If you pay a ransom, you have 72 hours
Mandatory ransomware payment reporting has been law in Australia since May 2025. The education period is over. Most organisations we speak to still do not know whether it applies to them.
The rule, in one paragraph
Under the Cyber Security Act 2024, an organisation that makes a ransomware or cyber extortion payment — or becomes aware that one has been made on its behalf — must report it to the Australian Signals Directorate within 72 hours. The obligation commenced on 30 May 2025. Failing to report can attract a civil penalty of up to 60 penalty units, currently around $19,800.
Note what the law does not do. It does not make paying a ransom illegal. It does not require you to report the incident itself under this particular provision. It requires you to report the payment, quickly, after it has been made.
Whether it applies to you
Two categories of organisation are caught:
- Businesses carrying on an enterprise in Australia with annual turnover of at least $3 million in the previous financial year.
- Responsible entities for certain critical infrastructure assets, regardless of turnover.
The $3 million threshold does more work than people expect. It is turnover, not profit, and not headcount. A twelve-person engineering consultancy, a single-site medical practice group, a family logistics business, a mid-sized club — a great many organisations that think of themselves as small businesses are comfortably over it.
If you are near the line, the practical answer is to assume you are covered. The cost of being wrong in that direction is a report you did not strictly need to file. The cost of being wrong in the other direction is a penalty during the worst week your organisation has had.
What actually triggers it
The trigger is the payment, and the clock starts when the payment is made or when you become aware one has been made on your behalf. That second limb catches a scenario people rarely plan for: an incident response firm, a broker, an insurer or an offshore parent negotiating and paying while you are managing the outage. You are still the reporting entity, and the clock is still running.
This is worth confirming in writing with anyone who could conceivably pay on your behalf. If your incident response retainer or cyber policy contemplates a third party handling negotiation, establish now who tells whom, and how fast.
What changed in January
The first phase of the regime was deliberately education-first: the emphasis was on helping organisations understand the obligation rather than penalising them for missing it. From 1 January 2026, the Department of Home Affairs moved to an active regulatory posture.
That shift is the reason this is worth your attention now rather than at some future policy review. The obligation has not changed. The consequence of ignoring it has.
Why 72 hours is shorter than it sounds
Three days sounds generous until you have watched an actual extortion event. The payment decision typically happens on day three or four of an incident, in the middle of a recovery effort, with the executive team exhausted and legal counsel, insurers, brokers and an incident response firm all in the conversation.
At that moment nobody is thinking about a statutory reporting clock, and the people who would normally think about it are busy. We have seen organisations handle the technical recovery competently and miss every notification obligation they had, simply because no one owned the task.
It also sits alongside other clocks. Depending on your circumstances you may have obligations to the OAIC under the Notifiable Data Breaches scheme, to a regulator, to your insurer, and under contract to your clients. These have different triggers and different deadlines. The ransomware payment report is one item on that list, not a substitute for it.
What to do before you need it
- Determine whether you are over the threshold and write the answer down. Not a discussion — a recorded position, with the turnover figure and the financial year it came from.
- Name the person who files the report. One named individual, with a named alternate, both of whom know the obligation exists. This is the single highest return item on this list.
- Put the obligation in the incident response plan, not in a compliance register nobody opens during an incident. It belongs on the same page as the recovery steps.
- Agree the notification chain with third parties — insurer, broker, incident response retainer, offshore parent — covering who informs you, and within what period, if a payment is made on your behalf.
- Rehearse it. Add a payment decision to your next tabletop exercise and see whether anyone in the room mentions the 72 hours unprompted. In our experience they usually do not, and finding that out in a meeting room is considerably cheaper.
- Reduce the chance you ever face the decision. Immutable, tested backups are what turn a ransom demand into a recovery timeline. That remains the only strategy that removes the question rather than answering it.
A useful test: ask your executive team who would file the ransomware payment report, and how long they would have. If the room goes quiet, that is the gap — and it costs nothing to close before you need it.
This is general information about a regulatory obligation, not legal advice. If you are facing an extortion event, involve legal counsel and your insurer immediately — sanctions screening and privilege considerations both apply to payment decisions and both sit outside the scope of this article.
The best outcome is never having to decide
Immutable backups with documented recovery objectives and restore testing on a schedule — so an extortion demand is a recovery timeline rather than a payment decision.