What changed, and why it catches you
Australia’s first standalone Cyber Security Act passed in November 2024, and its ransomware payment reporting rules commenced on 30 May 2025[1]. The reporting obligation is broad: any entity carrying on business in Australia with annual turnover of $3 million or more must report, as must every critical infrastructure entity regardless of size. The $3 million threshold brings most of the mid-market into scope.
The trigger is making a ransomware payment, or becoming aware that one was made on your behalf, for instance by your insurer or a negotiator. The deadline is 72 hours, and the report goes to the Australian Signals Directorate through cyber.gov.au[1]. A payment includes money or any other benefit, so handing over data or services also counts.
The penalty and the operational risk
Non-compliance carries a civil penalty of around $20,000[2]. For most affected businesses the operational risk matters more than that fine. The 72-hour reporting step has to be built into the incident response plan before an incident, because working out whether the obligation applies while systems are down costs time the business cannot spare. An education-first phase gave organisations until 31 December 2025 to prepare, and the regulator has been actively enforcing since 1 January 2026[2].
Five clocks, one incident
The new obligation sits on top of the ones that already apply, rather than replacing any of them. A single serious incident at a regulated, listed company can start five separate clocks at once: ransomware payment reporting to ASD, notifiable data breach assessment and notification to the OAIC, critical-infrastructure reporting under the SOCI Act, material-incident notification under APRA CPS 234, and continuous disclosure and directors’ duties obligations to the market. Each has a different deadline and a different recipient.
Obligations like these are hard to untangle once an incident is underway. Mapping them beforehand means no one has to work through five separate regulatory obligations while the systems are still down.
Paying can be a crime
Paying a ransom is not in itself illegal in Australia, but it becomes a criminal offence if the recipient is a sanctioned person or entity, carrying up to 10 years imprisonment[5]. Australia has already done this, sanctioning the Medibank hacker Aleksandr Ermakov in January 2024, so that any dealing with him, including a ransom payment, became an offence. The practical implication is that a board needs to agree its payment stance and a sanctions-screening step in advance, before it is dealing with a live extortion.
What the board should have ready
The threat is still growing. ASD calls ransomware the most disruptive cybercrime threat and assesses that AI is helping attackers move faster and appear more convincing[3]. A 2025 survey found that 64% of attacked firms paid, at an average of about A$711,000, and that the large majority of victims were small and medium-sized businesses[4].
- A named decision-maker for whether to pay, with a nominated backup
- A sanctions-screening step to run before any payment is considered
- The 72-hour ASD reporting step written into the incident response plan, alongside the OAIC, SOCI, APRA, and disclosure obligations that may run in parallel
- A tested position on who speaks to the regulator, the insurer, and affected customers
- A date on the calendar for when this was last rehearsed as a live scenario