned. The outcome is an unclear and difficult-to-navigate regulatory ecosystem. We argue this complex regulatory landscape will likely result in increased costs, variable compliance, and decreased confidence in providing cyber security services unless careful attention is paid to mitigating the detrimental effects of ‘regulatory overlap’. This article identifies and critically examines key elements of existing statutory, regulatory and guidance instruments imposing cyber security and CI obligations on cloud services providers, as well as agencies and institutions holding key regulatory roles. These elements are examined in the context of cloud services providers subject to direct legal obligations, such as being responsible entities for CI assets and/or systems of national significance under the SOCI Act and other cloud services entities that form part of the supply chain for other providers with such obligations.

Open via your library →

Cite this paper

https://doi.org/https://doi.org/10.53300/001c.140703

Or copy a formatted citation

@article{susanne2025,
  title        = {{Complex Regimes – Regulatory Overlap in Australia’s Cloud Services Sector}},
  author       = {Susanne Lloyd-Jones et al.},
  journal      = {Bond Law Review},
  year         = {2025},
  doi          = {https://doi.org/https://doi.org/10.53300/001c.140703},
}

Paste directly into BibTeX, Zotero, or your reference manager.

Flag this paper

Complex Regimes – Regulatory Overlap in Australia’s Cloud Services Sector

Flags are reviewed by the Arbiter methodology team within 5 business days.


Evidence weight

0.50

Balanced mode · F 0.40 / M 0.15 / V 0.05 / R 0.40

F · citation impact0.50 × 0.4 = 0.20
M · momentum0.50 × 0.15 = 0.07
V · venue signal0.50 × 0.05 = 0.03
R · text relevance †0.50 × 0.4 = 0.20

† Text relevance is estimated at 0.50 on the detail page — for your query’s actual relevance score, open this paper from a search result.