Microsoft Teams

If you pay a ransom, you now have to report it.

The Cyber Security Act introduced mandatory ransomware and extortion payment reporting — a genuinely new obligation most incident response plans don't cover. It exists regardless of whether paying was the right call. What matters is whether someone in your organisation knows the process before an incident happens.

  • New Obligation
  • Pairs with Essential Eight
  • Pre-Incident Readiness
  • No New Tools Needed
Review Your Incident Response Plan Free Essential Eight Checklist

What the obligation actually requires

If your organisation makes a payment in response to a ransomware or cyber extortion demand, there's now a mandatory requirement to report that payment to the relevant government body — separate from, and in addition to, any existing requirement to notify the OAIC if personal information was also involved. The obligation applies regardless of whether the payment decision itself was the right call.

Nobody knows the obligation exists

The people making the payment decision under time pressure are focused on business continuity, not a compliance obligation they've never had reason to think about.

No defined reporting owner

"Someone will handle it" gets missed in a crisis the same way any unassigned task does. It needs a named owner before an incident, not during one.

Legal isn't looped in early enough

By the time most businesses check what they're required to report, the payment has often already happened and the clock is already running.

What a defensible process looks like

This doesn't need to be complicated — but it does need to exist before an incident, not during one.

Named decision authority

Who has authority to approve or refuse a ransom payment, documented in the incident response plan.

Defined reporting trigger

The moment a payment decision is made, the clock starts — and a specific named person is responsible for the report.

Pre-drafted reporting template

Know what information needs to be captured before you're reconstructing it under pressure — amount, method, affected systems, threat actor details where known.

Tested tabletop exercise

Most incident drills stop at "systems restored." A proper exercise rehearses the reporting obligation too, not just detection and recovery.

Why this pairs naturally with Essential Eight

The strongest defence against ever facing this obligation is not being ransomed in the first place — exactly what an Essential Eight uplift reduces the likelihood of. Application control, patching, MFA and regular tested backups are the controls that most directly cut ransomware risk and recovery time. But Essential Eight reduces the probability of an incident; it doesn't remove the obligation to be ready if one happens anyway. We build ransomware payment-reporting readiness as a standard add-on to Essential Eight engagements — the decision authority, the reporting template, the tabletop exercise — because the two are naturally the same conversation.

Essential Eight Services Free Readiness Checklist

Related

Essential Eight ML2 uplift, fixed price Free Essential Eight Checklist Score your maturity in 15 minutes Essential Eight Explained Complete guide

Does your incident response plan cover this obligation?

A short, focused review — usually resolved inside an Essential Eight engagement or as a standalone workshop.

Book a Call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.