If your business pays a ransom, you now have 72 hours to report it
Picture the worst version of a bad week. Your files are encrypted, a countdown timer is on the screen, and someone is demanding payment to get your business back. There’s already a clock running. As of 30 May 2025, there’s a second one you may not know about.
Under the Cyber Security Act 2024, Australia’s first standalone cyber security law, many businesses that make a ransomware or cyber extortion payment now have to report it to the government within 72 hours. It’s a quiet change that caught a lot of business owners off guard, partly because the businesses most likely to be hit are the ones least likely to have read the legislation.
Here’s what it actually means, and why the smart response isn’t to memorise the reporting form.
Who’s caught by this
The obligation applies to businesses carrying on a business in Australia with an annual turnover above $3 million in the previous financial year, plus every entity responsible for critical infrastructure regardless of size (Cyber Security Act 2024; Department of Home Affairs guidance).
That $3 million line catches a lot of firms that don’t think of themselves as big. An established legal practice, a busy trades business, a mid-size clinic. If that’s you, this applies.
What you have to do
If a ransomware or extortion payment is made, you have 72 hours to report it to the Australian Signals Directorate, from when the payment is made or from when you become aware one has been made. The report goes through ASD’s ReportCyber portal. Miss the window and there’s a civil penalty attached, currently up to around $19,800.
Two details trip people up:
- It covers payments made on your behalf. If your insurer, your IT provider, or anyone else pays on your behalf, the clock still applies to you. You can’t outsource the obligation by outsourcing the payment.
- It’s separate from breach notification. Reporting a payment is not the same as notifying affected people under the Notifiable Data Breaches scheme. If personal information was exposed, that’s a different duty with its own rules. You may be dealing with both at once.
This isn’t legal advice on your specific obligations. If you think you could be in scope, it’s worth a short conversation with someone who knows your situation before you ever need it.
The point most people miss
It’s tempting to read all this, decide “we’d never pay a ransom anyway,” and move on. But the law exists precisely because plenty of businesses do pay, usually because in the moment it feels like the only way to get their data back. The 72-hour clock is what happens after you’ve already lost the bigger argument.
So the real takeaway isn’t about the report. It’s this: the way to never face that clock is to make paying pointless. If you can restore your business from a clean, offline backup, a ransom demand stops being a crisis and becomes an inconvenience. The attacker’s whole leverage is that you can’t get your data back without them. Take that away and the demand has no teeth.
What to actually do about it
- Work out if you’re in scope. If your turnover is over $3 million or you touch critical infrastructure, assume the obligation applies and plan accordingly.
- Know who might pay on your behalf. Talk to your insurer and your IT partner now about who decides, and who reports, if it ever comes to it.
- Put ReportCyber in your incident plan. When the worst happens, nobody should be googling where to report. It’s a line in the plan, with who’s responsible next to it.
- Make the payment unnecessary. Tested, offline backups are the whole game. A backup you’ve actually restored from in a drill is the difference between a bad day and a paid ransom.
The takeaway
The new rule is a reminder, not the problem itself. The businesses that sail through a ransomware attack aren’t the ones with the reporting form bookmarked. They’re the ones who can shrug, restore, and carry on. Build for that, and the 72-hour clock is one you’ll never have to watch.
Want to be sure you'd never have to pay?
Book a free, no-obligation security assessment. We'll check your backups, your plan and where you stand, so a ransom demand is a problem you've already solved.