- Sets one penalty unit at $364 from 1 July 2026. Its timing note expressly addresses offences committed on or after that date, so this page does not infer a civil-contravention timing rule from the instrument.
"the amount of a penalty unit is $364"
The Cyber Security Act 2024 sets 60-penalty-unit civil penalties for specific ransomware reporting, protected-information, CIRB notice, and draft-review-report contraventions.
Part 2 uses compliance, stop, and recall notices for smart-device breaches; it does not state a general 60-unit smart-device penalty.
Structured answer sets in this page tree.
Cited legal and guidance references.
The Cyber Security Act's express provisions differ from the smart-device notice pathway. Legal, incident-response, product, and compliance teams can use these triggers to check a ransomware report, protected-information use, response, or product enforcement issue. From 1 July 2026, one Commonwealth is $364, so 60 units equal $21,840. That figure is an arithmetic conversion, not an automatic penalty; confirm the applicable unit value, contravention date, entity type, and enforcement route before using it for a case.
Only specified contraventions carry the Act's 60-penalty-unit : the section 27 ransomware reporting duty, the secondary-use restrictions in sections 30, 40, and 56 when their additional conditions are met, a compulsory document notice under section 49, and the draft-report restriction in section 59.
The trigger and exceptions differ by section. Missing a covered ransomware report engages section 27(5). The protected-information provisions require more than any unauthorised handling: the information must fall within the relevant Part, the permitted-use rule must be contravened, the entity must not be a Commonwealth officer, and one of the listed sensitivity, confidentiality, or national-security conditions must apply. Sections 50 and 59 have their own exceptions.
The 60-unit amount is the stated maximum for a person other than a . Under section 82(5) of the Regulatory Powers Act, the court-ordered maximum for a body corporate is generally five times the amount specified for the provision, or 300 penalty units here. At the current $364 penalty-unit value, those figures convert to $21,840 and $109,200. Confirm which unit value applies to the alleged civil contravention before relying on a dollar figure. The court determines the appropriate penalty up to the applicable maximum.
Smart-device enforcement under Part 2 is built around notices. For a product within the prescribed class and circumstances, sections 15 and 16 impose manufacturer and supplier duties for the security standard and statement of compliance. The Secretary may issue a compliance notice when reasonably satisfied that an entity is not complying or when information suggests possible non-compliance.
If the compliance notice is not met or remediation is inadequate, the Secretary can escalate to a stop notice. If a stop notice is not met or remediation remains inadequate, the Secretary can escalate to a recall notice. If the recall notice is not complied with, the Minister may publish information including the entity identity, product details, non-compliance details, and product risks; the Smart Devices Rules add recall-notice details and recommended consumer actions.
The Part 3 scope test determines whether the ransomware reporting penalty can arise. A report duty can arise when a cyber security incident impacts a , an extorting entity makes a demand to benefit from the incident or its impact, and the reporting business entity provides, or becomes aware that another entity provided on its behalf, a payment or benefit directly related to that demand.
The 2025 Ransomware Payment Reporting Rules prescribe the ordinary turnover threshold as $3 million for the previous financial year, with a pro-rated formula where the business operated for only part of that previous financial year. A responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies can also fall within the reporting-business-entity test.
Build records around the statutory trigger, not a generic cyber incident ticket. Keep a separate record for each possible exposure: ransomware report failure, protected-information misuse, significant-incident information misuse, Board document notice failure, draft-report use, or smart-device notice escalation.
Part 6 applies the Regulatory Powers Act framework. A relevant court may make orders for the Act's civil penalty provisions. Enforceable undertakings may cover those provisions and sections 15 and 16. Injunctions apply to civil penalty provisions. Section 82 permits infringement notices for alleged civil penalty contraventions; an is an alternative process and is not a court finding that the provision was contravened. The Act identifies authorised applicants, authorised persons, and the relevant chief executive for those functions.
This guide helps assign ransomware reporting clocks, smart-device notice responses, Board notice handling, protected-information controls, and evidence records in Sorena.
Turn penalty triggers into scoped questions, evidence fields, owners, and review tasks.
Use Research Copilot to check the Act, ransomware rules, smart-device rules, and cited enforcement provisions.
Review civil penalty exposure, notice response records, source support, and next compliance actions with Sorena.
"the amount of a penalty unit is $364"
"the amount of turnover threshold"
"actions consumers are recommended to consider"
"within 72 hours"
"Civil penalty: 60 penalty units."
"Civil penalty orders may be sought"
"5 times the pecuniary penalty specified"
"who is alleged to have contravened"
"5 times the pecuniary penalty specified"
"responsible entity"