Skip to content
Q10 Systems
Home Pricing Switching providers Resources Call Q101300 110 210 Talk to Q10
← Resources

Mandatory Ransomware Payment Reporting in Australia: What Businesses Need to Know

Australia has mandatory reporting rules for certain ransomware and cyber-extortion payments. Here is who is in scope, when the 72-hour clock starts, what needs to be recorded and where the IT response fits.

Laptop on a desk representing ransomware incident response and payment reporting

Ransomware reporting is one of those topics that can sound simpler than it really is. The important point is that Australia’s mandatory regime is specifically about ransomware and cyber-extortion payments. It is not a rule saying every ransomware incident must be reported under this particular scheme.

If a business is in scope and it makes a payment, or becomes aware that somebody has made one on its behalf, the reporting clock can move quickly. The better approach is to understand that process before an incident rather than trying to work it out while systems are offline.

Laptop on a desk representing ransomware incident response and payment reporting

The important distinction: an incident is not automatically a payment report

Part 3 of the Cyber Security Act 2024 applies where an in-scope entity is affected by a cyber security incident and provides, or knows another entity has provided on its behalf, a payment or benefit to the extorting party in connection with the demand.

So a ransom note by itself does not trigger this specific payment-reporting obligation. A ransomware incident may still create other reporting, notification or contractual obligations, but those need to be considered separately.

Who is generally in scope?

For ordinary businesses, the legislation generally captures an entity carrying on business in Australia where annual turnover for the previous financial year exceeds the $3 million threshold. The rules also include a pro-rata calculation where the business only operated for part of the previous financial year.

Responsible entities for certain critical infrastructure assets can also be in scope under the Security of Critical Infrastructure framework, regardless of the normal turnover test.

If there is any doubt about whether a particular entity is legally captured, that is something to confirm with appropriate legal or regulatory advice rather than guessing during an incident.

The report is due within 72 hours

An in-scope reporting business entity must lodge the ransomware payment report within 72 hours of making the payment, or becoming aware that the payment has been made, depending on the circumstances.

The report is lodged using the Australian Government’s ransomware and cyber-extortion payment reporting form.

Business and technical team discussing a cybersecurity incident response

Photo by Lyubomyr Reverchuk via Unsplash.

What information needs to be captured?

The rules ask for information about the business, the cyber incident, its impact, the extorter’s demand, the payment and communications with the extorting party. That can include when the incident occurred, when it was discovered, customer and infrastructure impact, any ransomware or malware variant identified, vulnerabilities known to have been exploited, what was demanded, what was paid and the nature and timing of communications or negotiations.

The legislation recognises that an organisation may not know everything within three days. The report only requires information the business knows or is able to find out by reasonable search or enquiry within the reporting period.

Should a business pay a ransom?

The Australian Government discourages businesses and individuals from paying ransomware or cyber-extortion demands. Payment does not guarantee systems will be restored, that stolen information will be deleted, or that the organisation will not be targeted again.

Whether a payment is considered in a real incident is a serious business, legal, insurance and incident-response decision. Q10’s role is on the technical side: helping contain the incident, understand what happened, preserve useful evidence, recover systems and work with the client’s other advisers where required.

Business user reviewing a cybersecurity incident on a laptop

Photo by Sebastian Herrmann via Unsplash.

The useful preparation happens before ransomware arrives

Know who owns the incident

Someone needs authority to bring together IT, management, legal advisers, the cyber insurer and any specialist incident-response provider. That should not be decided for the first time while team members are locked out of their systems.

Preserve the evidence

Keep ransom notes, screenshots, suspicious emails, attacker communications, relevant logs and a clear timeline of what was discovered and when. Evidence that disappears during rushed recovery work can be difficult or impossible to recreate later.

Make sure recovery is real

Backups only help when they cover the systems and data the business actually depends on and can be restored when needed. Recovery testing should sit alongside endpoint protection, identity security and security monitoring, rather than being treated as an isolated backup product.

Other reporting obligations may still apply

The ransomware payment report is only one possible obligation. Depending on the incident and the organisation, there can also be requirements involving critical infrastructure, privacy and data breaches, regulators, customers, government contracts, insurers or other third parties.

That is why an incident-response plan should separate the technical response from the legal and regulatory decisions. The technical team should be able to produce reliable facts and evidence, while the appropriate advisers determine which formal obligations apply.

Where Q10 fits

Q10 can help businesses reduce ransomware risk through secure identity and device configuration, monitoring, backup and recovery, patching and incident preparation. If an incident does occur, we can help contain the technical problem, preserve evidence and work through recovery in a controlled way.

For the current government rules and reporting form, see the Department of Home Affairs Cyber Security Act guidance and Cyber.gov.au payment reporting page.

This article provides general information about the technology and incident-response side of ransomware reporting. It is not legal advice.

Start a conversation

Tell us what you need help with.

Tell us what is happening in plain English. You do not need to diagnose the issue first.