FORM AWT-1 · AGENT CHECK SHEET · LIBRARY 1.0SCORER 1.0.0 · 8 PUBLIC SCENARIOS · SPECIMEN DATA
AI Agent Compliance Workflow Tester

Home / Rules / Cyber Security Act 2024 (Cth) / Cyber Security Act 2024 s 27(2) and Rules s 7 (report contents)

Cyber Security Act 2024 s 27(2) and Rules s 7 (report contents)

The report must contain, to the extent the reporting business entity knows or can find out by reasonable search or enquiry within the 72-hour period, the information the rules require (Rules s 7): its contact and business details including its ABN (if any) and address, and those of any other entity that made the payment on its behalf; for the incident, when it occurred or is estimated to have occurred, when the entity became aware of it, its impact on the entity's infrastructure and on its customers, any ransomware or other malware variants used, any vulnerabilities in the entity's systems that were exploited, and information that could help a Commonwealth or State body respond to, mitigate or resolve it; for the demand, the amount or quantum demanded (or a description where a non-monetary benefit is demanded) and the method of provision demanded; for the payment, its amount or quantum (or description) and the method of provision; and for communications with the extorting entity, their nature and timing, a brief description of them and a brief description of any pre-payment negotiations. The report is given in the form the Secretary approves (ASD's online form) and may add other incident information.

Cyber Security Act 2024 (Cth). Edition: Cyber Security Act 2024 (Cth), No. 98 of 2024 (C2024A00098), with the Cyber Security (Ransomware Payment Reporting) Rules 2025 (F2025L00278). Checked 2026-09-25. Official source. The framework on compliance.theartofservice.com.

Steps that cite it

Evidence commonly asked for

Accepted citation forms are listed on the answer format page.