The Cyber Security Act 2024 has been law since 2024, and its ransomware payment reporting rules have been in force since 2025. Most Australian businesses captured by them have no idea the obligation applies — until the 72-hour clock is already running.
- The Cyber Security Act 2024 received Royal Assent on 29 November 2024. Mandatory ransomware payment reporting commenced 30 May 2025.
- If your business makes — or someone makes on your behalf — a ransomware or cyber extortion payment to an extorting entity, you have 72 hours to report it.
- The obligation captures businesses with annual turnover above $3 million in the previous financial year, plus critical infrastructure entities regardless of turnover.
- Payments made by insurers, incident response firms or negotiators on your behalf are still your report to file.
- Reporting is not the only exposure: paying a sanctioned entity is a separate criminal offence under Australia’s sanctions regime.
What the Cyber Security Act 2024 actually does
The Cyber Security Act 2024 is Australia’s first standalone cyber security act. It received Royal Assent on 29 November 2024 as part of the Australian Cyber Security Strategy, is administered by the Department of Home Affairs, and takes a whole-of-economy approach that closed long-standing legislative gaps and brought Australia into line with international practice.
Four measures in the Act matter to business: mandatory ransomware payment reporting; mandatory security standards for smart devices and other connectable products; the limited use obligation that governs how shared information can be used; and the Cyber Incident Review Board, which conducts no-fault reviews of significant incidents to find systemic weaknesses across the economy.
For most Australian businesses, the first measure has immediate teeth. It sits alongside your existing cyber security compliance obligations under the SOCI Act, the Privacy Act 1988 and the Notifiable Data Breaches scheme — it does not replace them.
Ransomware payment reporting: the 72-hour rule
If your business is a reporting business entity and a ransomware or cyber extortion payment is made in response to a cyber security incident, you must report it within 72 hours. This is the ransomware payment and cyber extortion payment reporting obligation, and the report is lodged through cyber.gov.au.
You are a reporting business entity if your annual turnover exceeded $3 million in the previous financial year. Critical infrastructure entities regulated under the SOCI Act are captured regardless of turnover. Critical infrastructure is captured on its own terms — if you run a critical infrastructure asset, the turnover test does not apply — critical infrastructure is regulated on its own footing. The clock starts when the payment is made — or, crucially, when you become aware that a payment was made on your behalf.
The 72-hour clock also starts the moment you become aware a payment was made on your behalf — not just when you pay directly.
| Your situation | Must report? |
|---|---|
| Annual turnover above $3M (previous financial year) | Yes |
| Turnover below $3M, not critical infrastructure | No |
| Critical infrastructure asset under the SOCI Act | Yes regardless of turnover |
| Your cyber insurer paid on your behalf | Yes still your obligation |
| An incident response firm or negotiator paid for you | Yes |
| You received a demand but did not pay | No under this obligation — NDB or SOCI may still apply |
What the report must contain
- Your organisation’s details
- The entity you are reporting on behalf of, where a third party made the payment
- Details of the cyber security incident
- Information about the extorting entity and the demand
Non-compliance with the reporting obligation carries a civil penalty under the Act — report promptly rather than testing where that line falls.
When the payment is made on your behalf
Here is the part no competitor page leads with. In a live cyber security incident, the cyber extortion payment to the extorting entity is frequently executed by someone other than the business itself — the cyber insurer, a retained incident response firm, or a professional negotiator acting under instruction.
The reporting obligation still sits with the reporting business entity. It does not transfer to whoever moved the money, and the 72-hour clock runs from the moment you become aware the payment was made. In the chaos of a live cyber security incident, that awareness can arrive days after the event — and the deadline does not wait for your paperwork to catch up.
The practical consequence is specific: your incident response plan must name who confirms that a payment occurred and who is responsible for lodging the report. If that is not written down before an incident, it will not happen inside 72 hours during one.
Paying a sanctioned entity is a criminal offence
Reporting is one exposure. Sanctions are another, and they are more serious. Australia’s autonomous sanctions framework has operated since 2011, and the Minister for Foreign Affairs can designate persons and entities under it. Designated persons face targeted financial sanctions and travel bans.
Making a payment to a designated entity can expose the payer to criminal liability — entirely separately from the reporting obligation. A cyber security incident can originate anywhere in the world, and the group behind it may already be designated — a determination you cannot make reliably under extortion pressure.
Before any payment is contemplated, get advice. Whether an entity is sanctioned is a legal question with criminal consequences — check the position with DFAT guidance and qualified legal counsel, not under deadline pressure alone.
The limited use obligation: reporting is safer than it sounds
Many businesses stay silent after an incident, fearing that reporting hands regulators a ready-made case against the reporting business entity. The Act is built to counter that fear. The limited use obligation restricts how information you share with government during an incident can be used by regulators, and provides protections around the admissibility of that information against the reporting entity.
The intent is to encourage disclosure rather than punish it — to make it safe to pick up the phone early so the national picture of ransomware activity is accurate.
One caveat matters. Limited use is not immunity. It does not switch off your other obligations: the Privacy Act 1988 and the Notifiable Data Breaches scheme still apply in parallel, and a data breach involving personal information may be separately notifiable. Reporting the payment satisfies that obligation — not every obligation the incident triggers.
What your business should do now
None of this requires new technology. It requires knowing where you stand and writing three things down before you need them:
- Confirm whether you cross the threshold. Check your annual turnover for the previous financial year, and whether you hold a critical infrastructure asset under the SOCI Act.
- Write the reporting step into your incident response plan with a named owner — who confirms a payment occurred, and who lodges the report inside 72 hours.
- Confirm with your insurer and any retained IR firm who lodges what. Do not assume the party that pays also reports.
- Know where the cyber.gov.au form is before you need it. Bookmark it in the plan; do not go hunting at 2am.
- Keep the Cyber Incident Review Board in mind. Post-incident reviews look for systemic lessons — a well-run response is the story you want on record.
Good ransomware protection reduces the odds you ever face this decision. A tested response plan means that if you do, the reporting obligation is handled by design rather than remembered in a panic.
“Most incident response plans read well on paper. The gap we see in a live incident is authority — who is actually allowed to make the call at 2am when the people named in the plan can’t be reached.”— PIP, from incident response work
The Cyber Security Act receives Royal Assent.
Mandatory ransomware payment reporting commences.
Active enforcement posture as guidance and subordinate rules mature.
Common questions
Is it illegal to pay ransomware in Australia?
What is a ransomware payment?
What is the current cyber security legislation in Australia?
Should you pay the ransom for ransomware?
This article is general information about the Cyber Security Act, not legal advice. Obligations depend on your circumstances — confirm your position with qualified legal counsel and the primary sources at cyber.gov.au, the Department of Home Affairs and legislation.gov.au.
Does your incident response plan name who files the report?
PIP helps Sydney businesses build incident response plans that hold up in the first 72 hours — including the obligations most plans leave out.
Build a response plan →
