Who must report ransomware and cyber extortion payments within 72 hours?
The applicability test for Report ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27) (Home Affairs (SOCI) and ASD), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Some businesses
Applies when the business has annual turnover over $3M or a critical infrastructure asset.
What the obligation is
Businesses with turnover over $3M, and critical infrastructure responsible entities, must report any ransomware payment to the Government within 72 hours.
Part 3 of the Cyber Security Act 2024 requires a "reporting business entity" that makes a ransomware or cyber extortion payment — or becomes aware that one was made on its behalf — to report it to the designated Commonwealth body within 72 hours of making the payment or becoming aware of it (s 27(1)). A reporting business entity is a business carrying on business in Australia whose annual turnover for the previous financial year exceeds the turnover threshold (set at $3 million by the Cyber Security (Ransomware Payment Reporting) Rules 2025 s 6), or a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies (s 26(2)). Commonwealth and State bodies are excluded. The report covers the incident, the demand, the payment and communications with the extorting entity (s 27(2)), and is lodged through the ransomware payment reporting form on cyber.gov.au. Information in a report may only be used or disclosed for permitted purposes (ss 29-30) and does not waive legal professional privilege (s 31). Reporting is a separate duty: it does not make a payment lawful where another law (for example Australian sanctions law) prohibits it.
The applicability test
Applies when the business has annual turnover over $3M or a critical infrastructure asset.
How the regulator frames it: Businesses carrying on business in Australia with annual turnover over $3 million in the previous financial year, and responsible entities for SOCI Part 2B critical infrastructure assets. Not Commonwealth or State bodies.
What triggers it: Making a ransomware or cyber extortion payment (money or any other benefit), or becoming aware that another entity made one on your behalf.
Threshold: Annual turnover over $3 million (previous financial year), or a SOCI Part 2B critical infrastructure asset.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (35 of 35: depends on size or structure).
The answer is the same in every industry: depends on size or structure. Industry does not change who must comply.
Business structure and size
Structure does not change the answer across all industries: for every structure the answer is "depends on size or structure".
| Size band | Answer across all industries, any structure |
|---|---|
| No employees (turnover $100K–$1M) | No |
| 1–5 employees (turnover $100K–$1M) | No |
| 6–19 employees (turnover $1M–$3M) | No |
| 20–99 employees (turnover $3M–$10M) | Yes |
| 100–499 employees (turnover $10M–$100M) | Yes |
| 500+ employees (turnover $100M–$1B) | Yes |
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in real estate agents with 20–99 employees, turnover $3M–$10M: applies. Annual turnover over $3 million — a reporting business entity (Cyber Security Act 2024 s 26)
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires annual turnover over $3M or a critical infrastructure asset.
- Pty Ltd company in real estate agents with no employees, turnover $100K–$1M: does not apply. Requires annual turnover over $3M or a critical infrastructure asset.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business operates a critical infrastructure asset: it then applies (responsible entity for a critical infrastructure asset (SOCI Act Part 2B)).
What you must do, and when
- When due
- Within 72 hours of making the payment or becoming aware it was made.
- Frequency
- When a triggering event occurs
- Evidence to keep
- Incident response plan with a ransomware decision protocol (who can authorise a payment, legal and sanctions checks); the lodged ransomware payment report and its receipt; incident log recording when the payment was made or became known (to evidence the 72-hour clock); record of communications with the extorting entity.
- Status
- Current
- Priority
- High
Penalty for not complying
Maximum penalty: Civil penalty of 60 penalty units ($21,840) for failing to report (Cyber Security Act 2024 s 27(5)). A court may order a body corporate to pay up to 5 times that amount — $109,200 (Regulatory Powers (Standard Provisions) Act 2014 s 82(5)).
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
What usually applies alongside it
Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:
- Pay redundancy under NES (s 119 FW Act): applies to 100% of the same businesses (2.0× the overall rate)
- Pay ACT payroll tax when threshold met: applies to 67% of the same businesses (2.0× the overall rate)
- Pay NSW payroll tax when threshold met: applies to 67% of the same businesses (2.0× the overall rate)
- Pay Northern Territory payroll tax when threshold met: applies to 67% of the same businesses (2.0× the overall rate)
- Pay Queensland payroll tax when threshold met: applies to 67% of the same businesses (2.0× the overall rate)
- Pay South Australian payroll tax when threshold met: applies to 67% of the same businesses (2.0× the overall rate)
Where it sits in the corpus
Rules Mate tracks 9 published obligations tagged "cyber", 4 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 0 of those apply outright. This obligation is rated high priority, and is triggered by events.
Regulator, legislation and tools
Regulated by Cyber and Infrastructure Security Centre — Department of Home Affairs and Australian Signals Directorate (Australian Cyber Security Centre).
Home Affairs (SOCI): Administers the Security of Critical Infrastructure Act 2018 — registration, risk management programs, and mandatory cyber incident reporting for critical infrastructure assets.
ASD: Cyber security guidance and incident response. Publishes the Information Security Manual (ISM), Essential Eight, and Right Fit For Risk requirements for federal subcontractors.
- Cyber and Infrastructure Security Centre — Department of Home Affairs
- Australian Signals Directorate (Australian Cyber Security Centre)
Free tools that help with this obligation:
Questions
- Who must report ransomware and cyber extortion payments within 72 hours?
- Applies when the business has annual turnover over $3M or a critical infrastructure asset.
- Do sole traders need to report ransomware and cyber extortion payments within 72 hours?
- Depends on size or structure. Across every industry and every size band, the engine's answer for a sole trader is: depends on size or structure.
- Do businesses with 1–5 employees need to report ransomware and cyber extortion payments within 72 hours?
- No (1–5 employees, turnover $100K–$1M).
- When is "Report ransomware and cyber extortion payments within 72 hours" due?
- Within 72 hours of making the payment or becoming aware it was made.
Related
- Report ransomware and cyber extortion payments within 72 hours (Cyber Security Act 2024 s 27): full obligation detail
- Who must comply: all obligations
- Who must report cyber security incidents to ASD (SOCI)
- Who must comply with Notifiable Data Breach (NDB) scheme
- Who must comply with Australian sanctions law + screening (DFAT)
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.