Artifact GuideAustraliaRansomware payment threshold and report content

Australia Cyber Security Act Ransomware payment threshold and report content

Under Part 3 of Australia's Cyber Security Act, a reporting business entity must report when it makes, or becomes aware that another entity made on its behalf, a payment or benefit directly related to an extortion demand arising from a cyber security incident.

The ordinary-business limb requires previous-financial-year turnover above $3 million. A separate limb covers responsible entities for critical infrastructure assets to which SOCI Act Part 2B applies.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Questions
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

A report is triggered only when every Part 3 condition is met: the entity is a , a has the required impact, an extortion demand is made, and a directly related payment or benefit is provided. The incident may have occurred, be occurring, or be imminent. The report then has a 72-hour deadline and prescribed content.

Search this module

Find a question or answer quickly

4 of 4 questions
Question 1

When does Australia's Cyber Security Act require a ransomware payment report?

Part 3 applies only where an incident has occurred, is occurring, or is imminent; it is a that has had, is having, or could reasonably be expected to have a direct or indirect impact on a ; an extorting entity makes a demand to benefit from the incident or its impact; and the reporting business entity provides, or knows another entity has provided on its behalf, a payment or benefit directly related to that demand.

The test is narrower than a general label for any digital disruption. Section 9 requires an event covered by the SOCI Act meaning or an unauthorised impairment of electronic communications to or from a computer, plus a listed constitutional connection. For incidents outside the critical-infrastructure-asset and constitutional-corporation limbs, section 26 presumes the event is a cyber security incident if it was probably internet-enabled, probably impaired a computer's connection, or probably seriously prejudiced specified Australian interests. That presumption does not create civil-penalty liability if the relevant condition did not exist in fact.

A is either a responsible entity for a critical infrastructure asset to which of the Security of Critical Infrastructure Act 2018 applies, or an entity carrying on business in Australia whose annual turnover for the previous financial year exceeds the and that is not a Commonwealth body, State body, or responsible entity for a critical infrastructure asset under the other limb.

The 2025 Rules prescribe a $3 million threshold for the previous financial year. Section 26 of the Act says annual turnover must exceed that threshold, so turnover of exactly $3 million does not satisfy the ordinary-business limb. If the business operated for only part of the previous financial year, the Rules prorate the threshold: $3 million multiplied by the number of days the business operated in that year, divided by the number of days in the year. The Act still requires turnover to exceed the resulting amount.

Part 3 and the Reporting Rules commenced on 29 May 2025. Commonwealth bodies and State bodies are excluded from the ordinary-business limb. A responsible entity for a critical infrastructure asset must use the separate limb, which applies only where SOCI Act applies to the asset.

The current cyber.gov.au form describes its ordinary-business option as turnover that is equal to or exceeds $3 million. That wording conflicts with section 26 of the Act, which says turnover must exceed the prescribed threshold. For turnover of exactly $3 million, preserve the calculation and seek confirmation from Home Affairs rather than treating the form label as an amendment to the Act.

  • Scope evidence: entity status at the time of payment, whether it carries on business in Australia, prior-financial-year turnover, any partial-year calculation, and whether it is the responsible entity for a critical infrastructure asset to which applies.
  • Incident evidence: why the event is treated as a and how it directly or indirectly impacted the .
  • Payment evidence: the extortion demand, who paid or provided the benefit, whether the payment was made on behalf of the , and when the entity made the payment or became aware it had been made.
Citations
Cyber Security Act 2024

Sections 9, 26, and 27 support the cyber-security-incident test and limited presumption, the complete payment-report trigger, the requirement for ordinary-business turnover to exceed the prescribed threshold, the separate SOCI responsible-entity limb, 72-hour timing, and report-content categories.

Question 2

What must an Australian ransomware payment report contain within 72 hours?

The must give the a report within 72 hours of making the ransomware payment or becoming aware that another entity made it on its behalf, whichever applies. The Australian Government provides the current reporting form through cyber.gov.au.

The Act requires the report to include information the knows or can find out by at the time of reporting. The report must cover contact and business details for the reporting business entity if it made the payment, or the other entity if another entity paid; the and its impact; the extortion demand; the ; and communications with the extorting entity about the incident, demand, and payment.

The Rules add detail: ABN if any and address for the reporting entity or other payer; when the incident occurred or is estimated to have occurred; when the became aware of it; impacts on infrastructure and customers; ransomware or malware variants; exploited vulnerabilities; response-useful information; the amount or quantum and method demanded; the amount or quantum and method provided, including non-monetary benefits; and the nature, timing, description, and any pre-payment negotiations in communications with the extorting entity.

  • Keep a 72-hour clock record showing whether time started from making the payment or from becoming aware that another entity made it on the 's behalf.
  • Keep a reasonable-search log for report fields that were known, found, estimated, or unavailable within the 72-hour period.
  • Keep the filed report, submission confirmation, incident notes, payment authorization trail, extortion communications, and any later correction or supplemental information together.
Citations
Question 3

Which evidence gaps can undermine a ransomware payment assessment?

An incident-response policy or payment approval note does not establish whether section 27 applies. The record needs the reporting-business-entity analysis, threshold calculation, 72-hour clock, and report-content inventory tied to the Act and Rules.

Do not rely on a generic ransomware playbook to decide whether the Part 3 report is triggered. Preserve the facts that distinguish a non-reportable incident from a reportable : entity status, Australian business activity, turnover, critical-infrastructure responsibility, the demand, the payment or benefit, and awareness that another entity paid on the reporting entity's behalf.

  • Missing threshold proof: no previous-financial-year turnover record, no partial-year formula record, treating turnover equal to $3 million as exceeding the threshold, or no evidence for the critical-infrastructure responsible-entity limb.
  • Missing clock proof: no timestamp for payment, no timestamp for awareness of a payment made by another entity, or no record explaining why the 72-hour period started when it did.
  • Missing report-content proof: no ABN/address details, incident timing and awareness record, customer and infrastructure impact notes, malware and vulnerability findings, demand and payment method details, or extortion-communications log.
Citations
Cyber Security Act 2024

Supports the scope test for a reportable ransomware payment and the report obligation imposed on a reporting business entity.

Question 4

How does the Act protect information in a ransomware payment report?

The Act limits how a and later recipients may use or disclose information obtained through a report. Permitted purposes include helping respond to the incident, administering the reporting regime, government cyber-response functions, National Cyber Security Coordinator functions, ministerial advice, intelligence functions, and specified proceedings about false or misleading information or obstruction.

The protections are qualified. They do not stop use for enforcing Part 3 or laws that impose a penalty or sanction for a criminal offence, and they do not cover information to the extent a body obtained it through another route. Providing information in the report does not otherwise affect a legal professional privilege claim, subject to the statutory exceptions for coronial inquiries, Royal Commissions, and specified federal-court proceedings.

Section 32 also restricts admissibility of report information held by a Commonwealth or State body against the in listed proceedings, with exceptions. Treat these provisions as limits on specified use and admissibility, not as secrecy, immunity from the reporting duty, or a guarantee that the underlying facts cannot be obtained elsewhere.

  • Separate the filed report from evidence collected independently so the source of each item remains clear.
  • Mark privileged material by reference to the applicable privilege analysis; filing does not create privilege for material that was not privileged.
  • Do not omit or delay required information on the assumption that the report creates a general immunity. Failure to give the section 27 report is a civil-penalty contravention, while sections 29 and 32 preserve specified exceptions for false or misleading information and obstruction proceedings.
Citations
Cyber Security Act 2024

Sections 29 to 32 set the permitted-use, secondary-use, privilege, and admissibility rules and their exceptions.

Primary sources

References and citations

legislation.gov.au
Referenced sections
  • Sections 29 to 32 set the permitted-use, secondary-use, privilege, and admissibility rules and their exceptions.
"Ransomware payment reports may only be used or disclosed for permitted purposes"
legislation.gov.au
Referenced sections
  • Supports the responsible-entity limb for critical infrastructure assets that are brought into the ransomware reporting test.
"Security of Critical Infrastructure Act 2018"
Related guides

Explore more topics

Australia Compliance Statement Evidence Workflow
Evidence workflow for preparing, supplying, and retaining statements of compliance under Australia's Cyber Security Act 2024 and Smart Devices Rules.
Australia Cyber Security Act 2024 scope and definitions
Official source scope guide for Australia's Cyber Security Act 2024: relevant connectable products, consumer-grade smart devices, reporting business entities, ransomware payment reports, and SOCI overlap.
Australia Cyber Security Act and SOCI Act overlap
How the Australia Cyber Security Act overlaps with the Security of Critical Infrastructure Act for responsible entities, ransomware payment reporting, smart devices, and evidence records.
Australia Cyber Security Act Applicability Test
Decide whether the Australia Cyber Security Act 2024 applies to a smart-device product, supplier, manufacturer, or ransomware payment reporting scenario.
Australia Cyber Security Act Commencement Timeline
Cyber Security Act 2024 commencement timeline for ransomware reporting, CIRB reviews, smart-device duties, statement retention, and statutory review.
Australia Cyber Security Act Compliance Checklist
Concrete checklist items for Australian Cyber Security Act smart-device and ransomware duties, with SOCI and APRA CPS 234 evidence checks.
Australia Cyber Security Act Compliance Guide
A cited compliance guide for Australia Cyber Security Act smart-device statements, ransomware payment reporting, incident coordination, and review-board readiness.
Australia Cyber Security Act Deadlines and Calendar
Cyber Security Act 2024 dates and event-driven deadlines for ransomware payment reports, smart-device duties, records, notices, and statutory review.
Australia Cyber Security Act FAQ
Answers to Australia Cyber Security Act questions on smart device scope, statements of compliance, ransomware reports, enforcement notices, and incident review.
Australia Cyber Security Act penalties and fines
Cyber Security Act 2024 civil penalties explained by section, including ransomware reports, protected information, CIRB notices, and smart-device enforcement.
Australia Cyber Security Act recordkeeping FAQ
What records to keep for Cyber Security Act 2024 smart-device statements, ransomware payment reports, and supported SOCI or APRA overlap checks.
Australia Cyber Security Act Requirements
Australia Cyber Security Act requirements for smart-device security standards, statements of compliance, ransomware payment reports, notices, and evidence records.
Australia Cyber Security Act Statement of Compliance Evidence
Evidence guide for Australia Cyber Security Act smart-device statements of compliance: required fields, manufacturer and supplier records, five-year retention, and examination readiness.
Australia Cyber Security Act templates
Source-backed field lists for Australia Cyber Security Act smart-device scope, statements of compliance, ransomware reports, notices, SOCI overlap, and records.
Australia Cyber Security Act vs EU Cyber Resilience Act
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Australia Cyber Security Act vs UK PSTI Act Guide
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
Australia ransomware payment reporting 72-hour duty
Explain when Australia's Cyber Security Act 2024 requires a ransomware payment report, when the 72-hour clock starts, and what information the report must contain.
Australia Ransomware Payment Reporting Workflow
Operational workflow for Australia Cyber Security Act 2024 ransomware payment reports: scope, 72-hour trigger, report fields, owners, evidence, and cited Act and Rules sources.
Australia Smart Device Applicability Workflow
Decide whether Australia's mandatory smart-device security standard applies, including commencement, connectivity, consumer use, exclusions, roles, and evidence.
Australia Smart Device Compliance Statement
What a smart-device statement of compliance must contain under Australia's Cyber Security Act 2024 and Smart Devices Rules, who prepares and supplies it, how long to retain it, and how to prepare for examination.
Australia Smart Device Security Standards under the Cyber Security Act
Plain-English guide to Australia's Cyber Security (Security Standards for Smart Devices) Rules 2025: scope, passwords, vulnerability reporting, support periods, statements of compliance, and evidence records.
CSA 2024 Smart Device Applicability Test
Check whether a smart device is a consumer-grade relevant connectable product under Australia's Cyber Security Act and Smart Devices Rules.
Cyber Security Act 2024 Smart Device Compliance Checklist
Checklist for Australia Cyber Security Act 2024 smart-device scope, password controls, vulnerability reporting, security-update support periods, statements of compliance, retention, and evidence.
Cyber Security Act 2024 Statements of Compliance FAQ
Australian smart-device statements of compliance: covered products, responsible actors, required contents, supporting evidence, and five-year retention.
Cyber Security Act vs EU CRA: scope and obligations comparison
Compare Australia's Cyber Security Act 2024 with the EU Cyber Resilience Act across smart-device duties, ransomware reporting, product-with-digital-elements scope, actors, records, and enforcement routes.
Cyber Security Act vs UK PSTI Act: device security obligations compared
Compare Australia's Cyber Security Act 2024 smart-device, ransomware, and SOCI-adjacent obligations with the UK's PSTI connected-product regime.
How do notices and recalls work under the Australia Cyber Security Act?
FAQ on Australia Cyber Security Act compliance notices, stop notices, recall notices, public notifications, owners, evidence fields, and cited timing.
How does the Australia Cyber Security Act overlap with the SOCI Act?
FAQ on when Australia Cyber Security Act ransomware reporting overlaps with SOCI critical infrastructure assets, responsible entities, and smart-device duties.
Manufacturer, Importer, and Supplier Duties under Australia's Cyber Security Act 2024
Cyber Security Act 2024 smart-device duties for manufacturers, importers, and suppliers, including role tests, scope, statements, and records.
SOCI overlap triage workflow for Australia Cyber Security Act
Triage SOCI Act overlap with Australia Cyber Security Act ransomware reporting and smart-device standards using separate owners, evidence, and cited scope checks.
Which smart devices are in scope under Australia's Cyber Security Act 2024?
FAQ on Cyber Security Act 2024 smart-device scope: relevant connectable products, consumer-grade criteria, exclusions, Australian consumer acquisition, and records to keep.