Cyber Security Act 2024: What Ransomware Payment Reporting and Limited Use Obligations Mean for Australian Startups

Cyber Security Act 2024: What Ransomware Payment Reporting and Limited Use Obligations Mean for Australian Startups

Until 2024, Australia regulated cyber security sideways — through privacy law, critical infrastructure law, directors’ duties and APRA standards. The Cyber Security Act 2024 (Cth) is the first Act to do it head-on, and founders who assume it’s aimed at the big end of town should look at the threshold: the centrepiece obligation — mandatory reporting of ransomware and cyber extortion payments — applies to any business carrying on business in Australia with annual turnover above $3 million. That is not enterprise scale. That is a seed-stage SaaS company with decent revenue, an e-commerce business, or an agency. The obligation went live on 30 May 2025, and the Department of Home Affairs’ self-declared “education-first” phase ended on 31 December 2025. Since 1 January 2026, this regime is in its enforcement era — and most startups still haven’t heard of it.

The 72-Hour Ransomware Payment Report

Part 3 of the Act works off three cumulative triggers. Under section 26, you are a reporting business entity if you carry on business in Australia (and aren’t a Commonwealth or State body) and your turnover for the previous financial year exceeded the threshold set by the Cyber Security (Ransomware Payment Reporting) Rules 2025 — $3 million, pro-rated if you only traded for part of that year — or you’re the responsible entity for a critical infrastructure asset to which Part 2B of the SOCI Act applies, in which case there is no turnover threshold at all. Then, if a cyber security incident has impacted you (directly or indirectly), an extorting entity has demanded a ransom, and a ransomware payment is made — by you, or by someone else on your behalf — section 27 requires a report to the Government (the Department of Home Affairs and the Australian Signals Directorate) through the cyber.gov.au reporting portal within 72 hours of making the payment or becoming aware it was made.

Three features of the design deserve a founder’s attention:

  • “Payment” is broader than money. The Act captures monetary and non-monetary benefits given in response to the demand — cryptocurrency, obviously, but also gifts, services or anything else of value. There is no minimum: a token payment made “to make it go away” is reportable.
  • Third-party payments count. If your insurer, incident response firm, negotiator or overseas parent pays on your behalf, the reporting obligation is still yours, and the clock runs from payment — or, if it was paid without your knowledge, from when you become aware of it. The Act applies extraterritorially, so routing the payment through an offshore entity changes nothing.
  • A demand alone is not reportable. If you’re hit, refuse to pay, and restore from backups, Part 3 requires nothing (voluntary reporting is encouraged, and other reporting regimes may still apply). Mandatory reporting is triggered only by payment.

The report itself, prescribed by section 27(2) and section 7 of the Rules, is more than a form-fill: it covers the incident, its impact on you and your customers, the malware variant and exploited vulnerabilities, the demand, the amount and method of payment, and your communications and negotiations with the attacker — all to the extent known or discoverable by reasonable enquiry.

Miss the deadline and you face a civil penalty of up to 60 penalty units — $21,840 at the penalty unit value applying to contraventions from 1 July 2026, and a court can impose up to five times that against a company under the Regulatory Powers framework. The dollar figure is modest by design; the real exposure is what non-reporting signals to every other regulator examining the same incident.

Limited Use: Real Protection, Not a Safe Harbour

The Act’s answer to “why would I tell the government anything?” is the limited use regime, and it’s genuinely valuable — provided you understand its edges.

Ransomware payment reports get their own protections under Part 3: the information can only be used for permitted purposes (sections 29 and 30) — helping you respond, intelligence functions, administering the regime — and cannot be recorded, used or disclosed for investigating or enforcing civil or regulatory contraventions of other laws. Note the italics: the restriction expressly carves out criminal offences. The report can still be used, and shared, for investigating or enforcing a law that imposes a penalty for a criminal offence — which, on its face, includes sanctions and money laundering offences connected to the very payment you’re reporting. What section 32 then adds is inadmissibility: the report itself can’t be tendered against you in criminal proceedings, civil penalty proceedings and most other proceedings, with exceptions including giving false or misleading information, enforcing the Act itself, Royal Commissions and coronial inquiries. But inadmissibility is not derivative-use immunity — investigators can follow leads the report gives them and build a case from what they find. Section 31 preserves legal professional privilege over material you’d otherwise hold privileged (though that preservation, too, gives way in Royal Commissions and coronial inquiries).

Separately, Part 4 creates a limited use obligation for information you voluntarily share with the National Cyber Security Coordinator during an incident, and the companion Intelligence Services and Other Legislation Amendment (Cyber Security) Act 2024 legislated the equivalent for information shared with the ASD. The policy goal is explicit: entities under attack were going quiet on government help because their lawyers feared the OAIC or ASIC would later weaponise what they said. Limited use is designed to let you bring ASD into the room early without writing the regulator’s brief.

Now the edges. Limited use protects the information you provided through that channel — it does not immunise the underlying conduct. If your security failures breach the Privacy Act’s APP 11, the OAIC can still investigate and can still compel the same underlying documents directly from you using its own powers; it just can’t build the case out of your report to the Coordinator. It does nothing for what you tell customers, the market or your insurer. And two traps are worth pinning to the wall: a voluntary disclosure to the Coordinator does not discharge your mandatory section 27 report, and none of this touches your other reporting clocks — the notifiable data breach regime, SOCI’s 12- and 72-hour incident reports, and APRA’s CPS 234 for regulated fintechs all run in parallel. One incident can put four regulators on four different deadlines.

The Act deliberately does not ban ransom payments — but don’t read that as clearance. Paying a sanctioned entity can be a criminal offence under Australia’s sanctions laws regardless of duress-adjacent commercial pressure, payments can engage money laundering provisions, and government policy strongly discourages payment (it neither guarantees decryption nor prevents publication of your data). The payment decision is a board-level legal decision requiring sanctions screening before funds move — not something an incident responder makes at 2am. And remember who reads the reports: you will be describing your negotiation with a criminal to the government, under compulsion, within 72 hours — and as set out above, the criminal-offence carve-out means that description can inform a sanctions or money laundering investigation even though the report itself is inadmissible.

The Act has two other moving parts founders should know exist: mandatory security standards for smart devices (no universal default passwords, vulnerability disclosure channels, published support periods) applying to consumer-grade connected devices manufactured from 4 March 2026 — squarely relevant if you ship hardware — and the Cyber Incident Review Board, appointed in May 2026, which conducts no-fault post-incident reviews of significant incidents — its requests for information are voluntary, but it can compel entities involved in an incident to produce documents.

A Practical Playbook

  1. Know your status before the incident. Check last financial year’s turnover against the $3 million threshold (pro-rated if you traded part-year) each July. Crossing it changes your incident response obligations overnight.
  2. Put the 72-hour clock in your incident response plan. If your cyber incident response plan doesn’t have a ransomware payment decision tree — sanctions screening, board approval, who files the section 27 report and when — it isn’t finished.
  3. Contract for it. If an insurer, negotiator or parent company might pay on your behalf, your engagement terms should require immediate notice to you — your clock runs from their payment.
  4. Use the front door. Limited use means engaging ASD and the Coordinator early is now a materially lower-risk move than silence. Route the engagement through lawyers so privilege is managed deliberately.
  5. Don’t let the protected channel lull you. Everything limited use doesn’t cover — breach notification, customer comms, market disclosure, APP 11 compliance — still needs its own workstream.

The Bottom Line

The Cyber Security Act 2024 is a bargain, and it helps to see both sides of it. The government gets visibility of ransomware payments it never had, on a 72-hour clock, from any business of even modest scale. In exchange, businesses get a real but bounded statutory protection: what you tell government during the worst week of the company’s life can’t become the regulator’s civil case against you — though it isn’t a shield against criminal investigation, and it doesn’t touch the underlying conduct. For startups the practical takeaways are blunt: if you turn over more than $3 million, this regime applies to you now; the grace period is over; and the time to design the payment decision, the reporting workstream and the government engagement is before the ransom note arrives — because 72 hours disappears very quickly when your systems are down.


This article is general information only, not legal advice — whether and how the Cyber Security Act applies depends on your turnover, your structure and the incident itself. Viridian Lawyers advises Australian technology startups on cyber and data regulation, incident response and regulatory engagement. If you want the ransomware decision tree built into your incident response plan before you need it, get in touch.

Recent Articles

blog-image
Cyber Security Act 2024: What Ransomware Payment Reporting and Limited Use Obligations Mean for Australian Startups

Until 2024, Australia regulated cyber security sideways — through privacy law, critical infrastructure law, directors’ duties and APRA standards. The Cyber Security Act 2024 (Cth) is the first …

blog-image
The SOCI Act and Your Startup: When Data-Holding Companies Get Caught by Critical Infrastructure Security Obligations

Most founders assume the Security of Critical Infrastructure Act 2018 (Cth) — the SOCI Act — is about power stations, ports and water treatment plants. It is. But since the 2021–22 amendments expanded …

blog-image
Design and Distribution Obligations for Fintech Startups: How ASIC's Target Market Determinations Apply to Financial Product Issuers

Most fintech founders file the design and distribution obligations under “big bank compliance” — something for the product committees of the majors, not a ten-person startup. ASIC sees it …