Report ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)
Businesses with turnover over $3M, and critical infrastructure responsible entities, must report any ransomware payment to the Government within 72 hours.
Who must comply
Businesses carrying on business in Australia with annual turnover over $3 million in the previous financial year, and responsible entities for SOCI Part 2B critical infrastructure assets. Not Commonwealth or State bodies.
What triggers it
Making a ransomware or cyber extortion payment (money or any other benefit), or becoming aware that another entity made one on your behalf.
When due
Within 72 hours of making the payment or becoming aware it was made.
Evidence required
Incident response plan with a ransomware decision protocol (who can authorise a payment, legal and sanctions checks); the lodged ransomware payment report and its receipt; incident log recording when the payment was made or became known (to evidence the 72-hour clock); record of communications with the extorting entity.
Max penalty
Civil penalty of 60 penalty units ($21,840) for failing to report (Cyber Security Act 2024 s 27(5)). A court may order a body corporate to pay up to 5 times that amount — $109,200 (Regulatory Powers (Standard Provisions) Act 2014 s 82(5)).
Summary
Part 3 of the Cyber Security Act 2024 requires a "reporting business entity" that makes a ransomware or cyber extortion payment — or becomes aware that one was made on its behalf — to report it to the designated Commonwealth body within 72 hours of making the payment or becoming aware of it (s 27(1)). A reporting business entity is a business carrying on business in Australia whose annual turnover for the previous financial year exceeds the turnover threshold (set at $3 million by the Cyber Security (Ransomware Payment Reporting) Rules 2025 s 6), or a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies (s 26(2)). Commonwealth and State bodies are excluded. The report covers the incident, the demand, the payment and communications with the extorting entity (s 27(2)), and is lodged through the ransomware payment reporting form on cyber.gov.au. Information in a report may only be used or disclosed for permitted purposes (ss 29-30) and does not waive legal professional privilege (s 31). Reporting is a separate duty: it does not make a payment lawful where another law (for example Australian sanctions law) prohibits it.
Enforced by
Source legislation
Topics
Related
- CWLTHComply with Australian sanctions law + screening (DFAT)Australian sanctions law prohibits dealings with designated persons + entities. Screening required.
- CWLTHNotifiable Data Breach (NDB) schemeUnder the NDB scheme, APP entities must notify the OAIC and affected individuals of an eligible data breach likely to cause serious harm — assessed within 30 days.
- CWLTHReport cyber security incidents to ASD (SOCI)Critical infrastructure asset operators must report critical incidents within 12 hours and other incidents within 72 hours.
- CWLTHGovernment cyber incident reporting via ASD ACSCFederal entities + critical infrastructure report cyber incidents to ASD ACSC.
- CWLTHReport serious NDIS incidents to the NDIS CommissionDeath, serious injury, abuse, neglect, unauthorised restrictive practices, and sexual misconduct must be notified.
- CWLTHAdopt Essential Eight Maturity Level 2 (federal subcontractors)Federal government contractors handling OFFICIAL: Sensitive must meet Right Fit For Risk (RFFR) including E8 ML2.
Frequently asked questions
- Who must comply with ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
- Businesses carrying on business in Australia with annual turnover over $3 million in the previous financial year, and responsible entities for SOCI Part 2B critical infrastructure assets. Not Commonwealth or State bodies.
- What triggers ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
- Making a ransomware or cyber extortion payment (money or any other benefit), or becoming aware that another entity made one on your behalf.
- When is ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27) due?
- Within 72 hours of making the payment or becoming aware it was made.
- What is the maximum penalty for ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
- Civil penalty of 60 penalty units ($21,840) for failing to report (Cyber Security Act 2024 s 27(5)). A court may order a body corporate to pay up to 5 times that amount — $109,200 (Regulatory Powers (Standard Provisions) Act 2014 s 82(5)).
- What evidence is required for ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
- Incident response plan with a ransomware decision protocol (who can authorise a payment, legal and sanctions checks); the lodged ransomware payment report and its receipt; incident log recording when the payment was made or became known (to evidence the 72-hour clock); record of communications with the extorting entity.
Source: https://www.cyber.gov.au/report-and-recover/report/ransomware-payment-and-cyber-extortion-payment-reporting. Rules Mate is not a law firm. Always verify against the live regulator source before acting.