Skip to main content
AFSL 222640 · Global Mutual Funds Pty Ltd
Cyber Consultant
{cyber-consultant
ransomware
cyber-security-act-2024

Mandatory Ransomware Payment Reporting in Australia: Cyber Security Act 2024 Obligations for Businesses

Since May 2025, Australian businesses with $3M+ turnover must report ransomware payments to the ASD within 72 hours under the Cyber Security Act 2024.

MyMoney® Editorial27 July 2026 8 min read

Since 30 May 2025, Australian businesses with an annual turnover of $3 million or more have been subject to a new mandatory obligation: if they make a ransomware or cyber extortion payment, they must report it to the Australian Signals Directorate (ASD) within 72 hours. This requirement, introduced by the Cyber Security Act 2024 (Cth), represents a fundamental shift in how Australian organisations must respond to ransomware attacks — and it has significant implications for incident response planning, cyber insurance, and the role of a qualified cyber consultant.

Understanding the Mandatory Ransomware Payment Reporting Obligation

The Cyber Security Act 2024 was passed by the Australian Parliament on 25 November 2024 and received Royal Assent on 29 November 2024. It forms part of the broader Cyber Security Legislative Package, which implements key initiatives from Australia's 2023–2030 Cyber Security Strategy.

The mandatory ransomware payment reporting obligation applies to "reporting business entities" — defined as businesses with an annual turnover of $3 million or more, or those responsible for critical infrastructure assets under the Security of Critical Infrastructure Act 2018 (Cth). If your business falls within this threshold and makes a ransomware or cyber extortion payment, you must notify the ASD within 72 hours of making that payment.

It is important to understand what this obligation does and does not require. There is no obligation to report if your business chooses not to make a payment. The reporting requirement is triggered solely by the act of payment. This is a separate obligation from the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth) — paying a ransom does not satisfy or waive any obligation to report a data breach if personal information was also compromised.

Key Requirements and What Your Report Must Include

When a ransomware payment reporting obligation is triggered, businesses must act quickly and accurately. Understanding the reporting requirements in advance — ideally as part of your incident response plan — is essential to meeting the 72-hour deadline under pressure.

  • 72-hour reporting window — The report must be submitted to the ASD within 72 hours of making the ransomware or cyber extortion payment. This clock starts from the moment of payment, not from when the incident was first detected.
  • Reporting channel — Reports are submitted through the ASD's ReportCyber portal (cyber.gov.au). Businesses should register for and test access to this portal before an incident occurs.
  • Information required — The report must include details about the nature of the cyber security incident, the payment made (including amount and method), and information about the threat actor where known. The ASD may follow up with requests for additional information.
  • Limited use protections — Information voluntarily shared with the ASD during a cyber incident is subject to "limited use" protections under the Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024. This means the information cannot be used for regulatory enforcement purposes, encouraging businesses to engage openly with the ASD.
  • Penalties for non-compliance — Failure to comply with the mandatory ransomware payment reporting requirement may result in civil penalties. Businesses should treat this obligation with the same seriousness as other regulatory reporting requirements.

Common Mistakes and Misconceptions About Ransomware Reporting

The ransomware payment reporting obligation is new, and many Australian businesses are not yet fully prepared to comply. Cyber consultants are already identifying a range of common mistakes and misconceptions that could expose businesses to regulatory risk.

  • Assuming the obligation only applies to large corporations — The $3 million turnover threshold captures a very large number of Australian SMEs, not just large enterprises. Many businesses that consider themselves "small" will be subject to this obligation.
  • Confusing ransomware reporting with NDB reporting — These are two separate obligations with different triggers, timelines, and regulators. A ransomware payment must be reported to the ASD within 72 hours; a notifiable data breach must be reported to the OAIC within 30 days of becoming aware of the breach. Both may apply to the same incident.
  • Not having a pre-approved payment decision process — The 72-hour reporting window is extremely tight. Businesses that have not pre-determined their decision-making process for ransomware payments — including who has authority to approve a payment and who is responsible for lodging the report — will struggle to comply under the stress of an active incident.
  • Failing to engage a cyber consultant before an incident — Incident response is not the time to be finding and briefing a cyber consultant for the first time. Businesses should have a pre-established relationship with a qualified cyber consultant who understands their systems, their obligations, and the reporting process.
  • Overlooking cyber insurance implications — Many cyber insurance policies have specific notification requirements that must be met before a ransom payment is approved. Failing to notify your insurer in time can void coverage. A cyber consultant can help you understand and coordinate these obligations.

Australian Regulatory Context: ASD, OAIC, and the Cyber Security Act 2024

The ransomware payment reporting obligation sits within a rapidly evolving Australian cyber security regulatory framework. Understanding the key regulators and their respective roles is essential for compliance.

The Australian Signals Directorate (ASD) is the primary cyber security agency for the Australian Government. It administers the ransomware payment reporting obligation and operates the ReportCyber portal. The ASD also publishes the Essential Eight Maturity Model, the Annual Cyber Threat Report, and a range of guidance materials for businesses of all sizes.

The Office of the Australian Information Commissioner (OAIC) administers the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth). If a ransomware attack results in unauthorised access to or disclosure of personal information that is likely to cause serious harm, the business must also notify the OAIC and affected individuals. The OAIC has broad enforcement powers, including the ability to seek civil penalties of up to $50 million for serious or repeated privacy interferences.

The Cyber Incident Review Board, established under the Cyber Security Act 2024, conducts no-fault, post-incident reviews of significant cyber security events and provides recommendations for mitigation. Participation in these reviews is separate from the mandatory reporting obligation.

For businesses responsible for critical infrastructure assets, additional obligations apply under the Security of Critical Infrastructure Act 2018 (Cth), including mandatory incident reporting to the ASD within 12 hours for critical incidents and 72 hours for other significant incidents. These obligations are separate from and in addition to the ransomware payment reporting requirement.

How a Cyber Consultant Can Help You Prepare and Respond

A qualified cyber consultant plays a critical role in helping Australian businesses prepare for ransomware incidents and meet their reporting obligations. Their value is greatest when engaged proactively, before an incident occurs.

  • Incident response planning — Developing and testing a ransomware-specific incident response plan that includes pre-approved decision-making processes for payment decisions, reporting obligations, and stakeholder communications.
  • Regulatory obligation mapping — Identifying all applicable reporting obligations (ASD, OAIC, APRA, sector-specific regulators) and building these into the incident response plan with clear timelines and responsibilities.
  • ReportCyber registration and testing — Ensuring the business is registered on the ASD's ReportCyber portal and that the relevant personnel know how to submit a report under time pressure.
  • Cyber insurance coordination — Reviewing cyber insurance policy notification requirements and ensuring these are integrated into the incident response plan to avoid inadvertent coverage voidance.
  • Essential Eight implementation — Implementing the ASD's Essential Eight controls to reduce the likelihood and impact of a ransomware attack in the first place. Businesses at Maturity Level 2 or above are significantly less likely to experience a successful ransomware attack.
  • Post-incident review support — Assisting with forensic investigation, remediation, and any engagement with the Cyber Incident Review Board following a significant incident.

Ransomware Readiness Checklist for Australian Businesses

Use this checklist to assess your organisation's readiness for a ransomware incident and the associated reporting obligations. If you cannot answer yes to each item, engaging a cyber consultant should be a priority.

  1. Does your business have a documented ransomware incident response plan that includes the 72-hour ASD reporting obligation?
  2. Is your business registered on the ASD's ReportCyber portal, and do the relevant personnel know how to submit a report?
  3. Have you identified all applicable reporting obligations (ASD, OAIC, APRA, sector regulators) and their respective timelines?
  4. Does your incident response plan include a pre-approved decision-making process for ransomware payment decisions, including who has authority to approve a payment?
  5. Have you reviewed your cyber insurance policy to understand notification requirements and how they interact with the ASD reporting obligation?
  6. Has your business implemented the ASD's Essential Eight controls to at least Maturity Level 2?
  7. Do you have a pre-established relationship with a qualified cyber consultant who can provide immediate support during an incident?

How MyMoney® Can Help You Find the Right Cyber Consultant

Preparing for ransomware incidents and meeting Australia's new mandatory reporting obligations requires specialist expertise. A qualified cyber consultant can help your business build the right incident response capabilities, implement preventive controls, and navigate the regulatory landscape with confidence.

MyMoney® connects Australian businesses with experienced cyber consultants who specialise in incident response planning, Essential Eight implementation, and regulatory compliance. Whether you need help preparing for the Cyber Security Act 2024 obligations, reviewing your cyber insurance arrangements, or responding to an active incident, our marketplace makes it easy to find the right professional.

Post a Brief to describe your cyber security needs and receive proposals from qualified consultants, or Browse Cyber Consultants to find professionals with ransomware response and regulatory compliance expertise. All information on this platform is general in nature and does not constitute legal, financial, or cyber security advice. Always engage a qualified professional for advice specific to your circumstances.

This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).

Need Professional Help?

Post a brief and let verified professionals compete with transparent, scored proposals.