Home / Rules / Cyber Security Act 2024 (Cth) / Cyber Security Act 2024 s 26 (reporting business entity, ransomware payment)
Cyber Security Act 2024 s 26 (reporting business entity, ransomware payment)
Part 3 applies where a cyber security incident that has occurred, is occurring or is imminent has or could have a direct or indirect impact on a reporting business entity, an extorting entity makes a demand of it or another entity to benefit from the incident or its impact, and the reporting business entity provides, or is aware another entity has provided on its behalf, a payment or benefit directly related to the demand (a ransomware payment). A reporting business entity is one that at the time of payment carries on a business in Australia with annual turnover for the previous financial year above the threshold the rules set (AUD 3 million, pro-rated by days where business was carried on for part of the year) and is not a Commonwealth or State body or a responsible entity for a critical infrastructure asset, or is a responsible entity for an asset to which Part 2B of the SOCI Act applies; an incident is presumed to be a cyber security incident where it was probably effected through the internet or a like service, probably impaired a computer's connection or probably seriously prejudiced stability, defence or national security, without penalty where that was not in fact so.
Steps that cite it
Evidence commonly asked for
- turnover determination for the previous financial year
- incident response playbook identifying the Part 3 trigger on any payment or benefit
- third-party payment arrangements captured
Accepted citation forms are listed on the answer format page.