Mandatory Ransomware Reporting: Your Obligations
A New Era of Mandatory Reporting
In November 2024, the Australian Government passed the Cyber Security Act 2024, introducing the country’s first mandatory ransomware payment reporting obligation. If your business has an annual turnover exceeding $3 million and you make a ransomware payment — or someone makes one on your behalf — you are now legally required to report it to the Australian Signals Directorate (ASD) within 72 hours.
This is not optional. It is not a recommendation. It is law, and non-compliance carries real consequences. For Australian SME owners and managers, understanding these obligations is now a critical part of running a business.
Why Was This Law Introduced?
The Australian Government estimates that ransomware costs the Australian economy approximately $2.59 billion per year. Yet until this legislation, there was no requirement to report ransom payments. The government had limited visibility into how many organisations were paying, how much they were paying, and to whom.
The mandatory reporting regime serves several purposes:
- Intelligence gathering: The ASD needs accurate data on ransomware payments to understand the threat landscape and develop better defences.
- Disrupting criminal business models: Transparency makes it harder for ransomware operators to operate in the shadows.
- Informing policy: Data on payment volumes and amounts helps shape future regulation and support programs.
- Protecting other businesses: Reports can help identify attack patterns and warn potential victims before they are hit.
Who Does It Apply To?
The reporting obligation applies to any entity that is a responsible entity for a critical infrastructure asset under the Security of Critical Infrastructure Act 2018, or any business or organisation with an annual turnover of $3 million or more. This turnover threshold captures a significant number of Australian SMEs.
If your business sits below the $3 million threshold, you are not currently subject to the mandatory reporting requirement. However, voluntary reporting to the ASD via ReportCyber is still strongly encouraged and can help the broader Australian business community.
Does It Apply to Payments Made by Third Parties?
Yes. If a cyber insurance provider, incident response firm, or any other party makes a ransom payment on your behalf, the reporting obligation still falls on you as the impacted entity. You cannot outsource your compliance responsibilities.
What Must Be Reported?
Within 72 hours of making a ransomware payment (or becoming aware that a payment was made on your behalf), you must submit a report to the ASD that includes:
- Your organisation’s details (name, ABN, contact information)
- The amount of the ransom payment and the currency used (including cryptocurrency details)
- The method of payment and any wallet addresses or transaction identifiers
- Details of the ransomware attack, including the type of ransomware (if known)
- The impact on your business operations
- Any demands or communications received from the attacker
- Whether you engaged law enforcement or incident response services
Importantly, information provided under this regime benefits from a limited use obligation. The ASD can use it for cyber security purposes but cannot share it with other regulators to take enforcement action against you. This “safe harbour” provision was specifically designed to encourage honest reporting without fear of regulatory pile-on.
Penalties for Non-Compliance
Failure to report a ransomware payment within the required timeframe can result in civil penalties. While the Act does not impose criminal sanctions for non-reporting, the civil penalty provisions are significant and can be enforced by the ASD.
Beyond formal penalties, failure to report may also affect your standing with:
- Cyber insurers: Policies increasingly require compliance with all applicable cyber laws as a condition of coverage. Non-reporting could void your claim. Learn more in our cyber insurance guide for SMEs.
- Customers and partners: If a breach becomes public and it emerges that you failed to report, the reputational damage can be severe.
- The Privacy Commissioner: While the ransomware reporting regime is separate from the Privacy Act obligations, a ransomware incident involving personal data will likely also trigger a Notifiable Data Breach under the Privacy Act.
Practical Steps to Prepare
You do not want to be scrambling to understand your obligations while your systems are encrypted and your business is offline. Preparation is everything.
1. Know Your Turnover Threshold
Confirm whether your business meets the $3 million annual turnover threshold. If you are close to the threshold, plan as though you are covered — turnover can fluctuate and you do not want a gap in your compliance posture.
2. Build Ransomware Reporting Into Your Incident Response Plan
Your incident response plan should include a specific section on ransomware reporting obligations. Document who is responsible for making the report, what information needs to be gathered, and the 72-hour deadline. Assign a backup person in case the primary contact is unavailable during an incident.
3. Understand the Reporting Process
Familiarise yourself with the ASD’s reporting portal before an incident occurs. Know the URL, have login credentials ready, and understand what fields need to be completed. Under pressure, even simple administrative tasks become difficult.
4. Brief Your Leadership Team
Ensure that your directors, CEO and CFO understand the reporting obligation. The decision to pay a ransom (which the government does not recommend) and the subsequent reporting requirement are board-level decisions, not purely IT decisions.
5. Engage Your Cyber Insurance Provider
If you have cyber insurance, discuss the reporting obligation with your insurer and broker. Understand how it interacts with your policy terms, particularly around incident notification and claims processes.
6. Invest in Prevention
The best way to avoid the reporting obligation is to avoid paying a ransom — and the best way to avoid paying a ransom is to prevent ransomware from succeeding in the first place. Our ransomware protection guide outlines 10 practical steps every SME should take.
The Bigger Picture
Mandatory ransomware reporting is part of a broader shift in Australia’s approach to cyber security regulation. The Cyber Security Act 2024 also introduced mandatory security standards for smart devices and a voluntary cyber incident review process. Combined with the strengthened Privacy Act and Security of Critical Infrastructure Act reforms, the message from government is clear: cyber security is a business obligation, not an IT afterthought.
Compliance obligations like mandatory reporting sit within the Assurance pillar of the IDIA framework — a framework-independent cybersecurity operating model that organises every control into four pillars: Identity, Data, Infrastructure and Assurance. The Assurance pillar covers governance, risk management, regulatory compliance and continuous improvement — ensuring obligations like the 72-hour reporting window are built into your operating rhythm rather than handled ad hoc during a crisis.
“Ransomware remains the most destructive cybercrime threat facing Australian organisations. Mandatory reporting gives us the intelligence we need to fight back.” — Australian Signals Directorate
Assess Your Readiness
Understanding your obligations is the first step. Taking action is the next. Platforms like How’s My Cyber use the IDIA framework (Identity, Data, Infrastructure, Assurance) to organise every control — including compliance and mandatory reporting readiness — into a clear operating model that works alongside any standard. Start with the free CYBER9 assessment to benchmark your business across nine critical domains in under 10 minutes. No technical expertise required — just honest answers about how your business operates today.
How secure is your business?
Take the free CYBER9 assessment and get your security score in under 10 minutes. No credit card required.
Try CYBER9 Free