Cybersecurity

Ransomware Payment Reporting: The 72-Hour Rule for Businesses Over $3m Turnover

If your business turns over more than $3 million a year and you pay a ransomware or cyber extortion demand, you now have 72 hours to report it to the Australian Government. The rule has been law since 30 May 2025, the education-first grace period ended on 31 December 2025, and the Department of Home Affairs has said it is now actively regulating. Most Melbourne SMEs we talk to have never heard of it. Here is what it says, who it catches, and what to put in your incident response plan today.

This is general information about a Commonwealth law, not legal advice. Check the position for your own business with your lawyer.

The rule in one paragraph

Part 3 of the Cyber Security Act 2024 (sections 26 to 32), supported by the Cyber Security (Ransomware Payment Reporting) Rules 2025, requires a “reporting business entity” that makes a ransomware or cyber extortion payment, or becomes aware that a payment has been made on its behalf, to report it to the Australian Signals Directorate within 72 hours. Failure to report carries a civil penalty of 60 penalty units. A Commonwealth penalty unit is $364 from 1 July 2026, so the maximum is $21,840 per breach.

Who has to report

You are a reporting business entity if you carry on business in Australia and either:

  • your annual turnover in the previous financial year exceeded $3 million (pro-rated if you did not trade for the full year), or
  • you are the responsible entity for a critical infrastructure asset under Part 2B of the Security of Critical Infrastructure Act 2018.

Commonwealth and state bodies are excluded. Not-for-profits are not. A charity or community organisation with more than $3 million in turnover is caught in exactly the same way as a company.

For a Melbourne SME, $3 million is not a large number. A 15 to 20 person professional services firm, a small manufacturer, a busy allied health group or a two-venue hospitality business will usually clear it.

What triggers the 72 hours

The clock starts when a payment is made, or when you become aware that someone has made a payment on your behalf. Three points people get wrong:

  1. A demand alone does not trigger the obligation. If you are hit by ransomware and do not pay, there is nothing to report under this Part. You may have other obligations (see below), but not this one.
  2. Payment is not just money. The Act captures any benefit provided to the extorting party, monetary or otherwise.
  3. “On your behalf” includes your insurer, your IT provider and your incident response firm. If your cyber insurer negotiates and pays, the obligation is still yours, and it starts when you become aware the payment was made.

Where and how you report

Reports go through ASD’s ransomware payment reporting form on cyber.gov.au. The Department of Home Affairs administers compliance. You receive a unique reference number on submission. Keep it: it is your evidence that you met the deadline.

Section 7 of the Rules sets out what the report must contain, to the extent it is known or can be found by reasonable enquiry:

  • your contact and business details, including ABN;
  • details of the incident: when it occurred, when you discovered it, the impact on the business and its customers, the malware variant and the vulnerabilities exploited, plus anything that would help a government response;
  • if someone else paid on your behalf, their details;
  • the demand: how much was demanded and how it was to be provided;
  • the payment: how much was paid and how;
  • the communications with the extorting party, including a brief description of any negotiation.

Seventy-two hours is not long to assemble that while you are also restoring systems. This is why the report belongs in the incident response plan as a named task with a named owner, not as something the managing director remembers on day four.

What the government can and cannot do with your report

The Act includes limited-use protections (sections 29 to 32) designed to make reporting safe. Reported information can be used to help you respond to the incident, to support intelligence functions and to inform the Minister. It is not admissible against you in criminal proceedings, in civil penalty proceedings or for breaches of other Commonwealth, state or territory laws, with narrow exceptions such as providing false or misleading information, obstruction, Royal Commissions and coronial inquiries. Home Affairs states plainly that the information “will not be used for enforcement actions, except where explicitly allowed under Part 3 of the Act”.

In practice: reporting a payment is not a confession, and it does not open a regulatory investigation into how you were breached.

The timeline

  • 30 May 2025: the obligation commenced.
  • 30 May to 31 December 2025: education-first period. Home Affairs said it would pursue regulatory action only for egregious non-compliance.
  • 1 January 2026 onwards: active regulatory focus.
  • 1 July 2026: penalty unit indexed to $364, taking the maximum civil penalty to $21,840.

What it does not cover

  • Ransomware or extortion where no payment is made.
  • Scam-related losses (business email compromise where you were tricked into paying a false invoice, for example). Those can be reported voluntarily through Scamwatch.
  • Physical extortion threats.

Two things are worth knowing. First, an incident that happens overseas still counts if your Australian entity is impacted and pays. Second, a voluntary disclosure to the National Cyber Security Coordinator under sections 35 and 36 of the Act does not satisfy the mandatory reporting requirement. They are separate.

How it sits alongside your other obligations

This rule does not replace anything. Depending on your business you may also have:

  • the Notifiable Data Breaches scheme under the Privacy Act, if personal information was accessed and serious harm is likely;
  • SOCI Act incident reporting if you are a critical infrastructure responsible entity;
  • contractual notification duties to clients, particularly if you supply government or regulated sectors;
  • notification duties under your cyber insurance policy, which usually run in hours, not days.

The practical answer is one incident response plan that lists every notification you might owe, who owns each one, and the deadline for each. The 72-hour ransomware report is one line on that list.

Five things to do this month

  1. Confirm whether you are over the threshold. Use last financial year’s turnover. If you are close, plan as if you are over it.
  2. Add the report to your incident response plan. Name the person who submits it and the person who approves it. Put the cyber.gov.au form location in the plan.
  3. Decide your payment policy in advance. Whether you would ever pay is a board decision, not a 2am decision. Whatever you decide, the reporting obligation follows the payment, not the policy.
  4. Brief your insurer and your IT provider. If either might pay on your behalf, agree who tells whom, and when, so the 72 hours does not start without you knowing.
  5. Collect the report details now. ABN, contact details and a template for the incident description can be prepared in advance. The rest you will only know during the incident, which is why logging and a competent incident response capability matter.

Frequently asked questions

We are under $3 million turnover. Does anything apply to us?

Not this obligation, unless you are a critical infrastructure responsible entity. The Notifiable Data Breaches scheme, your contracts and your insurance policy may still apply. And a cyber incident at a business under $3 million is no less damaging for being unreported.

Does the 72 hours run in business hours?

The Act says 72 hours. Treat it as elapsed time, including weekends.

Will reporting get us into trouble with regulators?

The limited-use protections are specifically designed so that it does not. The information cannot be used against you in enforcement except in narrow cases such as giving false information.

What if we do not know all the details within 72 hours?

The Rules require information that is known or can be found by reasonable enquiry. Report what you know within the deadline rather than waiting for a complete picture.

Who in our business should own this?

Whoever owns the incident response plan. In most SMEs that is the managing director or general manager, supported by the IT provider. It should not sit with IT alone, because the decision to pay and the legal exposure are business matters.

Sources

← Previous The Essential Eight Is Being Retired. Here Is What Melbourne SMEs Should Do Now

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon, just a clear-eyed look at where you stand and what's possible.