On this page
The short version
- 01Businesses with annual turnover over $3 million, and critical infrastructure entities, must report ransomware or cyber extortion payments.
- 02The report is due within 72 hours of making the payment, or of becoming aware it was made — including payments made on your behalf.
- 03Reports go to the Australian Signals Directorate via cyber.gov.au, and the information is covered by limited-use protections.
Australia’s first standalone cyber security law, the Cyber Security Act 2024, introduced mandatory reporting of ransomware payments. The obligation has applied since 30 May 2025, yet plenty of business owners still don’t know it exists — and the clock is short.
Who has to report#
The obligation applies to ‘reporting business entities’. In practice that means:
- Businesses with annual turnover of more than $3 million carrying on business in Australia.
- Entities responsible for critical infrastructure assets, whatever their turnover.
Businesses below the threshold aren’t required to report payments, though the Australian Cyber Security Centre still encourages everyone to report cyber incidents.
What triggers it — and the 72-hour clock#
A report is required when a ransomware or cyber extortion payment is made in connection with a cyber security incident affecting your business. It’s due within 72 hours of making the payment, or of becoming aware that a payment was made.
That second part matters: if an insurer, incident response firm or negotiator pays on your behalf, the report is still yours to make.
What goes in the report#
Reports go to the Australian Signals Directorate through the Australian Cyber Security Centre’s online portal on cyber.gov.au. They cover:
- Details of your business
- The cyber security incident and its impact
- The extortion demand
- The payment itself
- Communications with the attacker
Will the report be used against you?#
The law includes limited-use protections. Information in a ransomware payment report can only be used by Commonwealth bodies for specific permitted purposes — such as responding to the incident and intelligence functions — and generally not for civil or regulatory action against your business.
Failing to report can attract a civil penalty of up to 60 penalty units.
How to be ready before you need it#
Seventy-two hours disappears fast in the middle of an incident. The time to prepare is now:
- 01Know whether you’re covered — check your turnover against the $3 million threshold.
- 02Write it into your incident response plan, with a named person responsible for reporting.
- 03Talk to your insurer about how payments and reporting would be handled under your policy.
- 04Remember the other clocks. A ransomware incident may also be a notifiable data breach under the Privacy Act — see our Essential Eight guide.
- 05Make paying unnecessary. Tested, offline backups are the best reason never to face the question.
We help clients write incident response plans and put in the security controls that make ransomware far less likely to succeed in the first place.
Common questions
Do small businesses have to report ransomware payments in Australia?
Only if they’re a reporting business entity — generally annual turnover above $3 million, or responsibility for a critical infrastructure asset. Businesses below the threshold aren’t required to, but reporting incidents to the ACSC is still encouraged.
How long do I have to report a ransomware payment?
72 hours from making the payment, or from becoming aware that a payment was made on your behalf.
Where do I report a ransomware payment?
To the Australian Signals Directorate, through the Australian Cyber Security Centre’s reporting portal on cyber.gov.au.






