Australia Cyber Security Act 2024 (Ransomware Payment Reporting)
Businesses with turnover over AUD 3 million must report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours. Education-first phase ended 31 December 2025; enforcement from 1 January 2026. The Act also created the Cyber Incident Review Board and IoT security standards.
| Jurisdiction | Australia |
|---|---|
| Category | Cybersecurity |
| Status | Active |
| Effective date | |
| Latest development |
Analysis
The Cyber Security Act 2024 (Australia) and associated Cyber Security (Ransomware Reporting) Rules 2024 create mandatory ransomware and cyber extortion payment reporting to the Australian Signals Directorate (ASD) for certain businesses, with strict 72‑hour reporting deadlines, civil penalties, and supporting guidance from the Australian Government and ASD. Key obligations apply from 30 May 2025, with enforcement expected to tighten from 2026 under the Act and Rules.Cyber Security Act 2024 Cyber Security (Ransomware Reporting) Rules 2024 ASD – Ransomware payment reporting page Home Affairs factsheet – ransomware payment reporting
Below is a structured compliance analysis aligned with your requested sections.
Key Requirements
- Mandatory reporting of ransomware and cyber extortion payments
- Under section 27 of the Cyber Security Act 2024, a “reporting business entity” must report any ransomware or cyber extortion payment it makes, or that is made on its behalf, using the ASD online form.ASD ransomware reporting page Home Affairs ransomware factsheet (PDF) Cyber Security Act 2024 (Federal Register – full text)
- The Act defines “ransomware payment” broadly as a payment or benefit provided to an extorting entity seeking to benefit from a cyber security incident.Cyber Security Act 2024 (s.26–27, definitions)
- 72‑hour reporting deadline
- Reporting business entities must submit a ransomware or cyber extortion payment report within 72 hours of making the payment or becoming aware that a payment has been made on their behalf.ASD ransomware reporting page Home Affairs ransomware factsheet (PDF)
- The Cyber Security (Ransomware Reporting) Rules 2024 clarify that information must be provided to the extent the entity knows or is able, by reasonable search or enquiry, to find out within the 72‑hour period.Cyber Security (Ransomware Reporting) Rules 2024 (CISC PDF)
- Scope – AUD 3 million turnover and critical infrastructure
- Guidance and industry commentary confirm that businesses with annual turnover exceeding AUD 3 million and certain critical infrastructure entities fall within the definition of reporting business entities for these obligations.Gadens – New mandatory ransomware payment reporting obligations now in force Coalition – Australia’s ransomware reporting laws
- The Home Affairs impact analysis and explanatory materials for the Cyber Security Bill 2024 describe captured entities as businesses above a turnover threshold or designated critical infrastructure assets.Parliament of Australia – Cyber Security Bill 2024 bills digest Impact Analysis – Mandatory Ransomware Payment Reporting (PMC)
- Information to be included in the report
- Reports must include information such as:
- identity of the entity making the payment
- identity/description of the extorting entity receiving the payment
- amount and method of payment
- communications with the extorting entity
- details of the cyber incident and impact.Parliament of Australia – Cyber Security Bill 2024 bills digest Home Affairs ransomware factsheet (PDF) Cyber Security (Ransomware Reporting) Rules 2024
- Civil penalties and enforcement
- Failure to submit a report within the required 72‑hour timeframe can attract a civil penalty of up to 60 penalty units under the Act.Parliament of Australia – Cyber Security Bill 2024 bills digest Clyde & Co – Introduction of mandatory ransomware and cyber extortion payment reporting
- The Home Affairs factsheet and legal commentaries emphasise that non‑compliance may result in regulatory enforcement and penalties.Home Affairs ransomware factsheet (PDF) Bellrock Advisory – New ransomware reporting rules explained
- Commencement and phased approach
- The mandatory reporting regime commenced on 30 May 2025, from which date reporting business entities were required to begin using ASD’s reporting form.Gadens – New mandatory ransomware payment reporting obligations Bellrock Advisory – New ransomware reporting rules explained
- Government materials describe an initial education‑first implementation phase, followed by stronger enforcement once entities were expected to have embedded compliance processes.Impact Analysis – Mandatory Ransomware Payment Reporting Home Affairs ransomware factsheet (PDF)
- Online reporting mechanism
- Reports must be made via the ASD online reporting form available on Cyber.gov.au.ASD ransomware reporting form page Home Affairs ransomware factsheet (PDF)
Compliance Challenges
- Identifying whether an entity is a “reporting business entity”
- Many organisations struggle to determine whether their turnover exceeds AUD 3 million or whether they are captured as critical infrastructure under the Cyber Security Act and related rules.Gadens – mandatory ransomware reporting obligations Coalition – Australia’s ransomware reporting laws
- Legal analyses highlight confusion in complex group structures (e.g., subsidiaries vs. consolidated turnover).Clyde & Co – mandatory ransomware reporting Keypoint Law – Mandatory reporting of ransomware and cyber extortion payments
- Meeting the 72‑hour reporting deadline
- Organisations commonly report difficulty in investigating incidents, confirming payments, and assembling required data within the strict 72‑hour window.Home Affairs ransomware factsheet (PDF) Cyber Security (Ransomware Reporting) Rules 2024
- Industry commentary notes challenges in coordinating IT, legal, risk, finance, insurers and incident responders under tight timeframes.Clyde & Co – mandatory ransomware reporting IBA – Responding to ransomware (Australia section)
- Information completeness and “reasonable search or enquiry”
- The Rules only require information the entity “knows or is able, by reasonable search or enquiry, to find out” within 72 hours, but organisations must interpret what is “reasonable” in practice.Cyber Security (Ransomware Reporting) Rules 2024 Impact Analysis – Mandatory Ransomware Payment Reporting
- Legal briefings underline uncertainty about the level of forensic detail expected early in an incident.Bellrock Advisory – New ransomware reporting rules explained Keypoint Law – mandatory reporting rules
- Alignment with cyber insurance and incident response practices
- Many organisations rely on cyber insurance or incident response providers who may negotiate and facilitate payments; ensuring these intermediaries share data required for reporting is a known challenge.Coalition – Australia’s ransomware reporting laws IBA – Responding to ransomware
- Commentary highlights potential friction between insurer confidentiality and statutory reporting obligations.Clyde & Co – mandatory ransomware reporting Gadens – mandatory reporting obligations
- Fear of reputational impact and regulatory scrutiny
- Industry analyses note that organisations may be reluctant to disclose payments due to concerns about reputation, regulatory attention, and potential litigation, despite statutory obligations.Impact Analysis – Mandatory Ransomware Payment Reporting IBA – Responding to ransomware
Implementation Best Practices
- Establish a documented ransomware reporting procedure
- Organisations should design a formal playbook mapping incident discovery, decision‑making on ransom payments, data collection, and submission of the ASD report within 72 hours.ASD ransomware reporting page Home Affairs ransomware factsheet (PDF)
- Legal guidance recommends integrating this procedure into broader incident response plans and business continuity frameworks.Clyde & Co – mandatory ransomware reporting Keypoint Law – mandatory reporting rules
- Map roles and responsibilities
- Clearly assign responsibility for:
- incident detection and classification
- authorisation of any payment
- data collation (technical and financial)
- submission of the ASD report.Home Affairs ransomware factsheet (PDF) Cyber Security (Ransomware Reporting) Rules 2024
- Best‑practice advice from law firms emphasises designating a single accountable owner, often the CISO or risk/compliance function, for the reporting obligation.Gadens – mandatory reporting obligations Bellrock Advisory – reporting rules explained
- Integrate with existing cybersecurity frameworks
- Organisations should align ransomware reporting processes with recognised frameworks such as:
- Australian Government Essential Eight mitigation strategies.ASD Essential Eight guide
- Australian Government Information Security Manual (ISM) for governance and incident response structures.ASD Information Security Manual
- Industry commentary suggests mapping the Act’s obligations to controls in NIST CSF or ISO/IEC 27001, used by many Australian organisations for baseline cyber risk management.Coalition – Australia’s ransomware reporting laws IBA – Responding to ransomware
- Develop data capture templates
- To meet the information requirements under the Act and Rules, organisations can use structured templates that capture:
- incident description, timing and impact
- extorting entity details (if known)
- payment details (amount, method, intermediaries)
- communications with attackers.Home Affairs ransomware factsheet (PDF) Cyber Security (Ransomware Reporting) Rules 2024
- Legal advisories encourage “pre‑population” of form fields and checklists aligned with the ASD online form, to accelerate submission.Clyde & Co – mandatory ransomware reporting Gadens – mandatory reporting obligations
- Leverage tools and external resources
- Use ASD cyber.gov.au resources for ransomware preparedness, including guidance on responding and recovering from incidents.ASD – Report and recover main page ASD – Ransomware guidance (Australia)
- Engage incident response providers and legal counsel familiar with the Cyber Security Act and Rules to ensure compliance is embedded in contracts and runbooks.IBA – Responding to ransomware Clyde & Co – mandatory ransomware reporting
Recent Updates
- Enactment of the Cyber Security Act 2024
- The Cyber Security Act 2024 was enacted and published on the Federal Register of Legislation, establishing statutory ransomware payment reporting obligations.Cyber Security Act 2024 (Federal Register – full text)
- The Act introduced new structures for cyber security governance, including powers to make Ransomware Reporting Rules.[Cyber Security Act 2024 (Part 3 – Ransomware payments)](https://www.legislation.gov.au/C2024A00098
Recent developments
- — Australia’s Home Affairs has moved into the second phase of the mandatory ransomware and cyber extortion payment reporting program under the Cyber Security Act 2024, with more active regulatory enforcement for non‑compliance and fines of up to 60 penalty units (currently A$19,800) for failing to report payments within 72 hours. (source)
- — An industry analysis notes that businesses covered by the Cyber Security Act 2024 must now report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours, highlighting the Department of Home Affairs’ initial “education first” approach through 31 December 2025 and a shift to more assertive enforcement from 1 January 2026, which is prompting increased compliance planning. (source)
- — A Home Affairs factsheet on mandatory ransomware and cyber extortion payment reporting under the Cyber Security Act 2024 confirms Phase 2 (from 1 January 2026) as a “compliance and education” phase with a more active regulatory focus as entities become familiar with the regime, signalling heightened scrutiny of reporting practices. (source)
- — A detailed business guide to the Cyber Security Act 2024 explains the ransomware payment reporting obligation, clarifying that the 72‑hour clock starts when the covered business makes or becomes aware of a ransom payment and noting that civil penalties for non‑reporting have increased to A$21,840 from 1 July 2026, driving board‑level attention to incident response and payment decisions. (source)
- — The Australian government’s official ransomware and cyber extortion payment reporting page under section 27 of the Cyber Security Act 2024 sets out the online reporting process for “reporting business entities,” including the 72‑hour timeframe and required incident and payment details, reinforcing operational expectations for affected organisations. (source)
- — A legal insight article explains key parts of Australia’s Cyber Security Act 2024, emphasising that reporting business entities must report any ransomware payment made or discovered within 72 hours and outlining practical steps for compliance, which organisations are using to update playbooks and incident response procedures. (source)
- — Industry reporting shows that many large Australian companies continue to pay ransomware groups while now being compelled under the Cyber Security Act 2024 to disclose such payments to Home Affairs and ASD, prompting debate over whether mandatory reporting will deter payments or simply improve visibility into the scale of ransomware attacks. (source)
- — Coverage of the commencement of mandatory ransomware payment reporting rules (effective 30 May 2025) explains that all organisations with annual turnover above A$3 million must report payments within 72 hours via the ASD tool, with cybersecurity experts warning that the regime will significantly affect incident response strategies and cyber insurance negotiations. (source)
- — An international legal commentary on responding to ransomware highlights Australia’s Cyber Security Act 2024 as a leading example of mandatory payment disclosure, noting concerns from some businesses about reputational risk and regulatory exposure, but also recognising potential benefits in improving national threat intelligence and policymaking. (source)
- — Guidance for governance professionals on the Cyber Security (Ransomware Reporting) Rules 2024 stresses that the rules commenced on 30 May 2025 and that boards must oversee policies for documenting and reporting ransomware payments, underscoring the growing governance and compliance burden on Australian organisations in the cybersecurity sector. (source)
Related regulations
- Australia Online Safety Amendment (Social Media Minimum Age) Act 2024 — Australia, Active, effective 2025-12-10
- Australia Children's Online Privacy Code — Australia, Upcoming, effective 2026-12-10
- Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft) — Australia, Proposed
- NYDFS Cybersecurity Regulation — New York, Active, effective 2025-11-01
- Law on Cybersecurity of Vietnam — Vietnam, Active
- Austria NIS2 Act — Austria, Upcoming
- Luxembourg NIS2 Transposition — Luxembourg, Active
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
Put it into practice
- Generate the policy: Australian Privacy Act policy generator (generatepolicy.com)
- Buy the policy pack: Australia Privacy Act Compliance Policy (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates