Skip to main content
Rules Mate

Report ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)

Businesses with turnover over $3M, and critical infrastructure responsible entities, must report any ransomware payment to the Government within 72 hours.

highcurrentevent driven

Who must comply

Businesses carrying on business in Australia with annual turnover over $3 million in the previous financial year, and responsible entities for SOCI Part 2B critical infrastructure assets. Not Commonwealth or State bodies.

What triggers it

Making a ransomware or cyber extortion payment (money or any other benefit), or becoming aware that another entity made one on your behalf.

When due

Within 72 hours of making the payment or becoming aware it was made.

Evidence required

Incident response plan with a ransomware decision protocol (who can authorise a payment, legal and sanctions checks); the lodged ransomware payment report and its receipt; incident log recording when the payment was made or became known (to evidence the 72-hour clock); record of communications with the extorting entity.

Max penalty

Civil penalty of 60 penalty units ($21,840) for failing to report (Cyber Security Act 2024 s 27(5)). A court may order a body corporate to pay up to 5 times that amount — $109,200 (Regulatory Powers (Standard Provisions) Act 2014 s 82(5)).

Summary

Part 3 of the Cyber Security Act 2024 requires a "reporting business entity" that makes a ransomware or cyber extortion payment — or becomes aware that one was made on its behalf — to report it to the designated Commonwealth body within 72 hours of making the payment or becoming aware of it (s 27(1)). A reporting business entity is a business carrying on business in Australia whose annual turnover for the previous financial year exceeds the turnover threshold (set at $3 million by the Cyber Security (Ransomware Payment Reporting) Rules 2025 s 6), or a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies (s 26(2)). Commonwealth and State bodies are excluded. The report covers the incident, the demand, the payment and communications with the extorting entity (s 27(2)), and is lodged through the ransomware payment reporting form on cyber.gov.au. Information in a report may only be used or disclosed for permitted purposes (ss 29-30) and does not waive legal professional privilege (s 31). Reporting is a separate duty: it does not make a payment lawful where another law (for example Australian sanctions law) prohibits it.

Enforced by

Source legislation

Topics

cyberransomwareincident-reporting

Related

Frequently asked questions

Who must comply with ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
Businesses carrying on business in Australia with annual turnover over $3 million in the previous financial year, and responsible entities for SOCI Part 2B critical infrastructure assets. Not Commonwealth or State bodies.
What triggers ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
Making a ransomware or cyber extortion payment (money or any other benefit), or becoming aware that another entity made one on your behalf.
When is ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27) due?
Within 72 hours of making the payment or becoming aware it was made.
What is the maximum penalty for ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
Civil penalty of 60 penalty units ($21,840) for failing to report (Cyber Security Act 2024 s 27(5)). A court may order a body corporate to pay up to 5 times that amount — $109,200 (Regulatory Powers (Standard Provisions) Act 2014 s 82(5)).
What evidence is required for ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27)?
Incident response plan with a ransomware decision protocol (who can authorise a payment, legal and sanctions checks); the lodged ransomware payment report and its receipt; incident log recording when the payment was made or became known (to evidence the 72-hour clock); record of communications with the extorting entity.

Source: https://www.cyber.gov.au/report-and-recover/report/ransomware-payment-and-cyber-extortion-payment-reporting. Rules Mate is not a law firm. Always verify against the live regulator source before acting.