Starting 30 May 2025, Australian businesses with more than $3 million in annual turnover are now legally required to report if they make a ransomware or cyber extortion payment. That means, if you’re ever in the unfortunate position of paying an attacker to get your data back—or to stop them leaking sensitive information—you’ve got 72 hours to report that payment to the Australian Signals Directorate, or you could be facing serious penalties. But this isn’t just another government box-ticking exercise. It’s the start of a national effort to get a clearer picture of the ransomware threat landscape—who’s being targeted, how attacks are evolving, and how we can defend against them. And if you’re thinking, “This won’t apply to me,” think again. These laws are designed to capture real-world incidents across all industries—tech, construction, healthcare, finance, even small manufacturers. Welcome to the Don’t Be A Sitting Duck Podcast. I’m Leigh Kefford—let’s dive in.
Let’s break this down. What’s happening?
From 30 May 2025, under the Cyber Security Act 2024, businesses that meet the turnover threshold must report any ransomware or cyber extortion payment within 72 hours of making it—or becoming aware it’s been made on their behalf. This includes monetary and non-monetary payments—so that covers things like: Cryptocurrency Bank transfers Gift cards Even services or favours exchanged in response to a demand So yes, even paying a ransom in Bitcoin counts. Even if your MSP or legal team made the payment—you’re still required to report it.
Who does it apply to?
Any business with more than $3 million in annual turnover, or the equivalent if you’ve only operated for part of the year. There’s even a formula to work that out—for example, a startup that’s only traded for 73 days would pro-rata the $3 million threshold to about $600,000. If they crossed that? They’re captured by the law. The legislation also applies to critical infrastructure operators, regardless of turnover, and to any entity that pays a ransom on behalf of a reporting business.
Why is this being introduced?
Because ransomware is a business model—and it’s booming. Right now, the government has no clear visibility into who’s being hit, how often, or how much money is changing hands. By mandating reporting, the government can: Track which threat actors are most active in Australia Identify targeted industries and common entry points Understand what tactics criminals are using (e.g. phishing, unpatched systems, stolen credentials) Help businesses protect themselves with tailored advice This is about lifting Australia’s cyber resilience—and doing it with real, useful data. When does this start? There are two phases: From 30 May to 31 December 2025, it’s an education-first approach. Think town halls, awareness sessions, and support. From 1 January 2026, enforcement kicks in—so non-compliance could lead to penalties of up to 60 units, which is over $18,000 at today’s rates. What exactly needs to be reported? A lot more than just “we paid a ransom.” You’ll need to include: Your business details, including ABN Details of the incident—what happened, when, and how The impact—on your business and your customers The ransom demand—amount, method, and communications What variant of ransomware (if known) Any exploited vulnerabilities Who paid it—if it wasn’t you directly A summary of negotiations or interactions with the extorting party It’s detailed, but the idea is clear: the more accurate the picture, the better the response. What if I don’t comply? You could face civil penalties, especially after the initial transition period ends. But just as critical—you could also face reputation damage, insurance complications, and regulatory scrutiny from other bodies if you’re found to have concealed an attack. It’s not just about ticking a legal box—it’s about doing the right thing to strengthen your business, your industry, and the wider economy. So what should you do right now? Here’s your action plan: Check your turnover—does your business exceed the $3M threshold? If you’re not sure, get your finance team to run the numbers, especially if you’re a newer company. Assign responsibility—who in your organisation will be responsible for submitting reports? Is it your IT manager, CISO, legal counsel? Create an incident response playbook—include a ransomware reporting checklist and decision tree. Know where to go—familiarise yourself with the reporting form at cyber.gov.au. Train your team—make sure key people know what to do if an attack happens. Review your insurance—some policies may change based on your compliance with these new laws. Avoid payment in the first place—invest in prevention. Things like endpoint protection, multi-factor authentication, user awareness training, and regular backups will make you a harder target. And if you ever find yourself debating whether or not to pay a ransom—don’t do it alone. Talk to professionals, notify the authorities, and follow proper procedure.
ct comprehensive security assessments, including evaluating third-party vendor risks. Implementing advanced threat detection systems, employee cybersecurity training, and regular penetration testing can significantly reduce the likelihood of successful attacks.