NEWS

Australia Mandates Ransomware Payment Disclosure

Australia now requires businesses to disclose ransomware payments within 72 hours of occurrence. This new mandate, effective May 29, 2025, aims to gather crucial intelligence on cybercrime, reflecting the difficult reality companies face in combating attacks.

By
LNGFRM Team
Published June 12, 2025
Two web page outlines linked by a chain secured with a padlock.
Illustration by Addison Smith for LNGFRM

The digital frontier just got a little more complicated for Australian businesses.

As of May 29, 2025, a landmark requirement has come into effect, compelling companies to disclose the uncomfortable truth of ransomware payments.

This isn’t just another bureaucratic hurdle; it’s a stark acknowledgment of the pervasive threat of cybercrime and a strategic pivot in how Australia intends to combat it.

For any “reporting business entity” – typically those with an annual turnover exceeding AU$3 million, alongside certain critical infrastructure operators – the clock starts ticking the moment a ransomware payment is made, or they become aware it has been.

A mere 72 hours is all they have to fess up to the Australian Signals Directorate (ASD), the nation’s cyber intelligence arm, via a new online portal.

Failure to comply with this tight deadline could result in a civil penalty nearing AU$20,000, a sum that pales in comparison to the average ransom demand but adds insult to injury for an already victimized business.

This new mandate places businesses in an unenviable position, navigating a complex ethical and practical minefield.

On one hand, the ASD, consistent with global cybersecurity advice, vehemently urges companies never to pay a ransom.

Their reasoning is sound: there’s no guarantee criminals will honour their word, and every payment fuels the illicit economy that underpins these attacks.

Yet, the very existence of this reporting requirement underscores a pragmatic, if reluctant, acceptance of commercial reality.

Businesses, particularly those facing existential threats to their operations or data integrity, often find themselves with little choice but to pay up.

A 2024 McGrathNicol survey painted a grim picture, revealing the average Australian cyber ransom payment hit a staggering AU$1.35 million.

Even more telling, a mere one in ten businesses surveyed claimed they would never pay under any circumstances.

This new law, therefore, isn’t just about disclosure; it’s an implicit recognition of the difficult decisions businesses are forced to make when their digital lives hang in the balance.

The paradox is clear: the government advises against payment, but legislates for its reporting, effectively saying, “If you pay, tell us.”

This isn’t hypocrisy; it’s a tactical move.

By mandating disclosure, the ASD gains invaluable intelligence.

Each report contributes to a clearer, more granular understanding of the ransomware ecosystem targeting Australia: who is being targeted, by whom, how much they are paying, and perhaps, the methods of attack and recovery.

This data, aggregated and analysed, could prove instrumental in identifying trends, tracking criminal syndicates, and ultimately, bolstering national cyber defences.

Crucially, the legislation includes a significant safeguard: information provided in these reports cannot be used by the ASD or other government agencies for unrelated purposes, such as investigating breaches of the Privacy Act in connection with the incident.

This provision is designed to encourage transparency, alleviating fears that reporting a ransom payment might open the door to further regulatory scrutiny or penalties for the initial security incident.

It’s a delicate balance, aiming to gather critical intelligence without unduly punishing victims.

Yet, the burden of this new requirement falls squarely on businesses.

It’s not just about the 72-hour reporting window; it’s about the underlying imperative for robust cyber resilience.

This legislation serves as a loud and clear siren call for companies to conduct thorough cyber health checks and, perhaps more importantly, to maintain an up-to-date and actionable Data Breach Response Plan.

The time to prepare for a ransomware attack is not when the encrypted files appear on your screen, but long before.

Understanding the reporting obligations, having clear internal protocols for incident response, and knowing who to contact within the ASD are now non-negotiable elements of good corporate governance.

The introduction of this reporting obligation marks a maturation in Australia’s approach to cybersecurity.

It moves beyond simply urging prevention to acknowledging the grim reality of compromise.

It’s an admission that ransomware is not just a technical problem, but an economic and national security one.

The data collected from these mandatory reports will undoubtedly paint a more comprehensive picture of the threat landscape, allowing for more targeted law enforcement efforts, better intelligence sharing, and potentially, more effective international cooperation in disrupting these criminal enterprises.

However, the ultimate goal remains prevention.

While the government now has a window into the extent of ransomware payments, the ideal scenario is for businesses to never have to make such a report.

This new law, therefore, is a powerful reinforcement of the message that investment in cybersecurity is not an optional expense but a fundamental cost of doing business in the digital age.

It’s a call to action for every Australian enterprise to fortify its digital walls, because while the government now wants to know if you pay the price, they’d much rather you didn’t have to pay it at all.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

Mohit Bansal: On Zero-Headcount Security Scaling

Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.

By Mike Malone
Published June 30, 2026
© 2026 LNGFRM. All rights reserved.