An Australian business in the middle of a cyber incident can be sitting on three separate reporting obligations at once, owed to three different bodies, on three different timelines. They get treated as one thing constantly, and they are not.
Here is how they actually divide up.
Ransomware payment reporting: 72 hours
Sits under the Cyber Security Act 2024. Applies to businesses carrying on business in Australia with turnover above three million dollars, and to responsible entities for critical infrastructure assets at any turnover.
The trigger is a payment, not an attack. If a payment is made in response to a or extortion demand, by you or by anyone acting on your behalf, it must be reported to the Commonwealth within 72 hours of the payment. The obligation stays with you even when an insurer or negotiator does the paying. Failing to report risks a civil penalty of up to around $19,800.
Enforcement moved from education first to an active posture on 1 January 2026.
Notifiable data breaches: 30 days to assess
Sits under the Privacy Act and goes to the . Applies to most organisations covered by the Act, which includes all private health service providers regardless of turnover.
The trigger is an eligible data breach, meaning unauthorised access to or disclosure of that is likely to result in serious harm. The timing catches people out. You have 30 days to complete an assessment once you become aware there are reasonable grounds to suspect an eligible breach. If you conclude there is one, you must notify the OAIC and affected individuals as soon as practicable, not at the end of the 30 days.
The 30 days is a ceiling on deciding, not a licence to wait.
Critical infrastructure: 12 or 72 hours
Sits under the SOCI Act and goes to the . Applies to responsible entities for assets in the regulated sectors, which now reach well beyond the obvious ones into food and grocery, healthcare, education, data storage and processing, and more.
A cyber incident having a significant impact on the availability of an essential service must be reported within 12 hours. Incidents having a relevant impact but not that significant must be reported within 72 hours. Many organisations captured by these sectors have never checked whether they are a responsible entity, which is the first thing to establish rather than the last.
How they interact
They stack rather than substitute. A ransomware attack on a mid-size private health provider that pays a ransom and loses patient data can owe all three, and satisfying one does nothing for the others.
It is equally possible to owe only one. Paying to decrypt systems with no personal information involved brings the payment report and nothing else. A breach exposing personal data where you refuse to pay brings the OAIC notification and nothing else.
What to do about it now
Work out which of the three you could ever owe, and write it into the with the actual portal and the person responsible. Establish whether you are a responsible entity under SOCI, since that is the one people are most often wrong about. Confirm in writing whether your insurer or incident response provider files on your behalf.
Do this while nothing is happening. At hour 50 of an incident, with systems down and a board wanting answers, nobody should be reading legislation to work out who to call.



