Author: Dan Briggs | Published: 13 August 2026 | Reading time: 18 minutes
Executive summary: Since 1 January 2026, Australia’s mandatory ransomware payment reporting regime under the Cyber Security Act 2024 has moved out of its “education first” grace period and into active compliance and enforcement, according to the Department of Home Affairs. Any business carrying on operations in Australia with an annual turnover over $3 million now has 72 hours to report a ransomware or cyber extortion payment to the Australian Signals Directorate, with no minimum payment threshold and civil penalties of up to $19,800 for a missed report. Most business owners we talk to know the Notifiable Data Breaches scheme exists. Far fewer know this is a separate, newer obligation, sitting alongside it, with its own regulator, its own clock, and its own paperwork. This whitepaper sets out exactly who is caught, what triggers the duty to report, what a report must contain, and what to put in place before you ever need to use it.
What Changed on 1 January 2026
Australia’s mandatory ransomware and cyber extortion payment reporting obligation, created under Part 3 of the Cyber Security Act 2024, formally commenced on 30 May 2025. For the first six months, the Department of Home Affairs ran what it called an “education first” phase: town halls, guidance sessions and a stated preference to help entities understand the new form rather than penalise them, reserving regulatory action for cases of egregious non-compliance. That phase ended on 31 December 2025.
From 1 January 2026, the Department moved into what it labels a “Compliance and Education Approach.” In plain terms, that means the training wheels are off. The Department has said it will take a more active regulatory focus as the regime matures, backed by more detailed guidance built from the feedback it gathered during Phase 1. For any business that hasn’t yet worked out whether this obligation applies to it, that shift is the reason to do it now rather than after an incident, when a missed 72-hour window is no longer theoretical.
This sits inside a broader pattern. The Australian Signals Directorate’s Annual Cyber Threat Report for 2024–25 recorded more than 84,700 cybercrime reports nationally, roughly one every six minutes, with ransomware accounting for 11% of all reported incidents and over a third of ransomware victims having stolen data posted online regardless of whether they paid. The reporting regime exists because the government wants visibility into a threat it has historically had almost none of: how many Australian businesses are quietly paying ransoms, to whom, and how much it’s costing the economy.
Who Actually Has to Report: The $3 Million Test
A business is a “reporting business entity” under the Act if it meets either of two tests, according to the Department of Home Affairs’ official factsheet on the obligation. The first is familiar: entities responsible for a critical infrastructure asset under Part 2B of the Security of Critical Infrastructure Act 2018, covering sectors like energy, water, health, transport and communications. The second test is the one that catches most businesses off guard: any entity carrying on business in Australia with an annual turnover exceeding $3 million in the previous financial year.
There is no sector carve-out on that second test. It doesn’t matter whether you’re a law firm, a hospitality group, a regional freight operator, a not-for-profit running fee-for-service programs, or an accounting practice. If your turnover was over $3 million last financial year, you’re captured. The Department’s factsheet even sets out a pro-rata formula for businesses that only traded for part of the previous financial year: multiply $3 million by the number of days you traded, divided by 365. A business that traded for 73 days and turned over $1.2 million in that window would have an effective threshold of $600,000, not $3 million, because the formula scales the threshold down, not the turnover.
The test is turnover, not sector. A 40-person accounting firm, a hospitality group running three venues, or a regional transport company can all be “reporting business entities” under the Cyber Security Act, with no connection to critical infrastructure whatsoever.
Not-for-profits are not explicitly exempt either. A charity or membership body with $3 million or more in annual turnover, including grant revenue and fee income in many structures, meets the same test as a private company. We’d encourage any not-for-profit finance team reading this to check their turnover against the threshold rather than assume the obligation is aimed at someone else.
What Counts as a Reportable Payment
The obligation is only triggered once four things line up, per the Act and the Department’s guidance: a cyber security incident has occurred, is occurring, or is imminent; that incident has had, is having, or could reasonably be expected to have a direct or indirect impact on your business; an extorting party has made a demand connected to that impact; and your business, or someone acting on your behalf, provides a payment or benefit directly related to that demand.
A few details matter here that are easy to miss. There is no minimum payment threshold. Whether you pay $500 or $500,000, if it meets the criteria above, it’s reportable. The definition of “payment” is also wider than a bank transfer: it explicitly includes non-monetary benefits, such as goods, services or other value handed over to an extorting party. If a ransom demand is paid using cryptocurrency purchased through a third party, or negotiated down and settled through an intermediary, that still counts, and the third party’s involvement doesn’t remove your obligation to report.
You are not required to report a demand that was made but never paid. If an attacker threatens you and you refuse, walk away, and restore from backup instead, there’s nothing to report under this scheme. The obligation is specifically about payment, not about being targeted. Physical extortion threats and pure scam-related attacks (as opposed to a genuine cyber security incident) also sit outside this scheme, though the Department encourages reporting those separately through Scamwatch or voluntarily through the Australian Cyber Security Centre.
One scenario the factsheet spells out is worth flagging for any Australian business that relies on an overseas parent, cloud vendor or software-as-a-service provider: if that overseas entity is compromised and the incident has a direct impact on your Australian operations, and a payment is made on your behalf as part of resolving it, you are the reporting business entity, and the clock starts when you become aware the payment was made, not when it happened.
The 72-Hour Clock: What You Must Report and How
You have 72 hours from the time you make a ransomware or cyber extortion payment, or from the time you become aware a payment has been made on your behalf, to lodge a report with the Australian Signals Directorate through the Australian Cyber Security Centre’s online portal. That’s a short window, and it starts regardless of whether your incident response is finished, your board has met, or your insurer has signed off.
Under section 7 of the Cyber Security (Ransomware Payment Reporting) Rules 2025, a report needs to include, where reasonably known:
- Your business’s contact details and Australian Business Number.
- Details of the incident itself: when it occurred, when you became aware of it, and its impact on your business and your customers.
- The type of ransomware or malware used and the vulnerability it exploited, if known.
- The extorting entity’s demand, including the amount or benefit sought and the method requested.
- The payment actually made, including amount and method.
- A summary of communications and any pre-payment negotiation with the extorting party.
That’s a meaningful amount of detail to pull together inside 72 hours if you’re assembling it from scratch mid-incident. Businesses that have already mapped out who owns incident response, where logs live, and who has authority to authorise a payment get through this step far faster than those working it out for the first time under pressure.
One point of reassurance: information submitted in a report is tightly protected under Part 3 of the Act. It can generally only be used to help you respond to the incident, to support intelligence agency functions, or to inform government ministers, and by default it is not admissible in court or usable for regulatory enforcement action outside the Act itself. The regime is built to collect intelligence on the threat landscape, not to create a paper trail for prosecuting the victim.
Penalties, and Why the Fine Isn’t the Real Risk
Failing to lodge a report within the 72-hour window carries a civil penalty of up to 60 penalty units, currently $19,800, according to the Department’s factsheet and confirmed by legal commentary from firms including MinterEllison. For a business with a turnover of $3 million or more, that figure alone is unlikely to be the deciding factor in whether you take the obligation seriously.
The more material risk is what a missed report signals during a later review. Cyber insurers are increasingly asking about regulatory compliance history as part of underwriting and claims assessment. Boards and directors face their own separate obligations around cyber governance under frameworks like the AICD’s Governing Through a Cyber Crisis, and an unreported ransomware payment sitting in a board pack six months after the fact is a governance failure a director cannot delegate away. If your business supplies government agencies, banks or larger enterprise clients, an undisclosed ransomware payment discovered during a supply chain security review can end a commercial relationship faster than the incident itself did.
Why This Is Not the Same as Your OAIC Data Breach Obligation
In the conversations we have with clients after an incident, this is consistently the point of confusion, and it’s worth being direct about it: the ransomware payment reporting obligation under the Cyber Security Act is a completely separate duty from the Notifiable Data Breaches scheme administered by the Office of the Australian Information Commissioner.
They are triggered by different things, run on different clocks, go to different regulators, and one can apply without the other. The NDB scheme is triggered by unauthorised access to or disclosure of personal information that is likely to result in serious harm, and it requires notification to the OAIC and affected individuals as soon as practicable, generally within 30 days of becoming aware of an eligible breach. The ransomware payment reporting duty is triggered by the act of paying a ransom or cyber extortion demand, regardless of whether any personal information was involved, and it goes to the Australian Signals Directorate within 72 hours.
Run the scenarios through and the overlap becomes clear. A business that pays a ransom after an incident involving customer data has two separate reports to file, to two different bodies, on two different timelines. A business that pays a ransom to unlock encrypted operational files, with no personal information exposed, still has to make the 72-hour ransomware payment report, even though the NDB scheme was never triggered at all. OAIC data reported earlier this year shows 1,205 data breach notifications were lodged in 2025, a record high, and professional and financial services firms were among the fastest-growing categories. Very few of the ransomware incidents behind those notifications will have generated a matching Cyber Security Act report if the business paid and didn’t realise a second, separate obligation existed.
If your incident response plan currently has a single line that says “notify OAIC if required,” it needs a second line for this obligation, with its own owner, its own portal, and its own 72-hour trigger.
The Regional Blind Spot: Central West NSW and the $3 Million Threshold
We work with businesses across Sydney, Brisbane, Melbourne and Central West NSW, and the $3 million turnover test lands very differently depending on where a business sits. A Sydney CBD professional services firm generally has legal counsel on retainer and a reasonable chance someone has already flagged this obligation. A regional business in Orange, Bathurst or Dubbo turning over $4 or $5 million a year, running a freight and logistics operation, an agribusiness processing plant, a building products distributor, or a multi-site aged care or allied health provider, very often does not have that same access to specialist advice, and doesn’t think of itself as the kind of business a cyber security law was written for.
That’s the gap we see most often in Central West NSW: businesses well above the $3 million threshold, sometimes by a wide margin, who correctly assume the Security of Critical Infrastructure Act doesn’t apply to them because they’re not a utility or a hospital, and incorrectly conclude from that, that no federal cyber reporting duty applies to them at all. The turnover test doesn’t care about your industry. A regional transport company or a rural retailer with $6 million in annual sales is captured on exactly the same basis as a Sydney fintech, even though one has a compliance team and the other has a bookkeeper and an IT contractor who comes in when something breaks.
This matters in practice because regional businesses are frequently the softer target. Attackers increasingly assume that smaller regional operations run thinner IT security and are less likely to have tested backups or a documented incident response plan, which raises the odds a regional business ends up in a position where paying a ransom looks like the only fast way back online. If that happens, the 72-hour clock starts exactly the same way it would for a Sydney or Melbourne business, without the benefit of an in-house legal team to catch it.
Your Action Checklist for the Next 30 Days
The single most useful thing you can do about this obligation is decide, in advance, who owns it and what “reportable” means for your business, so nobody is reading the legislation for the first time mid-incident.
| Action | Why it matters | Who should own it |
|---|---|---|
| Confirm your turnover against the $3 million test | Establishes whether the Act applies to you at all, including pro-rata rules for a partial trading year | Finance / CFO |
| Add a specific line to your incident response plan for the Cyber Security Act obligation | Keeps the 72-hour ransomware payment report distinct from your OAIC/NDB notification step | IT provider / risk owner |
| Identify who has authority to approve a ransom payment and who lodges the ASD report | Removes ambiguity about ownership during a live incident, when speed matters most | Board / executive team |
| Confirm your cyber insurance policy references this obligation | Some insurers now expect regulatory reporting compliance as a condition of claims support | Insurance broker |
| Brief your board on the distinction between NDB notification and ransomware payment reporting | Directors carry personal governance exposure for cyber incident response readiness | Company secretary / board |
| Bookmark the ASD reporting portal and the Ransomware Playbook before you need them | Saves critical time inside the 72-hour window during an actual incident | IT provider |
None of this replaces good prevention. The most effective way to avoid ever needing to file a ransomware payment report is to avoid paying a ransom in the first place, which comes back to the fundamentals: tested, offline backups, multi-factor authentication everywhere, and patched systems. Our breakdown of the three pathways behind almost every small business cyber incident covers exactly where to focus first if you haven’t started.
How All IT Services Helps Clients Prepare
We work with businesses across Sydney, Brookvale and the Northern Beaches, Brisbane, Melbourne and Central West NSW to build cyber incident response plans that name this obligation explicitly, rather than leaving it as a generic “notify the relevant authorities” line. That means confirming whether your business meets the turnover test, working through your existing plan with your leadership team to allocate ownership of the 72-hour reporting duty, and making sure your board understands where this sits alongside your existing privacy and data breach obligations. For a deeper look at director-level obligations during a cyber incident, see our guide to the Governing Through a Cyber Crisis framework, and for the broader compliance picture professional services firms are now navigating, our 2026 compliance and governance playbook covers the Cyber Security Act alongside APRA CPS 230 and the Privacy Act reforms in one place.
We’re also seeing more businesses ask us to stress-test their incident response plan against this specific scenario as part of a broader review, prompted by the same RSM Australia research we covered here in July, which found more than a third of Australian organisations faced a ransomware incident last year. If you haven’t tested yours against the current rules, now, in the first full year of active enforcement, is the right time.
Not sure if this obligation applies to your business?
Our team can check your turnover against the threshold, review your incident response plan, and make sure the 72-hour reporting duty has a named owner before you ever need to use it. Call 1300 425 548 or get in touch below.
Frequently Asked Questions
Does the ransomware payment reporting rule apply to my small business?
It applies if your business carried on operations in Australia and had an annual turnover exceeding $3 million in the previous financial year, or if you are responsible for a critical infrastructure asset under the Security of Critical Infrastructure Act 2018. Turnover, not sector or headcount, is the deciding factor for most businesses. If you traded for only part of the previous financial year, a pro-rata formula set out in the Cyber Security (Ransomware Payment Reporting) Rules 2025 applies instead of the full $3 million figure.
Do I have to report a ransom demand even if I don’t pay it?
No. The obligation is triggered by making a payment or providing a benefit to an extorting party, not by receiving a demand. If you refuse to pay and recover another way, such as restoring from backup, there is nothing to report under the Cyber Security Act, though voluntary reporting to the Australian Cyber Security Centre is still encouraged.
Is this the same as notifying the OAIC under the Notifiable Data Breaches scheme?
No, and this is the mistake we see most often. The Notifiable Data Breaches scheme is triggered by unauthorised access to or disclosure of personal information likely to cause serious harm, and it is reported to the Office of the Australian Information Commissioner, generally within 30 days. Ransomware payment reporting is triggered by the payment itself, regardless of whether personal information was involved, and is reported to the Australian Signals Directorate within 72 hours. A single incident can trigger both obligations, one, or neither, and they need separate handling in your incident response plan.
What happens if we miss the 72-hour deadline?
A missed report can attract a civil penalty of up to 60 penalty units, currently $19,800. Since 1 January 2026, the Department of Home Affairs has moved from an education-first approach to an active compliance and enforcement posture, so the practical risk of a missed report being followed up has increased. Beyond the fine, an unreported payment can also affect cyber insurance claims and create governance exposure for directors if it surfaces later.
Where do we actually submit a ransomware payment report?
Reports are lodged through the Australian Signals Directorate’s online reporting portal, accessible via the Australian Cyber Security Centre’s website at cyber.gov.au. It’s worth bookmarking this link and confirming who in your business has authority to lodge a report before an incident occurs, rather than searching for it under pressure inside the 72-hour window.
Sources
- Department of Home Affairs, Factsheet: Mandatory ransomware and cyber extortion payment reporting
- MinterEllison, “Pay and tell: mandatory ransomware payment reporting obligations in force”
- Australian Signals Directorate, Annual Cyber Threat Report 2024–25
- Cyber Security (Ransomware Payment Reporting) Rules 2025, Federal Register of Legislation
