Skip to content

Compliance

Mandatory Ransomware Reporting Starts 30 May: What the Cyber Security Act 2024 Asks Of You

From 30 May 2025, ransomware payments must be reported to Home Affairs within 72 hours. Who the duty covers, and what it takes to be ready for it.

9 min read
Jump to section
  1. 01 What the Cyber Security Act 2024 requires
  2. 02 Which businesses have to report a payment
  3. 03 The 72-hour clock, and when it starts
  4. 04 Does the Act change how you prevent ransomware?
  5. 05 Four things to do before 30 May 2025
  6. 06 Where we help you get ready, and where we stop
  7. 07 Primary sources

This is an IT operator’s view of the ransomware payment reporting obligation in the Cyber Security Act 2024, which commences 30 May 2025. It isn’t legal advice or a government-compliance opinion. Whether a particular payment is reportable is your legal advisors’ call. So is who bears the obligation inside a corporate group, and how a report to Home Affairs is worded. We respond to ransomware incidents and help businesses prepare for the reporting obligation. They sign off on the reporting text.

Twenty-eight days from today, a new legal duty starts for Australian businesses above the AUD 3 million annual-turnover threshold. They must report any ransomware or cyber-extortion payment they make within 72 hours. Same obligation on every entity responsible for a critical-infrastructure asset, regardless of turnover. The Cyber Security Act 2024 establishes the reporting regime, and it is the first standalone cyber security statute in Australian federal law. The commencement date is 30 May 2025. Home Affairs has confirmed that Phase 1, through to 31 December 2025, will take an education-first posture, with active enforcement beginning 1 January 2026.

“Education-first” does not mean the obligation is optional. In an ambiguous case during the first seven months, the regulator will prefer guidance over penalty. It reserves penalty action for clearly egregious non-compliance. The obligation itself is live from 30 May. An entity that makes a ransomware payment on 3 June 2025 owes Home Affairs a report within 72 hours. Being the first to test the enforcement posture makes no difference.

For CCP-sized clients, this is genuinely a new regulatory obligation. The AUD 3 million turnover threshold captures almost every firm in our 20-to-250-staff band. We have one or two clients under it, but not many. The controls that reduce the likelihood of ever needing to make a ransomware payment are the controls we already require of every client. What the Cyber Security Act adds is a regulatory layer on top of the incident response. If a payment happens, a 72-hour clock now runs alongside everything else.

What the Cyber Security Act 2024 requires

The Act creates a ransomware payment reporting obligation on specified reporting entities. A payment counts if it is made to restore access to data, to prevent publication, or otherwise to respond to a cyber-extortion demand. The entity that makes one must report it to the Department of Home Affairs within 72 hours. The same 72 hours applies from the moment an entity becomes aware that a payment has been made on its behalf. An insurer or a third-party negotiator, for example.

The report must include specified content:

  • Nature of the cyber-extortion demand.
  • Who the demand came from, to the extent that is known.
  • Details of the payment.
  • Anything else the rules require.

The Department of Home Affairs administers the regime, not the Australian Signals Directorate or the Office of the Australian Information Commissioner. In Phase 2, from 1 January 2026, penalties for non-reporting start at 60 penalty units per contravention. At the current penalty unit value, 60 penalty units is around AUD 19,800.

The reporting is not punitive. The Act’s explanatory materials are clear that the purpose is intelligence, not discipline of the reporting entity. That means understanding the ransomware threat landscape, so Home Affairs and the broader cyber-security community can respond to it. In practice, a report lodged responsibly should not create any additional exposure beyond what the entity already has through the incident itself.

Which businesses have to report a payment

Two categories. Entities responsible for a critical-infrastructure asset under Part 2B of the Security of Critical Infrastructure Act 2018, regardless of size or turnover. And businesses carrying on a business in Australia with annual turnover exceeding AUD 3 million, as measured per the GST Act. The annual-turnover threshold catches the overwhelming majority of mid-market Australian businesses.

For a CCP-sized legal, accounting, construction, health, or mining-services firm, the threshold is almost certainly met. The rarer edge cases are not-for-profits operating below turnover and very small specialist consultancies. Many not-for-profits still exceed the threshold once grant income is counted. For any of our clients, we default to assuming the obligation applies, and confirm only if their turnover genuinely doesn’t reach it.

Exemptions to the reporting obligation

Small businesses under the AUD 3 million threshold are not caught by the turnover test. Entities that are not themselves carrying on business in Australia are outside scope. Beyond those two, the obligation is broad. There is no industry-specific exemption, and none for paying through an insurer or a third-party negotiator. Where an insurer pays, the policy-holder still has the reporting obligation. If a payment is made in connection with an Australian-resident entity’s assets or operations, it is almost certainly reportable.

Insurers, incident-response firms and ransomware negotiators pay on behalf of another entity, and they do not generally bear the primary reporting obligation. That obligation belongs to the entity the payment was made for. A professional adviser should still assume the obligation is their client’s.

The 72-hour clock, and when it starts

A compliant report must reach Home Affairs within 72 hours of the payment being made. The same 72 hours applies from the moment the reporting entity becomes aware of a payment made on its behalf. The clock does not start at the beginning of the incident. It starts when the payment is made. For most incidents that is several days after the incident began. It depends on whether a negotiation happened, and on how the payment was handled.

By then, other clocks are already running. If personal information has been compromised, the Notifiable Data Breaches clock under the Privacy Act runs for 30 days from awareness of the breach circumstances. The cyber-insurance notification clock typically runs 24 to 72 hours depending on the policy. The board or executive-notification clock is usually same-day. So a ransomware payment is the moment several reporting obligations converge at once. Preparing the templates and the response pattern in advance is what separates a controlled report from a scramble.

What goes in the report

The exact field set is defined in the rules being made under the Act. Broadly, the report covers:

  • Who you are: the identity and contact details of the reporting entity.
  • What happened: the nature of the cyber-incident that gave rise to the demand.
  • The demand itself: the threat actor to the extent identifiable, the amount, the currency and the payment channel.
  • The payment: amount, date and payment mechanism.

Home Affairs has published a draft survey-response form and explanatory document indicating the likely content.

For most reporting entities, the report itself is not technically difficult once the incident-response team has the timeline and the payment details together. The hard part is documenting the incident to that standard while the incident is still running. An entity that already has a mature documentation discipline produces a clean report. Improvise the incident response and the reporting at the same time, and both suffer.

Does the Act change how you prevent ransomware?

No. The Act does not create new preventive obligations. It creates a reporting obligation if a payment is made. What reduces the likelihood of needing to pay in the first place has not changed. It is still the Essential Eight controls, identity and access management, incident-response capability, and well-maintained backups with tested restoration.

The Act does create a secondary governance incentive to strengthen prevention. An entity that can produce clean incident documentation will get through the 72-hour clock smoothly. One that is still reconstructing what happened while the clock ticks will produce a report Home Affairs has to come back to.

The Cyber Security Act, the strengthened Privacy Act and the tightening of cyber-insurance underwriting close a set of grace periods that previously applied. A mid-market business that has been deferring investment in detection, response and documentation has fewer reasons to keep deferring it in 2025.

Four things to do before 30 May 2025

  1. Confirm whether the obligation applies to you, by the turnover threshold or by a critical-infrastructure connection.
  2. Identify the officer or executive who will bear operational accountability for reporting if an incident occurs.
  3. Update the incident-response plan to incorporate the 72-hour reporting window, and the decision tree for a payment made through an insurer or a negotiator.
  4. Run a tabletop exercise against a ransomware scenario that reaches the payment decision. The reporting step belongs in the runbook, not discovered during a live incident.

Most entities we work with have the preventive controls in reasonable shape. What they are missing is one specific runbook step. If a payment is made or imminent: trigger the 72-hour Home Affairs reporting process, contact privacy counsel, and engage the insurer. That step does not exist in pre-2024 runbooks, and it has to be added explicitly.

Cyber insurance and the cost of reporting

Most policies we have reviewed through 2024 do not name compliance costs for the new reporting obligation as a covered line item. The advisory and legal costs of preparing a 72-hour report usually come out of the broader incident-response cover within the policy. That cover is usually capped, and the wider incident tends to consume it before the reporting-compliance costs come up. If you are relying on your cyber-insurance policy to fund reporting compliance, confirm the position with your broker rather than assume it.

Where we help you get ready, and where we stop

We don’t draft Home Affairs reports, and we don’t give an opinion on whether a particular payment is reportable. Our work is the IT environment, the detection and response capability, and the incident documentation discipline that make a 72-hour reporting window survivable. During an active incident we are there, supporting the operational response.

For a mid-market client preparing for 30 May 2025, our involvement typically covers three areas.

  • Preventive controls. The Essential Eight baseline, the backup setup including tested recovery from offline or immutable backup, and identity and endpoint hardening. Tested recovery is the technical answer that most reduces the need to pay.
  • Detection and response. The tooling and discipline that lets an incident be reconstructed accurately under time pressure. That means keeping logs for long enough, and endpoint detection and response coverage across the estate. It also means a process that brings legal, executives and the insurer into the response inside hours rather than days.
  • The reporting runbook. Updating the incident-response plan to incorporate the 72-hour Home Affairs window, and running a tabletop that exercises it. The reporting step gets rehearsed before it has to be executed.

Three calls stay with the client’s legal advisors, executives and board. Whether a payment is reportable in law, what exactly goes in the report, and whether to make a payment at all. Our boundary is explicit. We run the machinery. They run the judgement.

The 30 May 2025 date does not care whether preparation has been completed. Incidents do not schedule themselves around planning calendars. Entities that have done the preparatory work in April and May 2025 are going to navigate the first months of the regime cleanly. Wait until the first incident and you will be doing both at once.

Primary sources

Tags compliancecyber-security-actransomwarecyber-extortionhome-affairs
Share LinkedIn Email
See if we're a fit