Skip to content
Back to Knowledge Base
Compliance

Australia's Cyber Security Act 2024: What Your Business Needs to Know

26 July 20266 min read
Australia's Cyber Security Act 2024: What Your Business Needs to Know

Australia passed its first standalone cyber security law in November 2024. The Cyber Security Act 2024 (Cth) received Royal Assent on 29 November 2024 as the centrepiece of the Cyber Security Legislative Package, which also amended the Security of Critical Infrastructure Act 2018 (SOCI Act) and the Intelligence Services Act. Despite the name, this is not a law aimed only at government agencies and critical infrastructure — parts of it apply directly to ordinary businesses, and the ransomware reporting obligation in particular has caught many mid-sized organisations unprepared.

This article explains what the Act actually requires, who it applies to, and the practical steps worth taking now.

The four pillars of the Act

The Act does four main things:

  1. Mandatory security standards for smart devices. Manufacturers and suppliers of consumer-grade smart (IoT) devices sold in Australia must meet minimum cyber security standards — covering things like password security, vulnerability reporting and transparency about how long security updates will be provided. These standards took effect on 4 March 2026, after a twelve-month transition period.
  2. Mandatory ransomware and cyber extortion payment reporting. Certain businesses must report ransomware payments to the government within 72 hours. This commenced on 30 May 2025 and is the pillar most likely to affect a small or medium business.
  3. "Limited use" protections for voluntarily shared incident information. Information a business voluntarily shares with the Australian Signals Directorate (ASD) or the National Cyber Security Coordinator during an incident can only be used for limited purposes — it cannot simply be handed to other regulators to build an enforcement case against you. The intent is to make it safer to ask the government for help early.
  4. A Cyber Incident Review Board. A standing body that conducts no-fault reviews of significant cyber incidents — similar in spirit to transport safety investigations — and publishes lessons for industry.

The ransomware payment reporting obligation

This is the part every Australian business above a modest size needs to understand.

Who must comply. You are a "reporting business entity" if you carry on business in Australia and had annual turnover of $3 million or more in the previous financial year. Responsible entities for critical infrastructure assets must comply regardless of turnover. Commonwealth and State government bodies are exempt. Note the threshold: $3 million turnover captures a very large share of Australian SMBs — this is not a big-business-only rule.

What must be reported. A ransomware or cyber extortion payment — whether made by you or by someone on your behalf, such as an insurer or incident response firm. The obligation is triggered by the payment, not by the attack itself, and there is no minimum payment amount. Paying a ransom is not itself illegal under the Act, though separate legal risks apply (for example, sanctions law if the recipient is a sanctioned entity), so payment decisions should always involve legal advice.

The deadline. Within 72 hours of making the payment, or of becoming aware that a payment was made on your behalf. Reports are made to the Australian Signals Directorate and the Department of Home Affairs via the ReportCyber portal at cyber.gov.au.

Penalties. Failing to report is a civil penalty provision carrying up to 60 penalty units — roughly $20,000 at current penalty unit values. That figure is modest, but the real exposure is reputational and regulatory: an unreported payment that later surfaces raises obvious questions for insurers, customers and other regulators. Enforcement began with an education-first phase and has since moved into active enforcement, so "we did not know" is no longer a comfortable position.

The smart device standards

If your business manufactures or supplies consumer smart devices in Australia, you now have direct obligations: devices must meet the mandatory security standard, and you must be able to produce a statement of compliance. For everyone else, the impact is indirect but useful — the standard lifts the baseline security of the cameras, sensors and networked gadgets that end up connected to business networks, and the published security support periods give you something concrete to ask vendors about before you buy.

Limited use protections: why they matter to you

One of the least discussed but most practical parts of the Act is the limited use obligation. Historically, many businesses avoided engaging with government during an incident out of fear that information handed to ASD would end up with the OAIC, ASIC or another regulator and be used against them. The Act restricts how voluntarily shared incident information can be used and disclosed: it can be used to help you respond and to build national threat intelligence, but not as a backdoor evidence-gathering channel for other enforcement action (subject to limited exceptions, such as serious criminal matters).

The practical takeaway: reporting an incident early to ASD and the National Cyber Security Coordinator is now a lower-risk, higher-value move than it used to be. Build this into your incident response plan.

What about the SOCI Act changes?

The same legislative package amended the SOCI Act, which regulates Australia's critical infrastructure sectors. The amendments refine how the regime works — including clearer treatment of data storage systems holding business-critical data, and a shift towards an all-hazards risk management approach. If you are a critical infrastructure entity, these changes matter directly. If you are not, the relevance is mostly indirect: SOCI-regulated customers are increasingly pushing security and incident-notification requirements down into their supply chains, so expect tighter contractual obligations if you service critical infrastructure sectors.

What your business should do now

  1. Confirm whether you are in scope for ransomware reporting. If your turnover is $3 million or more, you are. Put the 72-hour reporting obligation in writing, assign an owner, and make sure your board or leadership team knows it exists.
  2. Write a payment decision playbook before you need it. The worst time to decide whether to pay a ransom is at 3am during an incident. Document your position in advance: who decides, what legal and sanctions checks are required, how your insurer is involved, and who files the ReportCyber report. Your insurer's consent is often required before payment under the policy — get this sequence clear now.
  3. Review your incident response plan. It should cover detection, containment, internal escalation, insurer notification, legal counsel, government reporting (both ransomware payments and, where applicable, Notifiable Data Breaches obligations to the OAIC), and communications. Then exercise it — a plan nobody has rehearsed is a hypothesis.
  4. Get the fundamentals right. Ransomware succeeds against businesses with weak MFA, unpatched systems and untested backups. The Essential Eight remains the best baseline for Australian SMBs, and it is what insurers and enterprise customers will benchmark you against.
  5. Check your cyber insurance wording. Confirm whether ransom payments and extortion costs are covered, what notification obligations the policy imposes, and how the policy interacts with the new statutory reporting duty.

The bigger picture

The Cyber Security Act 2024 signals a clear direction of travel: ransomware payment is now a regulated event, incident transparency is being encouraged through legal protections, and baseline product security is becoming mandatory. None of this requires panic, but it does require preparation — an incident response plan that reflects the law as it is, not as it was.

If your organisation needs help working out which obligations apply and turning them into a workable incident response and governance framework, a vCISO engagement provides that senior security leadership on a retainer basis — without the cost of a full-time hire. The businesses that handle these requirements well are the ones that prepared before the incident, not during it.

ComplianceCyber Security ActRansomwareRegulation

Need Help With Your Security?

Our team of experts can guide you through implementation and certification. Start with a free assessment.

Start Free Assessment