Australia’s mandatory ransomware and cyber-extortion payment reporting regime has been active since 30 May 2025. Covered businesses must report a qualifying payment within 72 hours of making it—or, if someone else paid on their behalf, within 72 hours of becoming aware of that payment. A ransom demand alone does not trigger this particular reporting duty.
Which Australian businesses must report?
The obligation applies to a reporting business entity: broadly, a business carrying on business in Australia with turnover of at least AUD $3 million in the previous financial year, or a responsible entity for a critical-infrastructure asset covered by Part 2B of the Security of Critical Infrastructure Act. The turnover threshold is assessed for the relevant entity, not simply because a company is large or operates in Australia.
If a business operated for only part of the previous financial year, the applicable Rules scale the AUD $3 million threshold according to the fraction of that year the business operated. Check the Rules against the entity’s circumstances rather than treating $3 million as a simple, universal annual threshold.
The regime can apply when a payment is made through an international office or by another party for the Australian entity. That can include a payment arranged or made by an insurer, negotiator, contractor or other third party. The identity of the person who transferred the funds does not, by itself, remove the business’s reporting responsibility.
#1 Best Overall
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
What triggers the report—and what does not?
The reporting trigger is a ransomware or cyber-extortion payment made after a cyber-security incident affecting the reporting entity. The duty covers a payment made by the business and one made on its behalf. A demand that the business refuses, ignores or otherwise does not pay does not trigger this mandatory payment report.
Physical-extortion threats and scam-related attacks are outside this specific mandatory ransomware-payment reporting regime. That does not mean they should go unreported: other reporting channels or obligations may be relevant.
Rank #2
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
When does the 72-hour clock start?
If the business makes the payment, the 72-hour period starts when it makes that payment. If another entity pays on the business’s behalf, the period starts when the business becomes aware that the payment has been made. The Act uses whichever of those circumstances applies. Do not assume that a third-party payment gives the business an additional 72 hours from the time it later confirms every detail.
Submit the report through the official ransomware payment reporting form on Cyber.gov.au within the applicable period. If some information is unavailable, the report must include what the entity knows or can find through reasonable search or enquiry during the 72-hour period; the requirement is not to delay filing until every fact has been established.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #3
- Slim durable design to help take your important files with you
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
What information should the report contain?
The prescribed report asks for information across several areas. Gather what is known or reasonably discoverable within the reporting window:
- Business details: identifying information about the reporting entity and relevant contacts.
- Incident facts: what happened, when it was identified, and how the incident affected the entity.
- Extortion demand: the demand and relevant communications or terms.
- Payment information: details of the payment and, where applicable, the person or organisation that made it on the entity’s behalf.
Preserve the demand, communications, incident timeline, payment records and details of any insurer, lawyer, negotiator or other third party involved. These records support the report and help establish when the payment was made or when the business learned it had been made.
Rank #4
- World’s First 6TB 2.5” Portable Hard Drive
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
A practical response sequence
- Preserve records and establish the timeline. Record the incident, demand, communications, payment arrangements and any third parties involved. Note both the payment time and, where relevant, when the business learned that someone else had paid.
- Check whether the affected entity is covered. Assess the previous-financial-year turnover test, any part-year adjustment, and whether the entity is responsible for a covered Part 2B critical-infrastructure asset.
- Confirm whether a payment occurred. Ask the insurer, negotiator, contractor or other party handling the incident whether payment was made on the business’s behalf.
- File within the applicable 72-hour period. Use the official Cyber.gov.au reporting form. Include information known or reasonably discoverable in that period rather than waiting for a complete investigation.
- Review other incident obligations separately. Check whether the event also requires action involving customers, an insurer, a privacy or other regulator, or sanctions compliance. Get legal or government support as appropriate.
Does reporting mean a company is prohibited from paying?
No. The reporting regime creates a duty to report qualifying payments; it is not itself a ban on paying a ransom. That distinction does not settle whether a particular payment is lawful or advisable. Sanctions rules and other legal obligations may apply, and the operational, financial and security consequences of paying are separate questions for the company to assess with appropriate advice.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What this reporting duty does not replace
A ransomware payment report is not a substitute for other notifications or responses. Depending on the incident, a business may also need to consider customer communications, privacy requirements, insurer conditions, sector-specific regulator obligations and sanctions compliance. Which duties apply depends on the facts and the entity; the payment-reporting deadline does not resolve those separate questions.
Quick Recap
Best Value
- Slim durable design to help take your important files with you
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- Back up smarter with included device management software[2] with defense against ransomware
- Help secure your important files with password protection and hardware encryption
- 3-year limited warranty
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

