• Menu
  • Skip to right header navigation
  • Skip to primary navigation
  • Skip to secondary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

Before Header

Call us now  07 4688 2188

  • Facebook
  • Instagram
  • LinkedIn
  • Twitter
  • YouTube

Clifford Gouldson Lawyers

  • About
    • Our Origin Story
    • Our Future
    • Toowoomba
    • Brisbane
    • Sunshine Coast
    • What our clients say!
  • Careers
  • Supporting our Community
    • Bringing art to the business world
  • Contact Us
  • Search
  • About
    • Our Origin Story
    • Our Future
    • Toowoomba
    • Brisbane
    • Sunshine Coast
    • What our clients say!
  • Careers
  • Supporting our Community
    • Bringing art to the business world
  • Contact Us
  • Search

Mobile Menu

  • Our Team
  • Practice Areas
  • Knowledge
  • Events
  • Industries
  • For Individuals
  • Facebook
  • LinkedIn
  • Twitter
  • YouTube
  • Our Team
  • Practice Areas
  • Knowledge
  • Events
  • Industries
  • For Individuals

Ransomware Reporting Obligation Changes Start Today!

You are here: Home / News / Ransomware Reporting Obligation Changes Start Today!

As of today, a failure to report a ransomware payment could lead to your organisation being fined. From 30 May 2025, a failure to report a ransomware payment could lead to your organisation being fined. That’s when new reporting obligations surrounding ransomware payments came into effect across Australia.

Ransomware is a kind of malware that usually inhibits a business’s systems or their access to files. Hackers who rely on ransomware often demand payment or some other kind of benefit in exchange for removing the malware from the business’s system.

The Legislation

Part 3 of the Cyber Security Act 2024 (Cth) (the Act) requires ‘reporting business entities’ which are impacted by cyber security incidents to report any payment made to an entity trying to benefit from the impact of the incident.

The Act aims to improve cyber security, encourage transparency, improve responses to cyber security incidents and ultimately prevent or mitigate such incidents. While the Act came into effect generally in November last year, Part 3 only commences 30 May 2025 – today! At the same time, the Cyber Security (Ransomware Payment Reporting) Rules 2025 (the Rules) will commence and these Rules may be relevant when interpreting Part 3 of the Act

Who must report?

Not every business is a ‘reporting business entity’ according to the Act. In order to be required to report ransomware payments, an entity must be carrying on a business in Australia and have an annual turnover above $3 million for the previous financial year. However, if the business has only been carried on for part of the previous financial year, it is calculated using the following formula:

$3 million × number of days in the part number of days in the previous financial year

Public bodies and entities responsible for critical infrastructure assets are generally not ‘reporting business entities’. However, a responsible entity for critical infrastructure assets under Part 2B of the Security of Critical Infrastructure Act 2018 (Cth) will be a reporting business entity for the purposes of the Act.

When to report?

A report must be made when a ransomware payment is made to a person or another entity who wants to benefit from the impact of a cybersecurity incident and makes demands to that end. So, there are four key factors to look out for:

  1. A cyber security incident has occurred;
  2. This incident has had an impact on the reporting business entity;
  3. Another entity has demanded payment or some other kind of benefit;
  4. This benefit has been given to them.

A cyber security incident is an event or events involving unauthorised impairment of electronic communication to or from a computer. However, such an event is only a cyber security incident for the purposes of the Act if the incident:

  1. involves a critical infrastructure asset; or
  2. involves the activities of a corporation; or
  3. impeded the ability of a computer to connect to a telegraphic, telephonic or similar service; or
  4. has serious implications for Australia’s social or economic stability, defence, or national security.

If the above factors have been satisfied, then the reporting entity has 72 hours to make a report (s 27(1)).

If an organisation fails to make the report, it can be fined

What must a report include?

The report needs to be made to an authorised Department such as the Australian Signals Directorate or the Australian Cyber Security Centre.

Rule 7 sets out the information that is required to be included in any report of a cyber security incident. A report must include the contact and business details, the ABN (if applicable) and the address of both the reporting entity and the entity demanding payment. The report must also include information about the cyber security incident including:

  • when the incident occurred;
  • when the reporting business entity became aware of the incident;
  • any impact on infrastructure;
  • any impact on customers;
  • the kind of ransomware or other malware used;
  • the vulnerabilities (if any) in the system that were exploited;
  • any other information that could be helpful to the investigating body.

Going forward

If you are considered a reporting business entity under the Act, you are bound by the reporting obligations above. So it would be advisable for you to consider your system’s vulnerabilities and fortify it against ransomware attacks. Also, you should review your cyber insurance notification regime and internal cyber security policies to ensure that reporting occurs within the required time. If you have questions about this alert please contact a member of our Intellectual Property + Technology team.


For further information, contact Ben Gouldson.

The assistance of Eve Gellatly, Legal Assistant, in researching this article is gratefully acknowledged.

Previous Post: « Katy/Katie Perry Trademark Case Heads to High Court

Primary Sidebar

We can help

Ben Gouldson

Managing Director and Trade Marks Attorney*

Melanie Sharpe

Lawyer

Nicola Hayden

Lawyer and Trade Marks Attorney*

Brooke Giblin

Legal Secretary & Personal Assistant

Related Alerts

April 9, 2025
Yes, crypto currency is personal property!

The legal system has taken some time to come to grips with crypto currency,...

Privacy & AI: How much does your AI know?

There have been a number of changes to Australia’s privacy laws recently and businesses...

March 5, 2025
Recent Decision on Copyright Infringement: a Puff Piece

In December 2024, the Federal Court of Australia handed down a judgment on a...

View other alerts

Footer

Clifford Gouldson Lawyers

CLIFFORD GOULDSON LAWYERS
P: 07 4688 2188
F: 07 4688 2199
mail@cglaw.com.au
  • Facebook
  • Instagram
  • LinkedIn
  • Twitter
  • YouTube

Locations

TOOWOOMBA (Head Office)
259 Ruthven Street,
Toowoomba Q 4350

PO Box 8208,
Toowoomba South Q 4350

Toowoomba Office

BRISBANE
Level 5, 231 George Street,
Brisbane Q 4000

PO Box 12802 George Street,
Brisbane Q 4003

Brisbane Office

 

SUNSHINE COAST
Regatta Corporate Building, Office 3,
Ground Floor, Innovation Parkway,
Birtinya Q 4575

Locked Bag 5010
Caloundra DC Q 4551

Sunshine Coast Office

Practice Areas

  • Property + Business Transactions
  • Workplace
  • Litigation + Dispute Resolution
  • Intellectual Property + Technology
  • Wills, Estates, Planning + Structuring
  • Business + Corporate Advisory
  • Construction
  • Privacy & Disclaimer
  • Terms of Use

Site Footer

CG Law (Trading) Pty Ltd ACN 143 426 028 t/a Clifford Gouldson Lawyers ABN 89 143 426 028 Liability limited by a scheme approved under professional standards legislation.

The contents of this website are provided solely for general information purposes and do not constitute legal or other professional advice. Clifford Gouldson Lawyers expressly disclaims any liability arising from the use or reliance on the information provided. If you require legal or other expert advice or assistance, then you should seek our help or the services of a qualified professional.

Copyright © 2025 Clifford Gouldson Lawyers · Privacy & Disclaimer · Terms of Use · Marketing by John Gray Marketing · Site by Kingfisher