IronSights

Cyber Security Act 2024

The Cyber Security Act 2024: 72 hours to report a ransom.

Australia's first standalone cyber security Act did four things that matter to businesses: mandatory ransomware payment reporting, limited use of what you tell the government mid-incident, minimum security standards for smart devices, and a no-fault review board. The reporting obligation is the one with a clock on it.

General guidance for Australian businesses, current as at August 2026. It is not legal advice; the law changes and your circumstances matter, so take your own advice before acting.

The obligation with a clock

Report a ransomware payment within 72 hours.

If your business turns over $3 million or more a year, or you are responsible for a critical infrastructure asset, a ransomware or cyber extortion payment must be reported to the Department of Home Affairs within 72 hours of the payment being made, or of you becoming aware that someone made it for you. That includes payments made by an insurer, a broker or a responder acting on your behalf.

The regime started on 30 May 2025. Home Affairs took an education-first approach for the first six months and moved to active compliance from 1 January 2026, so the grace period is over.

Paying is not illegal under this Act. Not reporting is the offence. Payment can still be unlawful under sanctions or proceeds-of-crime law, which is a reason to take advice before you pay.

What the report covers

  • Who you are, and contact details
  • What happened: the incident and the extortion demand
  • The impact on your business
  • Details of the payment: amount, currency and to whom, as far as you know
  • Any information the attacker gave you, including their communications

Keep the ransom note and every message from the attacker. They are evidence for the report, for your insurer, and for working out whether the data-theft claim is even true.

What else is in the Act

Four changes, one of which applies to nearly everyone.

Mandatory ransomware payment reporting

Businesses with annual turnover of $3 million or more (and, separately, entities responsible for critical infrastructure assets) must report a ransomware or cyber extortion payment to the Department of Home Affairs within 72 hours of making it, or of becoming aware one was made on their behalf. In force since 30 May 2025.

Limited use of what you tell government

Information you voluntarily give the National Cyber Security Coordinator during an incident is restricted in how it can be used and shared, so that asking for help does not hand a regulator a case against you. It is a limit on use, not an amnesty: it does not stop regulators obtaining the same facts through their own powers.

Security standards for smart devices

Mandatory baseline security requirements for consumer-grade connectable products supplied in Australia, covering things like default passwords, vulnerability disclosure and a stated security update period. The rules commence 4 March 2026 and bite on manufacturers and suppliers rather than on businesses that merely use the devices.

The Cyber Incident Review Board

An independent, no-fault board that reviews significant incidents after the response is over and publishes lessons. It does not assign blame or determine liability; the point is that the next organisation does not repeat the same failure.

One incident, several clocks

The ransomware report does not replace anything else.

A single ransomware incident at a mid-sized Australian business can trigger all of these at once. Put them side by side in the incident response plan, with a named owner for each.

ObligationWho toWhen
Ransomware payment reportDepartment of Home AffairsWithin 72 hours of the payment
Notifiable data breachOAIC and affected individualsAssess within 30 days; notify as soon as practicable
Incident report (voluntary)ASD's ACSC via ReportCyberAs soon as you can; it is how the ACSC helps
Insurer notificationYour cyber insurerPer the policy, often within 24 to 72 hours
Sector regulatorAPRA, ASIC or others as applicablePer the sector's own rules

The NDB side is covered on the Notifiable Data Breaches page. If you are in an incident right now, start with incident response and ransomware recovery, because whether you need to pay at all is the question worth answering first.

Common questions

Asked and answered.

  1. What is the Cyber Security Act 2024?

    Australia's first standalone cyber security Act, which received royal assent on 29 November 2024. It introduced mandatory ransomware payment reporting, a limited-use protection for information shared with the National Cyber Security Coordinator during an incident, a power to set minimum security standards for smart devices, and the Cyber Incident Review Board. It sits alongside, and does not replace, the Privacy Act and the SOCI Act.

  2. Who has to report a ransomware payment?

    Businesses carrying on business in Australia with an annual turnover of $3 million or more in the previous financial year, plus entities responsible for critical infrastructure assets regardless of turnover. If that is you and you (or someone acting for you, such as an insurer or an incident response firm) pay a ransom or an extortion demand, the report is due within 72 hours of the payment or of you becoming aware of it. Reporting started 30 May 2025.

  3. Does the Act make paying a ransom illegal?

    No. It does not prohibit payment. It requires you to report it. Payment can still be unlawful for other reasons, notably sanctions and proceeds-of-crime law if the recipient is a sanctioned entity, which is one of the reasons to take advice before paying rather than after.

  4. What happens if we do not report?

    Non-compliance attracts civil penalties. Home Affairs ran an education-first approach for the first six months of the regime and moved to active compliance and enforcement from 1 January 2026, so a missed report is now a real exposure rather than a theoretical one.

  5. Is the ransomware report the same as notifying the OAIC?

    No, and one does not satisfy the other. The ransomware payment report goes to the Department of Home Affairs within 72 hours of payment. A Notifiable Data Breach notification goes to the OAIC and to affected individuals if personal information was involved and serious harm is likely. A single ransomware incident routinely triggers both, plus ReportCyber, your insurer and any sector regulator.

  6. What is limited use, exactly?

    A restriction on how information you voluntarily provide to the National Cyber Security Coordinator during a significant incident can be used and onward-shared, so businesses are not deterred from asking for help. It is narrower than legal privilege: it does not prevent regulators using their own powers to obtain the same information, and it does not cover what you say to everyone else.

  7. Do the smart device rules apply to us?

    They apply to manufacturers and suppliers of consumer-grade connectable products supplied in Australia, from 4 March 2026. If you buy and deploy smart devices, the practical effect is that new stock should meet a baseline (no universal default passwords, a vulnerability disclosure channel, a stated support period), which is worth writing into your procurement checklist rather than assuming.

  8. What should we do before an incident?

    Decide now who authorises a payment and who files the report, and put the 72-hour clock in your incident response plan next to the NDB assessment. Keep the attacker communications; they are part of the report. And get advice before paying: sanctions exposure, whether the data is actually recoverable, and whether payment even helps are questions you want answered in advance, not at 2am.

Incident now, or preparing for one?

Do not work out who files the report during the incident.

We build the 72-hour report and the NDB assessment into the incident response plan, with owners and templates, so the clocks are somebody's job before they start running.