If your business turns over more than $3 million a year and you paid a ransom to get your systems back, you now have 72 hours to tell the federal government — by law. Not "should." Must. That obligation has existed since May 2025, and for the first seven months it ran on an "education first" grace period. That grace period ended on 1 January 2026. We're now two months into active enforcement, and most business owners we talk to have never heard of it.
This isn't a distant, theoretical rule. It's already live, already being enforced, and already has real penalties attached.
What the law actually requires
The Cyber Security Act 2024 introduced Australia's first mandatory ransomware and cyber extortion payment reporting regime, formalised through the Cyber Security (Ransomware Payment Reporting) Rules 2025. If a covered business makes a ransomware or cyber extortion payment — or becomes aware that one has been made on its behalf — it must report that payment to the Australian Signals Directorate within 72 hours, using the reporting form at Report | Cyber.gov.au.
This is a payment-reporting obligation, not a general breach-notification scheme like the Notifiable Data Breaches rules we covered in our Privacy Act series. It applies specifically when money, services, data or any other benefit has changed hands to a cyber extortionist — not simply because an incident occurred.
Who counts as a "reporting business entity"
See MinterEllison's summary of who must report.
What actually has to be reported
There's no minimum threshold under this regime — every ransomware or cyber extortion payment must be reported, regardless of size. A "payment" isn't limited to money either; the rules cover any benefit provided to the extortionist, including services, goods or data.
The report itself needs to cover the impact of the incident, the ransomware variant if it's known, any vulnerabilities that were exploited, the amount and method of payment, and any communications that took place with the attacker. That's a lot to reconstruct accurately within 72 hours if nobody documented anything while it was happening — which is exactly the state most businesses are in mid-incident.
Enforcement is no longer theoretical
The regime ran in two phases. From 30 May to 31 December 2025, the government took an "education first" approach — informing businesses about the obligation rather than penalising gaps. From 1 January 2026, that shifted to active regulatory enforcement. Failing to report within the required timeframe now risks a civil penalty of up to 60 penalty units, currently $19,800, on top of the reputational fallout of a public compliance failure landing on top of a cyber incident.
Read the Department of Home Affairs factsheet.
What an incident actually costs a small business
The reporting obligation is one thing. The underlying risk it's built around is the more useful reason to actually get ready. The ASD's most recent Annual Cyber Threat Report found small and medium business owners are victims of cybercrime at 6.2% — more than double the rate for employees, and more than four times the rate for individuals who aren't business owners at all. Ransomware remains the most disruptive category: the ACSC responded to 138 ransomware incidents in FY2024–25, and in 35% of those cases, the victim's data was posted online regardless of whether a payment was made.
The average cost of a cybercrime incident to a small business is now $56,600, up 14% on the year before. See the ASD's Annual Cyber Threat Report 2024–25.
A 72-hour reporting clock is a hard problem for a business with no incident plan. It's a manageable one for a business that already knows who to call.
What readiness means — and what it doesn't
To be direct about scope: momentuum doesn't respond to live ransomware incidents, negotiate with attackers, or advise on whether to pay. That work belongs with specialist cyber incident responders, your cyber insurer and a lawyer — not a business automation team, and not any business without deep, current expertise in exactly that. Paying a ransom can also carry its own legal risk if the recipient turns out to be a sanctioned entity; DFAT's guidance on cyber sanctions and ransomware payments is worth reading before anyone assumes payment is even a lawful option.
What readiness actually means, and what's realistic to put in place in advance, is narrower and more useful: knowing whether your business is a reporting entity, having a written incident response plan with the reporting pathway already in it, knowing who in the business is responsible for triggering it, and having your cyber insurer and IT provider's details on that one page rather than in someone's head. None of that requires an incident to have happened first.
Where this overlaps with your broader privacy obligations
Worth knowing: the $3 million turnover threshold used here is the same figure the Privacy Act's small business exemption is built around — an exemption the government has flagged for removal later in 2026. A business already sitting over that line for ransomware reporting purposes should assume its privacy obligations are heading the same way. A ransomware incident that exposes customer data can trigger both regimes at once: a ransomware payment report to the ASD, and potentially a notifiable data breach to the OAIC, on two different clocks, from the same incident.
A business that takes the time now to understand what personal information it actually holds is most of the way to knowing what a ransomware incident would actually expose, too — worth doing as one piece of work, not two.
What to actually put in place now
- Confirm whether you're a reporting entity. Check last financial year's turnover against the $3 million threshold, and check whether any part of the business sits under critical infrastructure regulation.
- Write the incident response plan down. One page: who's told first, who decides on next steps, who contacts the insurer, where the 72-hour reporting form actually is.
- Confirm what your cyber insurance actually covers — and whether it requires you to use specific incident responders or notify the insurer within a set window, which can be tighter than 72 hours.
- Know who you'd call at 7am on a Saturday — an IT/security provider, a cyber-incident specialist if you don't have one on retainer, and a lawyer who can advise fast. Having the names before the incident is the entire point.
- Revisit it alongside your Privacy Act readiness work, not as a separate project — the overlap above means most of the audit work serves both.
None of this prevents an incident. It's the difference between a 72-hour deadline that's manageable and one that starts with "who do we even call."
This article provides general business information, not legal, cyber security or insurance advice. Whether your business is a reporting entity, and what your specific obligations are, depends on your circumstances — get advice from a qualified cyber security and legal adviser rather than relying on this summary.
Not sure if your business is actually covered — or ready?
Book a free 20-minute call — we'll help you work out whether the $3 million threshold applies to you, what a sensible one-page readiness plan looks like, and where it overlaps with your Privacy Act work.
