30 May 2025
Cyber Security Act 2024 (Cth), Part 3
Mandatory ransomware payment reporting
In forceDepartment of Home Affairs / National Cyber Security Coordinator
Businesses with annual turnover over $3 million, and all critical infrastructure entities, must report any ransomware payment to the Australian Signals Directorate, via the ReportCyber portal, within 72 hours of making the payment or becoming aware one was made on their behalf. Reporting does not legalise the payment; it is a transparency obligation that sits alongside existing OAIC and AUSTRAC obligations.
Who is affected
Australian businesses over $3M turnover and all SOCI-regulated critical infrastructure entities.
What to do
Update incident response plan with the 72-hour reporting clock. Brief board on payment-decision authority.

Remote Support