Free tool · no sign-up
Four quick questions about your organisation and the incident. We'll tell you, in plain language, whether the Cyber Security Act 2024's ransomware/cyber extortion payment reporting rules apply to you — and exactly who to report it to.
General guidance only — not legal advice. It covers the ransomware/cyber extortion payment reporting obligation under the Cyber Security Act 2024 specifically; it does not assess other obligations (e.g. the separate SOCI Act incident-reporting duty for critical infrastructure entities, or the Notifiable Data Breaches scheme). Confirm your position with legal counsel or the ACSC directly. Rules current as of 2026-08-02.
Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.
Estimate based on typical engagement patterns. Precise scope confirmed on call after reviewing your environment.
Talk to us — a free 30-minute call covers your reporting obligations, your technical gaps, and a fixed-price plan to close them.
Hi! I’m the Compliance365 AI. I can help you work out which security or privacy framework you need, explain what’s involved, and answer questions about ISO 27001, SOC 2, Essential Eight, and more.
What can I help you with today?
Messages are sent to our AI assistant (Claude, by Anthropic) to generate a reply — not stored as part of your account and not used to train AI models.