Home / Rules / Cyber Security Act 2024 (Cth) / Cyber Security Act 2024 s 27(1) (report within 72 hours)
Cyber Security Act 2024 s 27(1) (report within 72 hours)
The reporting business entity must give the designated Commonwealth body (the Department and ASD, through ASD's online report form) a ransomware payment report within 72 hours of making the ransomware payment or of becoming aware that it has been made on its behalf; contravention attracts a civil penalty of 60 penalty units, and the entity, its officers, employees and agents are protected from actions for damages for acts done in good faith in compliance (s 28). Incidents where a demand was made but no payment provided, and physical extortion or scams, are outside the obligation. Home Affairs applied an education-first approach to 31 December 2025 and active compliance from 1 January 2026.
Steps that cite it
- KC-04 S2 Is a ransomware payment report required?
- KC-04 S3 When is the report due?
- KC-04 S4 To whom?
- KC-04 S6 Who lodges?
Evidence commonly asked for
- report submitted on the ASD form with timestamp within 72 hours
- escalation path from payment decision to reporting
- records of when payment or awareness occurred
Accepted citation forms are listed on the answer format page.