• Annual Report 2024-25 now available

    Our Annual Report 2024-25 is now available.

    The report outlines our progress throughout the 2024-25 year to assure the quality of higher education in Australia.

    It provides an account of TEQSA’s performance against measures and targets set out in our 2024–28 Corporate Plan and the 2024-25 Portfolio Budget Statements.

    In August, we published our 2025-29 Corporate Plan, which outlines our priorities for the coming years.

    Image provides 'Highlights of 2024-25' year from the 2024-25 Annual Report.

    Date
    Last updated:
    Featured image
    Student at desk with light
  • Sector update: Cyber security and illegal academic cheating services

    TEQSA has issued a sector update, highlighting continuing concerns of cyber security risks posed by illegal academic cheating services to higher education providers:

    TEQSA holds concerns that illegal academic cheating services continue to target students, persuading them to share personal login details to provider IT systems, and using these to access sensitive information. These activities put students, academic and professional staff, and institutions at risk.

    Our sector update outlines providers’ responsibilities under the Higher Education Standards Framework (Threshold Standards) 2021 to mitigate these risks and provide a safe and secure environment for staff and students. It offers effective management strategies to support providers in meeting these obligations.

    TEQSA also offers numerous resources on our website, to help providers uplift their capability, including the following free online learning modules:

    Date
    Last updated:
    Featured image
    Sector update
  • Report a cyber security incident – key contacts

    To report cyber incidents, please contact the responsible body below. Other reporting obligations may apply in your jurisdiction. It is the responsibility of providers to ensure they are aware of, and meeting, their reporting requirements with state and territory cyber security agencies. 

    Office of the Australian Information Commissioner (OAIC)

    An institution that is covered by the Privacy Act 1988 needs to notify the OAIC if a data breach has occurred, along with any individuals who may be at risk of serious harm.

    Australian Signals Directorate (ASD)

    Under the Security of Critical Infrastructure Act 2018 and the Cyber Security Act 2024 it is mandatory for a university to report certain cyber incidents to the ASD.

    Other cybercrimes, cyber security incidents or vulnerabilities can be reported to the Australian Cyber Security Centre within the ASD.

    Tertiary Education Quality and Standards Agency (TEQSA)

    Providers need to notify TEQSA of incidents where there is a significant data breach and the provider may be at risk of not meeting its obligations under the Threshold Standards.

    Last updated:

    Related links

  • Cyber security – the role of TEQSA

    As Australia’s higher education regulator, TEQSA protects the quality and integrity of the Australian higher education sector and expects providers to manage sensitive information, such as intellectual property, research data and personal details, responsibly. This includes establishing and enacting measures to identify and manage cyber security risks.

    Higher Education Standards Framework provisions

    Under the Higher Education Standards Framework (Threshold Standards) 2021, providers are required to maintain their information security systems by: 

    • ensuring that information systems and records are securely and confidentially maintained to prevent unauthorised or fraudulent access to private or sensitive information (standard 7.3.3(b))
    • promoting and fostering a safe environment, including by advising students and staff on actions they can take to enhance safety and security online (standard 2.3.4)
    • having a critical incident policy and readily accessible procedures (standard 2.3.5)
    • taking preventative action to mitigate foreseeable risks to academic and research integrity (standard 5.2.2)
    • exercising due diligence to identify, prevent and manage risks within a provider’s remit of operations (domain 6).

    To ensure compliance with these obligations providers should:

    • have measures in place to understand the nature of cyber threats faced by their institution. Senior management and the governing council need to stay abreast of existing and emerging threats to inform and support the whole-of-institution risk mitigation strategy
    • ensure students and staff (including sessional staff) receive appropriate training on how to safeguard sensitive information and report concerns
    • have appropriate policies to identify and address cyber security incidents and embed such policies effectively into daily operations
    • be aware of cyber security threats associated with learning management systems (LMS), particularly if courses are delivered by a third-party provider
    • take prompt action in accordance with their security and incident response plans, paying close attention to the wellbeing and safety of all affected parties.
       
    Last updated:

    Related links

  • Cyber security e-learning modules

    These training modules, for Institutes of Higher Education and University Colleges, will build your knowledge of cyber security in the higher education sector and provide information on cyber security risks and how to mitigate them.

    At a glance
    • Content: 2 online modules
    • Duration: 3 hours, self-directed and self-paced
    • Cost: Free
    About the cyber security training resources

    Decorative image only

    The modules are available online and free of charge to all interested staff with an Australian higher education provider email address. Alternatively, providers are able to download the modules and embed them into their e-learning system. 

    There are 2 modules available:

    The modules aim to support institutions in developing awareness and capability to mitigate the risk of cybercrime. The cyber security modules add to our existing e-learning resources, the TEQSA Masterclass – contract cheating detection and deterrence.

    If you have already registered for our online Masterclass, you do not need to register again in our learning management system, simply use your existing username and password.

    Some users may not receive confirmation emails when signing up. If this occurs, please allow 2-3 business days and then try logging in again. If you are still unable to login, email integrityunit@teqsa.gov.au.

    Designers and contributors

    The modules were developed in collaboration with RMIT University’s Centre for Cyber Security Research and Innovation (CCSRI). They are an adaptation of resources which were created at the request of the Department of Education for Australian universities.

    Last updated:
  • Managing and reporting cyber security risks

    TEQSA has published a new resource to support providers in identifying and managing cyber security risks.

    The Australian higher education cyber security agencies and organisations placemat is available to download from TEQSA’s website. It provides details of Australian government, non-governmental and private organisations who can support higher education providers in identifying and managing cyber security risks.

    The new resource is offered to support providers in identifying organisations who can offer information and assistance to help them develop and implement robust cyber security measures.

    To protect the quality and integrity of Australian higher education, its important providers manage sensitive information responsibly. This includes identifying cyber security risks and having plans in place to mitigate these risks.

    It is a provider’s responsibility to ensure they are aware of, and meeting, their reporting requirements. Information on reporting a cyber security incident is also available.

    Related links

    Date
    Last updated:
    Featured image
    Cyber security
  • Cyber security

    This page provides:

    • key contacts for reporting cyber security incidents
    • an overview of Australian higher education cyber security agencies and organisations
    • information on TEQSA’s role and providers’ responsibilities, as they relate to information management and cyber security.

    Reporting obligations may change over time. It is each provider’s responsibility to stay up to date on their cyber security and compliance obligations.

    Institutes of Higher Education and University Colleges can also access TEQSA’s cyber security e-learning modules. These modules are designed to build knowledge and awareness of cyber security in higher education, the related risks and how to mitigate them. The modules are an adaptation of resources which were developed for Australian universities by the Department of Education. 

    Last updated:
  • Consultation opens for legislative framework review

    Update: Consultation has been extended until 31 October 2025

    On Wednesday 3 September, the Minister for Education released a consultation paper inviting views about the future regulation of Australian higher education and potential changes to the Tertiary Education Quality and Standards Agency Act 2011 (TEQSA Act).

    Led by the Department of Education, the consultation paper is inviting views from higher education students, staff, providers, and the wider community. Responses to the consultation paper should be submitted to teqsalr@education.gov.au by 5pm on Friday 31 October 2025.

    More information

    Date
    Last updated:
    Featured image
    Consultation