Home / Rules / Cyber Security Act 2024 (Cth)
Cyber Security Act 2024 (Cth): the rules AI agent steps rest on
- Edition
- Cyber Security Act 2024 (Cth), No. 98 of 2024 (C2024A00098), with the Cyber Security (Ransomware Payment Reporting) Rules 2025 (F2025L00278)
- Checked current
- 2026-09-25
- Official source
- https://www.legislation.gov.au/C2024A00098/latest/text
| Rule | Our statement | Steps that cite it |
|---|---|---|
| Cyber Security Act 2024 s 26 (reporting business entity, ransomware payment) | Part 3 applies where a cyber security incident that has occurred, is occurring or is imminent has or could have a direct or indirect impact on a reporting business entity, an extorting entity makes a demand of it or another entity to benefit from the incident or its impact, and the reporting business entity provides, or is aware another entity has provided on its behalf, a payment or benefit directly related to the demand (a ransomware payment). A reporting business entity is one that at the time of payment carries on a business in Australia with annual turnover for the previous financial year above the threshold the rules set (AUD 3 million, pro-rated by days where business was carried on for part of the year) and is not a Commonwealth or State body or a responsible entity for a critical infrastructure asset, or is a responsible entity for an asset to which Part 2B of the SOCI Act applies; an incident is presumed to be a cyber security incident where it was probably effected through the internet or a like service, probably impaired a computer's connection or probably seriously prejudiced stability, defence or national security, without penalty where that was not in fact so. | KC-04 S1 Is Tallowood a reporting business entity?; KC-04 S2 Is a ransomware payment report required? |
| Cyber Security Act 2024 s 27(1) (report within 72 hours) | The reporting business entity must give the designated Commonwealth body (the Department and ASD, through ASD's online report form) a ransomware payment report within 72 hours of making the ransomware payment or of becoming aware that it has been made on its behalf; contravention attracts a civil penalty of 60 penalty units, and the entity, its officers, employees and agents are protected from actions for damages for acts done in good faith in compliance (s 28). Incidents where a demand was made but no payment provided, and physical extortion or scams, are outside the obligation. Home Affairs applied an education-first approach to 31 December 2025 and active compliance from 1 January 2026. | KC-04 S2 Is a ransomware payment report required?; KC-04 S3 When is the report due?; KC-04 S4 To whom?; KC-04 S6 Who lodges? |
| Cyber Security Act 2024 s 27(2) and Rules s 7 (report contents) | The report must contain, to the extent the reporting business entity knows or can find out by reasonable search or enquiry within the 72-hour period, the information the rules require (Rules s 7): its contact and business details including its ABN (if any) and address, and those of any other entity that made the payment on its behalf; for the incident, when it occurred or is estimated to have occurred, when the entity became aware of it, its impact on the entity's infrastructure and on its customers, any ransomware or other malware variants used, any vulnerabilities in the entity's systems that were exploited, and information that could help a Commonwealth or State body respond to, mitigate or resolve it; for the demand, the amount or quantum demanded (or a description where a non-monetary benefit is demanded) and the method of provision demanded; for the payment, its amount or quantum (or description) and the method of provision; and for communications with the extorting entity, their nature and timing, a brief description of them and a brief description of any pre-payment negotiations. The report is given in the form the Secretary approves (ASD's online form) and may add other incident information. | KC-04 S5 What goes in the report? |