Website-Header-1440-x-1024-2.jpg

Mandatory ransomware reporting laws your business should know about.

NOVEMBER 10, 2025 Daniel Reid

As of 30 May 2025, Australia has implemented mandatory reporting laws for ransomware and cyber extortion payments under the Cyber Security Act 2024.

In this article, we unpack the reporting obligations, timeline and what organisations could potentially face in penalties for non-compliance. To begin, Ransomware is a form of malicious software that cybercriminals use to restrict access to a victim’s data, demanding payment to restore it.

What is the reporting obligation?

Australian businesses who make a payment following a ransomware or cyber extortion incident must report this to the Australian Signals Directorate (ASD) within 72 hours of payment or when they have become aware of a person making payment on their behalf.

Does the reporting obligation apply to my business?

Under Part 3 of the Act, these entities defined as reporting businesses include those with:

  • An annual turnover of AUD $3 million of more.
  • Those that are responsible for critical infrastructure assets under the Security of Critical Infrastructure Act 2018.

What is required in a ransomware payment report to ASD?

The report must include the following:

  • Contact and business details of the reporting entity.
  • Details of the cyber incident, including its impact on the business. This also includes things such as the ransomware demand, the value demanded, and payment method requested (monetary or non-monetary).
  • Copies of any communication with the extorting entity in relation to the cyber incident, ransomware demand or payment.
  • Information about any third party involved in making the payment.
  • Any other information relating to the incident that could assist the ASD.

Penalties for Non-Compliance

Failure to report within the 72-hour window can result in civil penalties up to 60 penalty units (AUD $19,800).

The government has indicated it will take an “education-first” approach during the initial rollout phase (until 31 December 2025), offering warnings to some businesses rather than immediate fines.

How would a cyber insurance policy assist with this?

A cyber insurance policy offers two critical benefits when responding to a ransomware incident. First, it helps cover the costs associated with incident reporting, including the fast evaluation and assessment of the breach’s severity. This ensures that organisations can understand what has occurred and begin remediation without delay.

Second, the policy provides expert guidance to assist with compliance, particularly in meeting the reporting obligations to the Australian Signals Directorate (ASD). We work closely with clients to ensure that all required disclosures are made accurately and within the mandated timeframe, offering support throughout the communication process so businesses aren’t left to navigate it alone.

To understand this new law more or to review your businesses cyber protection against the evolving threat of ransomware, chat with our Cyber Insurance experts by emailing Daniel Reid on dreid@pno.com.au or by calling  (03) 9536 7304