- Current official filing form for mandatory ransomware or cyber-extortion payment reports under section 27.
"You are only required to disclose information you know, or by reasonable search or enquiry, are able to find out."
Start this workflow after a ransomware or cyber extortion payment to decide whether Part 3 applies, start the 72-hour report clock, collect the required report fields, and preserve the evidence behind the submission.
The workflow is based on the Cyber Security Act 2024 and the Cyber Security (Ransomware Payment Reporting) Rules 2025. It supports operational planning but does not replace case-specific legal, contractual, insurer, sanctions, or law-enforcement advice.
Structured answer sets in this page tree.
Cited legal and guidance references.
Australia's reporting regime became operational at the end of May 2025. The Federal Register commencement table lists 29 May 2025 for Part 3, while Home Affairs guidance describes mandatory reporting as active from 30 May 2025. A must give a ransomware payment report within 72 hours after making the payment or becoming aware that the payment has been made, whichever applies. Identify the trigger, confirm scope, gather information the entity knows or can find by within the reporting window, file through the Australian Government form on cyber.gov.au, and preserve the submitted record.
Open Part 3 triage only when all five conditions are present. An incident has occurred, is occurring, or is imminent; it is a ; it has had or could reasonably be expected to have a direct or indirect impact on the entity; an has made a demand to benefit from the incident or its impact; and a payment or benefit directly related to that demand has been provided. Include ransom, cyber extortion, and non-monetary benefits because the Act covers benefits as well as money.
Confirm the Act's test instead of relying on the incident label. Section 9 requires an event covered by the SOCI Act meaning or an unauthorised impairment of electronic communications to or from a computer, plus a listed constitutional connection. For incidents outside the critical-infrastructure-asset and constitutional-corporation limbs, section 26 presumes the event is a cyber security incident if it was probably internet-enabled, probably impaired a computer's connection, or probably seriously prejudiced specified Australian interests. The presumption cannot support civil-penalty liability if the relevant condition did not exist in fact.
The incident commander and legal or compliance lead should first confirm whether the affected entity is a at the time the payment is made. The Act covers responsible entities for critical infrastructure assets to which of the Security of Critical Infrastructure Act 2018 applies, and qualifying businesses carried on in Australia whose previous-financial-year annual turnover exceeds the prescribed threshold.
The Act uses "exceeds" and the Rules prescribe a $3 million threshold, while the current cyber.gov.au form describes the turnover option as "equal to or exceeds $3 million." Treat an exact-$3 million case as a filing-instruction discrepancy that needs prompt case-specific confirmation; do not let it delay triage or deadline tracking.
If no payment or benefit was provided, section 27 does not require a report. Keep the incident in the organisation's other reporting workflows because duties under the Security of Critical Infrastructure Act, privacy law, prudential standards, law-enforcement arrangements, insurance, or contracts may still apply.
If the made the , the workflow clock starts when it made the payment. If another entity paid on its behalf, the clock starts when the reporting business entity became aware that the payment had been made. Log the payment and awareness timestamps even when only one starts the statutory clock, then record the basis for the deadline.
Do not wait for perfect attribution or full forensic certainty. The Rules state that information is only required to the extent the knows it or can find it by within the 72-hour period. Keep a timestamped evidence log showing what was known, who searched for missing information, and which fields remained unknown at submission time.
Use the Act's six field groups as the report structure, then add the fields prescribed by the Rules. Record who is reporting, who paid if different, what happened, what was demanded, what was provided, and what communications occurred with the .
Section 27 requires the report to be given to the . The Australian Government currently directs reporting entities to the and cyber extortion payment reporting form on cyber.gov.au. The compliance owner should confirm that the live form remains the approved filing route at submission time and preserve its confirmation page or transmission record.
A third party may use the live form on behalf of the , but the statutory duty remains the reporting business entity's. Keep the submitter's authority, the reporting entity's approval, and the final submission confirmation together; a report made only in the third party's own name may not establish that the required entity reported.
Do not assume the live form's "Additional information" field is entirely optional. Rule 7(4)(g) requires information known or reasonably discoverable within the reporting window that could assist a Commonwealth or State body to respond to, mitigate, or resolve the incident. Keep that required information separate from other incident information the entity chooses to add under subsection 27(3).
Assign the 72-hour clock owner, report-field owners, evidence requests, approval checkpoints, and submission records in Sorena.
Convert the ransomware reporting trigger, scope test, report fields, and evidence index into assigned incident-response tasks.
Use Research Copilot to check follow-up questions against the Act, Rules, and explanatory material.
Review ransomware payment reporting ownership, evidence handling, and report preparation with Sorena.
Before submission, run a short approval checkpoint that checks scope, deadline, field completeness, the source of each fact, and whether any unknown field has a reasonable-search note. Section 27 permits other information about the incident, so distinguish required fields from optional additional information and confirm the report is consistent with any parallel incident-reporting obligations.
The reporting duty does not authorise or recommend making a . Payment legality, sanctions exposure, anti-money-laundering controls, insurer consent, law-enforcement engagement, and corporate approval remain separate questions that should be addressed before payment where time and circumstances allow.
An entity that fails to give the required report is liable to a civil penalty of 60 penalty units. The report does not itself discharge any other applicable statutory, regulatory, contractual, or insurance reporting duty; assess each duty on its own terms.
After submission, retain the report package as an incident evidence record. Include the submitted report, timestamped approval, submission confirmation, source artifacts used for each field, unresolved information notes, and follow-up tasks. Also retain a privilege note where legal counsel has assessed privileged material, because the Act states that providing information in a report does not otherwise affect a claim of legal professional privilege.
The Act's use and admissibility protections are limited. They do not cover information obtained independently or information already lawfully public. The Act also allows use for action over a breach of Part 3 and for the specified criminal-law purposes. Do not describe the report as immune from all regulatory, civil, or criminal use.
"You are only required to disclose information you know, or by reasonable search or enquiry, are able to find out."
"Information is only required to be given to the extent that the reporting business entity knows or is able"
"the nature and timing of any communications between the entity and the extorting entity"
"the amount of turnover threshold for a business for the previous financial year is $3 million"
"within 72 hours of making the ransomware payment or becoming aware"
"the cyber security incident, including its impact on the reporting business entity"
"does not otherwise affect a claim of legal professional privilege"
"provides, or is aware that another entity has provided on their behalf, a payment or benefit"