FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / Cyber Security Act 2024 (Cth) / Cyber Security Act 2024 s 26 (reporting business entity, ransomware payment)

Cyber Security Act 2024 s 26 (reporting business entity, ransomware payment)

Part 3 applies where a cyber security incident that has occurred, is occurring or is imminent has or could have a direct or indirect impact on a reporting business entity, an extorting entity makes a demand of it or another entity to benefit from the incident or its impact, and the reporting business entity provides, or is aware another entity has provided on its behalf, a payment or benefit directly related to the demand (a ransomware payment). A reporting business entity is one that at the time of payment carries on a business in Australia with annual turnover for the previous financial year above the threshold the rules set (AUD 3 million, pro-rated by days where business was carried on for part of the year) and is not a Commonwealth or State body or a responsible entity for a critical infrastructure asset, or is a responsible entity for an asset to which Part 2B of the SOCI Act applies; an incident is presumed to be a cyber security incident where it was probably effected through the internet or a like service, probably impaired a computer's connection or probably seriously prejudiced stability, defence or national security, without penalty where that was not in fact so.

Cyber Security Act 2024 (Cth). Edition: Cyber Security Act 2024 (Cth), No. 98 of 2024 (C2024A00098), with the Cyber Security (Ransomware Payment Reporting) Rules 2025 (F2025L00278). Checked 2026-09-25. Official source. The framework on compliance.theartofservice.com.

Steps that cite it

Evidence commonly asked for

Accepted citation forms are listed on the answer format page.