IronSights
All insights

compliance

You paid the ransom. You now have 72 hours.

Australia's mandatory ransomware payment reporting left its grace period at the end of 2025. Enforcement has been active all year and most businesses still have not heard of it.

By IronSights Editorial, Practitioner team6 August 20263 min read
ByIronSights Editorial6 August 20263 min read

There is a reporting obligation attached to paying a ransom in Australia, and in our experience most businesses that would be caught by it have never heard of it.

The Cyber Security Act 2024 introduced mandatory reporting of and cyber extortion payments from 30 May 2025. The first stretch was deliberately gentle, an education first approach that ran to the end of that year. From 1 January 2026 the Department of Home Affairs moved to an active regulatory posture. That change happened quietly and it has now been in force for seven months.

Who it applies to

Two groups. Businesses carrying on business in Australia with an annual turnover above three million dollars, and entities responsible for critical infrastructure assets regardless of turnover.

The three million dollar threshold catches a lot of organisations that do not think of themselves as regulated. A busy medical centre, a mid-size law firm, a construction company, a logistics operator. If your revenue clears that line, this applies to you.

What triggers it, and the clock

The trigger is a payment, not an attack. If you or someone acting on your behalf makes a payment in response to a ransomware or cyber extortion demand, you have 72 hours from when the payment is made to report it.

Read that phrase again, because it does more work than it looks like. Someone acting on your behalf includes your insurer, your firm, and any negotiator engaged on your account. If they pay, the obligation is still yours. We have seen organisations assume the specialist handling the negotiation also handled the reporting. That assumption is worth checking in writing before you ever need it.

The penalty for not reporting is a civil penalty of up to 60 penalty units, which is currently around $19,800.

This is not the same as notifying a data breach

These two obligations get confused constantly and they are genuinely different.

The ransomware payment report goes to the Commonwealth under the Cyber Security Act and is about the payment. Its purpose is intelligence, giving government a real picture of how much is being paid and to whom. It is not a public disclosure.

The scheme sits under the Privacy Act, goes to the , and is about harm to individuals whose was involved. Different regulator, different trigger, different timeline.

You can easily owe both. You can also owe one and not the other. Paying a ransom to decrypt systems where no personal information was accessed triggers the payment report and not the breach notification. A breach where you refuse to pay triggers the notification and not the payment report.

What to do before it is relevant

Decide now who is responsible for filing, and write it down in the incident response plan next to the names and phone numbers. In the middle of an incident, at hour 50, with systems down and a board asking questions, nobody wants to be working out which regulator wants what.

Ask your insurer and your incident response provider directly whether they file on your behalf or expect you to. Get the answer in the engagement terms rather than in an email during a crisis.

And understand that the reporting obligation is not a reason to pay or not to pay. That decision sits on its own merits. This is simply what follows if you do.

Keep reading

More from the IronSights team.