Mandatory Ransomware Payment Reporting: A 72-Hour Compliance Guide under the Cyber Security Act 2024
30 July 2026
TechnologySHARE
Since 30 May 2025, organisations with an annual turnover exceeding AUD $3 million have been legally required to report ransomware and cyber extortion payments to the Australian Signals Directorate within 72 hours. The obligation applies regardless of whether the payment was made directly or by a third party on the organisation's behalf — and it runs concurrently with all the other demands of an active cyber incident response.
For most organisations, the 72-hour window is the most operationally pressured period they will experience. This article covers who the obligation applies to, what the reporting timeframe looks like in practice, what the report must contain, and what steps organisations can take now to make compliance achievable when an incident occurs.
Who Must Comply? Mandatory Ransomware Reporting Thresholds for AU Businesses
Australia's mandatory ransomware payment reporting obligation commenced on 30 May 2025 under Part 3 of the Cyber Security Act 2024. The obligation applies when three conditions are all met.
First, the entity must be a reporting business entity — defined as an organisation carrying on business in Australia with an annual turnover exceeding AUD $3 million for the previous financial year, or an entity responsible for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies, regardless of turnover.
Second, the entity must have been impacted by a ransomware or cyber extortion incident, either directly or indirectly.
Third, a ransomware or cyber extortion payment must have been made — either by the entity itself, or by another party on its behalf. The obligation covers both monetary and non-monetary payments, including gifts, services, or other benefits provided in response to an extortion demand.
Two points are worth noting. Organisations that receive a ransom demand but do not pay are not required to report. The obligation applies only when a payment is made. Additionally, where a third party makes a payment on behalf of the reporting entity, the reporting obligation still falls on the reporting entity.
What the 72 hours actually look like — and why preparation matters
The reporting obligation requires a ransomware payment report to be submitted within 72 hours of making the payment, or within 72 hours of becoming aware that a payment has been made on the organisation's behalf. On paper, 72 hours sounds manageable. In practice, it is one of the most compressed and demanding periods an organisation will face.
During that same window, an organisation is simultaneously managing system containment and recovery, coordinating with an incident response provider, notifying insurers and legal counsel, communicating with senior management and potentially the board, assessing whether personal information has been affected — which may trigger a separate obligation under the Privacy Act's Notifiable Data Breaches scheme — and managing operational continuity with systems potentially offline. The information required for the ransomware payment report must be gathered and submitted while all of this is underway.
An organisation that has not prepared its reporting process in advance is unlikely to meet the deadline without significant difficulty. The civil penalty for failing to report is up to 60 penalty units.
What the report needs to cover
The information required in a ransomware payment report is set out in subsection 27(2) of the Cyber Security Act 2024 and section 7 of the Cyber Security (Ransomware Payment Reporting) Rules 2025. The obligation is to report what the entity knows, or is able to find out by reasonable search or enquiry, at the time of making the report.
The report must include the following, where known or obtainable:
About the organisation:
Contact and business details of the entity that made the payment, including ABN
About the incident:
When the incident occurred or is estimated to have occurred
The impact of the incident on the reporting entity
About the demand and payment:
Details of the ransomware or cyber extortion demand, including the amount demanded, the currency or asset type specified, and the payment method requested
Details of the payment made, including the amount, currency or asset type, and how it was made
Details of any communications with the extorting entity
If a third party made the payment:
Details of the third party that made the payment on the entity's behalf
Additional information:
Any other information relating to the cyber security incident that is known or obtainable by reasonable search or enquiry at the time of the report
Practical implications for preparation
Two aspects of this list are worth noting from a preparedness perspective.
First, much of the information — particularly the details of the demand, the payment, and communications with the attacker — will only exist at the time of the incident. It cannot be prepared in advance. This reinforces the importance of preserving all communications and records from the moment an attack is identified, as these will be needed to complete the report within the 72-hour window.
Second, the standard is reasonable search or enquiry — not certainty. Organisations are not expected to know information they cannot reasonably obtain. Where information is unknown at the time of reporting, the report can be submitted with what is known, noting that further information may not be available.
Reports are submitted through the ASD's ReportCyber portal.
Three things to prepare before an incident occurs
The 72-hour reporting window, the parallel demands of incident response, and the need to gather information under pressure all point to the same conclusion: advance preparation is what makes compliance achievable.
1. Build the reporting obligation into the incident response plan
An organisation's incident response plan should explicitly address the ransomware payment reporting obligation. This means documenting, in advance, who is responsible for making the determination that a payment has been made, who is authorised to submit the report to ASD, and what the internal escalation path looks like when an incident occurs. The 72-hour clock starts at the point of payment — not at the point when the organisation has completed its internal review. Response plans that do not account for the reporting obligation will leave teams attempting to locate the reporting form and determine the submission process in the middle of an active incident.
2. Familiarise the team with the ReportCyber portal in advance
The ransomware payment report is submitted through ASD's ReportCyber portal at cyber.gov.au/report-and-recover/report. Relevant staff — including IT, legal, and senior management — should access the portal before an incident occurs to understand what information is required and how the form is structured. Preparing a template that pre-populates the organisation's ABN, contact details, and reporting contact in advance can reduce the time needed to complete the submission under pressure.
3. Check how cyber insurance interacts with the reporting obligation
Where an organisation holds cyber insurance, the policy may provide for the insurer or an appointed incident response provider to manage aspects of the incident — including, in some cases, making a ransomware payment on behalf of the insured. Under the Cyber Security Act, the reporting obligation falls on the reporting business entity, not the third party that made the payment. The 72-hour clock starts when the entity becomes aware that a payment has been made on its behalf — not when the payment was actually made. Organisations should review their insurance policy to understand whether a payment could be made on their behalf, and if so, ensure that notification to the organisation is built into the insurer's incident response process so the 72-hour window is not inadvertently missed.
The ransomware payment reporting obligation is straightforward in its structure: if a covered organisation makes or becomes aware of a payment, a report must be submitted to ASD within 72 hours. The challenge lies in meeting that deadline under the conditions that invariably accompany a ransomware incident.
Organisations that have built the reporting obligation into their incident response plan, familiarised relevant staff with the ReportCyber portal, and understood how their insurance arrangements interact with the reporting requirement are significantly better positioned to comply than those that have not.
For guidance on specific obligations or incident response planning, consult a cyber security or legal adviser, or refer to the Department of Home Affairs and ASD directly.
Official sources:
Department of Home Affairs — Factsheet: Mandatory ransomware and cyber extortion payment reporting
Federal Register of Legislation — Cyber Security (Ransomware Payment Reporting) Rules 2025
Last updated: July 2026
SHARE
