Support
Contact
Book a Free ReviewCall 1300 053 948
Ransomware

Ransomware reporting now has teeth: what enforcement looks like in 2026

Australia's 72-hour ransomware payment reporting rule moved from education to enforcement in 2026. Who must report, what regulators expect, and how to prepare.

The 72-hour ransomware payment reporting rule spent its first months in "education mode". That grace period is over — from January 2026, the regulator moved to active enforcement. Here's what that changes.

When Australia's Cyber Security Act introduced mandatory ransomware payment reporting, the Department of Home Affairs flagged a soft launch: through 2025, the focus was awareness, not penalties. That posture formally changed — from 1 January 2026, Home Affairs adopted a compliance and enforcement approach. We covered the rule itself when it landed; this is the update on what enforcement means in practice.

Who has to report, again?

A business must report if it carries on business in Australia with annual turnover above $3 million (or is in critical infrastructure), and it — or someone on its behalf — makes a ransomware payment or gives any benefit to an extorting party. The report goes to the Australian Signals Directorate within 72 hours of the payment being made. Note the trigger carefully: the clock starts at payment, not at the attack, and "benefit" is broader than cash.

What does enforcement actually look like?

Enforcement means the difference between a rule and a consequence. In practice, expect:

Civil penalties for non-reporting.

Failing to report a payment within 72 hours now carries real exposure, where in 2025 it drew guidance letters.

Follow-up questions.

Reports feed ASD's national threat picture, and reported incidents can draw requests for further detail — another reason clean incident records matter.

Cross-checking.

Regulators see incidents from multiple angles — data breach notifications to the OAIC, insurance claims, public leak sites. A payment that surfaces elsewhere but was never reported is the worst position to be in.

One important protection remains: the scheme's limited-use rules mean information you report cannot be freely weaponised against you for other regulatory purposes. The design intent is honest reporting, not ambush.

What should be in your playbook before you ever need it?

The businesses that handle this well decided everything before the incident. Your incident response plan should already name:

Who decides on payment

a named decision-maker plus legal advice, because paying is a legal, ethical and practical minefield (and no guarantee of recovery).

Who files the report

with the 72-hour clock, the ASD reporting step must be on the checklist, owned by someone, not assumed.

What gets recorded

timeline, communications, amounts, wallet details. If a payment happens under duress at 2am, the record is what protects you later.

How you avoid the whole question

immutable backups and tested recovery so payment is never the only path back.

FAQ

Frequently asked questions

We're under $3 million turnover — does any of this apply?

The mandatory reporting obligation does not, but voluntary reporting to ASD is encouraged and genuinely useful — and if personal information was taken, Privacy Act notification duties apply at any size.

Does reporting a payment get us in trouble for paying?

Paying a ransom is not illegal in most circumstances (sanctions being the exception to check with lawyers), and the scheme's limited-use protections exist so reporting is not self-incrimination. Not reporting is what now carries the penalty.

What if our IT provider or insurer pays on our behalf?

The obligation still lands on your business — payments made on your behalf count. Make sure any provider or insurer involved in a negotiation knows the reporting step is non-negotiable and time-boxed.

Isn't the best strategy just never paying?

Never needing to pay is the strategy. That is a backup, detection and response capability built before the incident — which is precisely what our 24/7 SOC and recovery services exist for.

Pressure-test your plan

If you cannot name your payment decision-maker and your report-filer right now, your plan has a gap. We build and rehearse these playbooks with clients — a one-hour tabletop exercise now beats a 2am scramble later.

Book your free IT & Cyber Security Review

See exactly where your IT and security stand, and what to fix first. No jargon, no obligation.