In May 2025, the Australian Government introduced new reporting obligations under the Cyber Security Act 2024. As the mandatory ransomware and cyber extortion payment reporting requirement has now been in effect for four months, the Department has updated its guidance materials to support companies in meeting these obligations.
These measures aim to strengthen national cyber resilience by improving visibility into ransomware and cyber extortion activity across the economy.
Who Must Report
Entities are considered reporting business entities if they meet any of the following criteria:
Not-for-profit organisations are not explicitly exempt.
What Must Be Reported
A report must be submitted when:
Reports are not required if no payment is made, or if the incident involves scams or physical extortion (these should be reported to Scamwatch).
When to Report
Reports must be submitted within 72 hours of:
How to Report
Reports must be submitted via the Australian Signals Directorate (ASD) portal and include:
Penalties for Non-Compliance
Failure to report within the required timeframe may result in a civil penalty of up to 60 penalty units.
However, reporting obligation is being introduced in two phases:
For further information, including different scenarios of how the reporting obligations apply to Australian companies, see the updated guidelines here.
Industry survey: Ransomware
The Department of Home Affairs has launched a Ransomware Survey, available here until midnight on 31 October 2025.
Your responses will help the Department improve the ransomware reporting form, guidance materials, overall user experience, as well as identify areas where businesses may need support.