Australia Cyber Security Act 2024 (Ransomware Payment Reporting)

Businesses with turnover over AUD 3 million must report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours. Education-first phase ended 31 December 2025; enforcement from 1 January 2026. The Act also created the Cyber Incident Review Board and IoT security standards.

JurisdictionAustralia
CategoryCybersecurity
StatusActive
Effective date
Latest development

Analysis

The Cyber Security Act 2024 (Australia) and associated Cyber Security (Ransomware Reporting) Rules 2024 create mandatory ransomware and cyber extortion payment reporting to the Australian Signals Directorate (ASD) for certain businesses, with strict 72‑hour reporting deadlines, civil penalties, and supporting guidance from the Australian Government and ASD. Key obligations apply from 30 May 2025, with enforcement expected to tighten from 2026 under the Act and Rules.Cyber Security Act 2024 Cyber Security (Ransomware Reporting) Rules 2024 ASD – Ransomware payment reporting page Home Affairs factsheet – ransomware payment reporting

Below is a structured compliance analysis aligned with your requested sections.


Key Requirements

  • Mandatory reporting of ransomware and cyber extortion payments
  • 72‑hour reporting deadline
  • Scope – AUD 3 million turnover and critical infrastructure
  • Information to be included in the report
  • Civil penalties and enforcement
  • Commencement and phased approach
  • Online reporting mechanism

Compliance Challenges

  • Identifying whether an entity is a “reporting business entity”
  • Meeting the 72‑hour reporting deadline
  • Information completeness and “reasonable search or enquiry”
  • Alignment with cyber insurance and incident response practices
  • Fear of reputational impact and regulatory scrutiny

Implementation Best Practices

  • Establish a documented ransomware reporting procedure
  • Map roles and responsibilities
  • Integrate with existing cybersecurity frameworks
  • Develop data capture templates
  • Leverage tools and external resources

Recent Updates

  • Enactment of the Cyber Security Act 2024
  • The Cyber Security Act 2024 was enacted and published on the Federal Register of Legislation, establishing statutory ransomware payment reporting obligations.Cyber Security Act 2024 (Federal Register – full text)
  • The Act introduced new structures for cyber security governance, including powers to make Ransomware Reporting Rules.[Cyber Security Act 2024 (Part 3 – Ransomware payments)](https://www.legislation.gov.au/C2024A00098

Recent developments

  • — Australia’s Home Affairs has moved into the second phase of the mandatory ransomware and cyber extortion payment reporting program under the Cyber Security Act 2024, with more active regulatory enforcement for non‑compliance and fines of up to 60 penalty units (currently A$19,800) for failing to report payments within 72 hours. (source)
  • — An industry analysis notes that businesses covered by the Cyber Security Act 2024 must now report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours, highlighting the Department of Home Affairs’ initial “education first” approach through 31 December 2025 and a shift to more assertive enforcement from 1 January 2026, which is prompting increased compliance planning. (source)
  • — A Home Affairs factsheet on mandatory ransomware and cyber extortion payment reporting under the Cyber Security Act 2024 confirms Phase 2 (from 1 January 2026) as a “compliance and education” phase with a more active regulatory focus as entities become familiar with the regime, signalling heightened scrutiny of reporting practices. (source)
  • — A detailed business guide to the Cyber Security Act 2024 explains the ransomware payment reporting obligation, clarifying that the 72‑hour clock starts when the covered business makes or becomes aware of a ransom payment and noting that civil penalties for non‑reporting have increased to A$21,840 from 1 July 2026, driving board‑level attention to incident response and payment decisions. (source)
  • — The Australian government’s official ransomware and cyber extortion payment reporting page under section 27 of the Cyber Security Act 2024 sets out the online reporting process for “reporting business entities,” including the 72‑hour timeframe and required incident and payment details, reinforcing operational expectations for affected organisations. (source)
  • — A legal insight article explains key parts of Australia’s Cyber Security Act 2024, emphasising that reporting business entities must report any ransomware payment made or discovered within 72 hours and outlining practical steps for compliance, which organisations are using to update playbooks and incident response procedures. (source)
  • — Industry reporting shows that many large Australian companies continue to pay ransomware groups while now being compelled under the Cyber Security Act 2024 to disclose such payments to Home Affairs and ASD, prompting debate over whether mandatory reporting will deter payments or simply improve visibility into the scale of ransomware attacks. (source)
  • — Coverage of the commencement of mandatory ransomware payment reporting rules (effective 30 May 2025) explains that all organisations with annual turnover above A$3 million must report payments within 72 hours via the ASD tool, with cybersecurity experts warning that the regime will significantly affect incident response strategies and cyber insurance negotiations. (source)
  • — An international legal commentary on responding to ransomware highlights Australia’s Cyber Security Act 2024 as a leading example of mandatory payment disclosure, noting concerns from some businesses about reputational risk and regulatory exposure, but also recognising potential benefits in improving national threat intelligence and policymaking. (source)
  • — Guidance for governance professionals on the Cyber Security (Ransomware Reporting) Rules 2024 stresses that the rules commenced on 30 May 2025 and that boards must oversee policies for documenting and reporting ransomware payments, underscoring the growing governance and compliance burden on Australian organisations in the cybersecurity sector. (source)

Related regulations

Put it into practice

Browse all regulations · Compliance deadlines · Latest updates