Knowledge / practitioner au-compliance IR

Ransomware payment reporting

Cyber Security Act 2024 Part 3. If you pay, or someone pays for you, the clock is 72 hours. ASD takes the form; Home Affairs watches compliance.

Part 3 of the Cyber Security Act 2024 creates a mandatory ransomware and cyber extortion payment report. It is not a ban on paying. It is a report after a payment. Home Affairs guidance says the obligation has been active from 30 May 2025.

You are a reporting business entity if you carry on business in Australia and your annual turnover for the previous financial year is equal to or exceeds AUD 3 million, or if you are a responsible entity for a critical infrastructure asset covered by Part 2B of the Security of Critical Infrastructure Act 2018. State bodies are carved out of the turnover limb. Under AUD 3 million and not SOCI Part 2B means the Act does not force this particular report.

Section 27: give the designated Commonwealth body a ransomware payment report within 72 hours of making the payment, or of becoming aware that another entity made it on your behalf. ASD is the designated Commonwealth body and hosts the form on cyber.gov.au (Ransomware payment and cyber extortion payment reporting). Home Affairs administers the Act and monitors compliance. ASD receives the report; it is not the regulator for this duty.

Report what you know, or can find by reasonable search: who paid, the incident, the demand, the payment, and communications with the extorting entity. Put this clock next to the NDB clock and, if you are in, SOCI cyber incident reporting. Paying does not pause any of those. Paying also does not guarantee recovery. Prefer containment, offline backups, and legal advice before any payment decision.

Practical desk: decide in the IR playbook who can authorise a payment and who files the 72-hour form. Keep the Form URL and the Home Affairs factsheet in the same folder as the NDB checklist. If a third party pays on your behalf, your awareness still starts the clock.

Fact source: ASD's ACSC, ransomware payment and cyber extortion payment reporting.