If you pay a ransom, you may have 72 hours to report it
Since 30 May 2025, a business carrying on business in Australia with annual turnover above $3 million must report a ransomware or cyber extortion payment within 72 hours of making it.
Source: Department of Home Affairs — read the factsheet
Two questions decide it
Do you carry on business in Australia?
The obligation attaches to the business, not to where the attacker is or where the servers sit.
Is your annual turnover above $3 million?
This is the threshold in the rule. If you are near it, the answer is worth confirming properly rather than assuming, because it changes what you must do under pressure.
Thresholds and reporting rules change. Before you rely on this, read the primary source and confirm your own position — the link is above and it is the same document we work from.
The clock starts at the payment, not at the incident
The 72 hours runs from making the payment. By that point you are already several days into the worst week your business has had, and the reporting obligation is competing with restoring systems, calling customers and working out what was taken.
That is the practical problem. Not that the rule is hard to understand, but that nobody reads it for the first time on the day they need it. It takes ten minutes to know where you stand, and those ten minutes are only cheap now.
Paying and reporting are separate decisions
- Reporting a payment is not the same as reporting a data breach. A ransomware event can trigger obligations under more than one scheme, on different clocks, to different recipients.
- The obligation is about the payment. Decisions about whether to pay at all involve your insurer, your lawyer and law enforcement, and they are not ours to make.
- Your cyber insurance policy almost certainly has its own notification requirements, with their own timeframe. Those are contractual and they are separate from this rule.
- The time to find all of this out is before an incident, written down, with the phone numbers somewhere other than the email account you may have just lost.
This page explains a rule and links to the primary source. It is not legal advice and must not be relied on as legal advice. Whether the obligation applies to your business, and what you would have to do, is a question for your lawyer.
We are not lawyers, insurance brokers or tax agents, and we do not advise on whether you comply with anything. What we do is tell you honestly what your controls look like, with evidence.
Knowing the rule is the easy half
The harder question is whether your controls would stop you ever having to make that decision. That is what the Readiness Check measures, and twenty minutes is enough to work out whether you need one.