Cyber Security Act 2024: What the Ransomware Payment Reporting Rules Mean for Your Business

Cyber Security Act Ransom Reporting

The Cyber Security Act 2024 has been law since 2024, and its ransomware payment reporting rules have been in force since 2025. Most Australian businesses captured by them have no idea the obligation applies — until the 72-hour clock is already running.

The short version
  • The Cyber Security Act 2024 received Royal Assent on 29 November 2024. Mandatory ransomware payment reporting commenced 30 May 2025.
  • If your business makes — or someone makes on your behalf — a ransomware or cyber extortion payment to an extorting entity, you have 72 hours to report it.
  • The obligation captures businesses with annual turnover above $3 million in the previous financial year, plus critical infrastructure entities regardless of turnover.
  • Payments made by insurers, incident response firms or negotiators on your behalf are still your report to file.
  • Reporting is not the only exposure: paying a sanctioned entity is a separate criminal offence under Australia’s sanctions regime.
The law

What the Cyber Security Act 2024 actually does

The Cyber Security Act 2024 is Australia’s first standalone cyber security act. It received Royal Assent on 29 November 2024 as part of the Australian Cyber Security Strategy, is administered by the Department of Home Affairs, and takes a whole-of-economy approach that closed long-standing legislative gaps and brought Australia into line with international practice.

Four measures in the Act matter to business: mandatory ransomware payment reporting; mandatory security standards for smart devices and other connectable products; the limited use obligation that governs how shared information can be used; and the Cyber Incident Review Board, which conducts no-fault reviews of significant incidents to find systemic weaknesses across the economy.

For most Australian businesses, the first measure has immediate teeth. It sits alongside your existing cyber security compliance obligations under the SOCI Act, the Privacy Act 1988 and the Notifiable Data Breaches scheme — it does not replace them.

The core obligation

Ransomware payment reporting: the 72-hour rule

If your business is a reporting business entity and a ransomware or cyber extortion payment is made in response to a cyber security incident, you must report it within 72 hours. This is the ransomware payment and cyber extortion payment reporting obligation, and the report is lodged through cyber.gov.au.

You are a reporting business entity if your annual turnover exceeded $3 million in the previous financial year. Critical infrastructure entities regulated under the SOCI Act are captured regardless of turnover. Critical infrastructure is captured on its own terms — if you run a critical infrastructure asset, the turnover test does not apply — critical infrastructure is regulated on its own footing. The clock starts when the payment is made — or, crucially, when you become aware that a payment was made on your behalf.

Cyber incidentsystems hit
Extortion demand
Payment madeby you or a third party
72h
clock starts
Report lodgedcyber.gov.au

The 72-hour clock also starts the moment you become aware a payment was made on your behalf — not just when you pay directly.

Are you captured by the reporting obligation?
Your situationMust report?
Annual turnover above $3M (previous financial year)Yes
Turnover below $3M, not critical infrastructureNo
Critical infrastructure asset under the SOCI ActYes regardless of turnover
Your cyber insurer paid on your behalfYes still your obligation
An incident response firm or negotiator paid for youYes
You received a demand but did not payNo under this obligation — NDB or SOCI may still apply

What the report must contain

  1. Your organisation’s details
  2. The entity you are reporting on behalf of, where a third party made the payment
  3. Details of the cyber security incident
  4. Information about the extorting entity and the demand

Non-compliance with the reporting obligation carries a civil penalty under the Act — report promptly rather than testing where that line falls.

The trap most plans miss

When the payment is made on your behalf

Here is the part no competitor page leads with. In a live cyber security incident, the cyber extortion payment to the extorting entity is frequently executed by someone other than the business itself — the cyber insurer, a retained incident response firm, or a professional negotiator acting under instruction.

The reporting obligation still sits with the reporting business entity. It does not transfer to whoever moved the money, and the 72-hour clock runs from the moment you become aware the payment was made. In the chaos of a live cyber security incident, that awareness can arrive days after the event — and the deadline does not wait for your paperwork to catch up.

The practical consequence is specific: your incident response plan must name who confirms that a payment occurred and who is responsible for lodging the report. If that is not written down before an incident, it will not happen inside 72 hours during one.

A separate offence

Paying a sanctioned entity is a criminal offence

Reporting is one exposure. Sanctions are another, and they are more serious. Australia’s autonomous sanctions framework has operated since 2011, and the Minister for Foreign Affairs can designate persons and entities under it. Designated persons face targeted financial sanctions and travel bans.

Making a payment to a designated entity can expose the payer to criminal liability — entirely separately from the reporting obligation. A cyber security incident can originate anywhere in the world, and the group behind it may already be designated — a determination you cannot make reliably under extortion pressure.

Before any payment is contemplated, get advice. Whether an entity is sanctioned is a legal question with criminal consequences — check the position with DFAT guidance and qualified legal counsel, not under deadline pressure alone.

Why disclosure is protected

The limited use obligation: reporting is safer than it sounds

Many businesses stay silent after an incident, fearing that reporting hands regulators a ready-made case against the reporting business entity. The Act is built to counter that fear. The limited use obligation restricts how information you share with government during an incident can be used by regulators, and provides protections around the admissibility of that information against the reporting entity.

The intent is to encourage disclosure rather than punish it — to make it safe to pick up the phone early so the national picture of ransomware activity is accurate.

One caveat matters. Limited use is not immunity. It does not switch off your other obligations: the Privacy Act 1988 and the Notifiable Data Breaches scheme still apply in parallel, and a data breach involving personal information may be separately notifiable. Reporting the payment satisfies that obligation — not every obligation the incident triggers.

Do this now

What your business should do now

None of this requires new technology. It requires knowing where you stand and writing three things down before you need them:

  1. Confirm whether you cross the threshold. Check your annual turnover for the previous financial year, and whether you hold a critical infrastructure asset under the SOCI Act.
  2. Write the reporting step into your incident response plan with a named owner — who confirms a payment occurred, and who lodges the report inside 72 hours.
  3. Confirm with your insurer and any retained IR firm who lodges what. Do not assume the party that pays also reports.
  4. Know where the cyber.gov.au form is before you need it. Bookmark it in the plan; do not go hunting at 2am.
  5. Keep the Cyber Incident Review Board in mind. Post-incident reviews look for systemic lessons — a well-run response is the story you want on record.

Good ransomware protection reduces the odds you ever face this decision. A tested response plan means that if you do, the reporting obligation is handled by design rather than remembered in a panic.

“Most incident response plans read well on paper. The gap we see in a live incident is authority — who is actually allowed to make the call at 2am when the people named in the plan can’t be reached.”
— PIP, from incident response work
Where it sits in the timeline
29 Nov 2024

The Cyber Security Act receives Royal Assent.

30 May 2025

Mandatory ransomware payment reporting commences.

Through 2026

Active enforcement posture as guidance and subordinate rules mature.

FAQ

Common questions

Is it illegal to pay ransomware in Australia?
Paying a ransom is not itself prohibited. However, if the payment goes to an entity designated under Australia’s autonomous sanctions regime, that is a criminal offence. Separately, businesses above the reporting threshold must report the payment within 72 hours.
What is a ransomware payment?
A payment made to an extorting entity in response to a cyber security incident, in order to regain access to systems or data or to prevent their release. It includes payments made on your behalf by a third party.
What is the current cyber security legislation in Australia?
The Cyber Security Act 2024 is Australia’s first standalone cyber security act. It operates alongside the SOCI Act, the Privacy Act 1988 and the Notifiable Data Breaches scheme.
Should you pay the ransom for ransomware?
Australian government guidance is not to pay: payment does not guarantee recovery and it funds the ransomware business model. This post does not constitute legal advice.

This article is general information about the Cyber Security Act, not legal advice. Obligations depend on your circumstances — confirm your position with qualified legal counsel and the primary sources at cyber.gov.au, the Department of Home Affairs and legislation.gov.au.

Incident response

Does your incident response plan name who files the report?

PIP helps Sydney businesses build incident response plans that hold up in the first 72 hours — including the obligations most plans leave out.

Build a response plan
Scroll to Top