Free tool · no sign-up
Do you have a mandatory ransomware payment reporting obligation?
Four quick questions about your organisation and the incident. We'll tell you, in plain language, whether the Cyber Security Act 2024's ransomware/cyber extortion payment reporting rules apply to you — and exactly who to report it to.
General guidance only — not legal advice. It covers the ransomware/cyber extortion payment reporting obligation under the Cyber Security Act 2024 specifically; it does not assess other obligations (e.g. the separate SOCI Act incident-reporting duty for critical infrastructure entities, or the Notifiable Data Breaches scheme). Confirm your position with legal counsel or the ACSC directly. Rules current as of 2026-08-02.
Get a realistic scope in 30 seconds
Three questions. Instant estimate including the third-party platform licence costs you'll avoid. No sign-up.
Estimate based on typical engagement patterns. Precise scope confirmed on call after reviewing your environment.
Not sure if you're covered by Essential Eight or need broader incident response readiness?
Talk to us — a free 30-minute call covers your reporting obligations, your technical gaps, and a fixed-price plan to close them.