Why the Cyber Security Act Means Your Ransomware Payments Are Now on the Record

Why the Cyber Security Act Means Your Ransomware Payments Are Now on the Record

If you run a small or medium business in Australia, there is a piece of legislation you need to understand. It has been reshaping how businesses respond to ransomware since May 2025, and the government is now actively enforcing it.

Many business owners still do not know this law exists. That is a real problem, because the penalties for getting it wrong are far higher than most people assume.

This post breaks down what the Cyber Security Act requires, who it applies to, and what you need in place before an incident happens.

What is the actual obligation?

The Cyber Security Act 2024 is Australia’s first standalone cyber security law. It received Royal Assent on 29 November 2024.

Part 3 of the Act introduces a mandatory reporting obligation for ransomware and cyber extortion payments. If your business makes a ransomware or cyber extortion payment, or you become aware that one was made on your behalf, you have 72 hours to report it to the Australian Signals Directorate (ASD).

This obligation commenced on 30 May 2025. The government initially ran an education first approach, giving businesses six months to become familiar with the requirement before pursuing enforcement action. That period ended on 31 December 2025. Since 1 January 2026, the Department of Home Affairs has moved to active compliance and enforcement.

There is no minimum payment threshold, and non-monetary benefits count too. You can read the full breakdown in the Department of Home Affairs factsheet.

What happens if you do not report?

Fail to report within 72 hours, and your business is exposed to a civil penalty of up to 60 penalty units.

Following the scheduled indexation on 1 July 2026, a Commonwealth penalty unit is now worth $364. For a body corporate, a five times multiplier applies under the Regulatory Powers (Standard Provisions) Act 2014. That puts the maximum penalty at $109,200 for a business. An individual reporting entity faces up to $21,840.

That is a meaningful number for any organisation, and it sits on top of the reputational cost of being found non-compliant during a cyber incident.

Who does it apply to?

The obligation applies to you if either of the following is true.

Your business is carrying on business in Australia and had an annual turnover exceeding $3 million in the previous financial year. Or you are a responsible entity for a critical infrastructure asset, regardless of turnover.

The law also applies to third-party payments. If a lawyer, insurer, or incident response firm pays a ransom on your behalf, the 72-hour clock starts from the point you become aware of the payment, not from when they made it.

A protection worth knowing about

One detail in the Act deserves more attention than it usually gets. Under section 32, information you provide in a ransomware payment report cannot be used as evidence against your business in civil or criminal proceedings. There are some exceptions, most notably where the information provided is false or misleading.

This matters, because it removes one of the main reasons business owners hesitate to report. The obligation exists to give government a clearer picture of the ransomware landscape, not to build a case against businesses that come forward in good faith.

What you need ready before an incident

The best time to prepare for this obligation is before you need it.

You need an incident response plan that treats detection, containment, and reporting as one connected process. At least two people in your business should know the reporting process and where to file, so the obligation does not stall while everyone works out whose job it is.

Speed matters here. A 72-hour window disappears quickly once you account for internal escalation, legal advice, and getting the facts straight.

Work with Aryon

At Aryon, we help Australian businesses build stronger cyber defences, prepare for ransomware, and meet obligations like those under the Cyber Security Act.

We can help you understand where you stand, build a response plan that covers your reporting obligations, and reduce the chance you ever need to use it.

Get in touch with us to learn more.

Share this Article!