For most small and medium business owners, a ransomware attack has always felt like a technical problem. You call IT, you assess the damage, and you decide whether to pay. The new mandatory ransomware reporting rules change that. A ransomware attack is now a legal event as well as a technical one. How you respond has consequences for your insurance cover, your contracts and your position as a director.
The payment reporting regime has applied since 30 May 2025. The education-first phase ended on 31 December 2025, and the Department of Home Affairs has taken a more active regulatory approach since 1 January 2026. The direction of travel is clear. Reporting is shifting from voluntary to compulsory, and regulators expect businesses to treat a ransomware incident with the same seriousness as a workplace injury or a tax issue.
What the New Reporting Rules Require
Part 3 of the Cyber Security Act 2024 (Cth) requires a reporting business entity to report a ransomware or cyber extortion payment to the Australian Signals Directorate within 72 hours of making it, or of becoming aware that someone made it on the entity’s behalf. The Cyber Security (Ransomware Payment Reporting) Rules 2025 set the turnover threshold and the information the report must contain. The Home Affairs factsheet explains the mechanics.
The obligation applies to a business with annual turnover above $3 million in the previous financial year, and to responsible entities for critical infrastructure assets. A business that operated for only part of the previous year uses a pro-rata threshold. Many SMEs fall below the threshold. They have no obligation to report a payment, but they can still report the incident to the Australian Signals Directorate voluntarily.
Three points matter for business owners. First, the obligation arises only when a ransom is paid. An attack or a demand alone does not trigger it. Second, a failure to report can attract a civil penalty of up to 60 penalty units. Third, the Act restricts how the government can use the report. The information in it is generally inadmissible in criminal proceedings, civil penalty proceedings and tribunal proceedings, subject to limited exceptions. The report itself is not the main risk. The underlying incident is, because it may trigger separate obligations under the Privacy Act, your insurance policy and your customer contracts.
Australia is among the first jurisdictions to mandate reporting of ransomware payments. A comparative legal analysis of ransomware responses describes the Australian law as the first of its kind and notes that Canada has debated a similar requirement. The United States has legislated reporting for critical infrastructure operators, and the United Kingdom has proposed a broader regime. The trend is toward transparency, not silence.
Reporting is only one layer
Separate from the payment reporting regime, the Notifiable Data Breaches scheme requires entities covered by the Privacy Act to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals of an eligible data breach. A breach is eligible where it is likely to result in serious harm. A ransomware attack that exposes personal information will often meet that test. You must assess a suspected breach promptly and within 30 days, and notify as soon as practicable once you have reasonable grounds to believe an eligible breach has occurred.
Coverage depends on size and sector. Most businesses with annual turnover of $3 million or less are exempt from the Privacy Act. The exemption does not apply to health service providers. From 1 July 2026, it also no longer protects many businesses newly regulated under the anti-money laundering reforms, including lawyers, accountants and real estate agents. The government has agreed in principle to remove the exemption entirely, but the current exposure draft of the next privacy reform bill does not do so.
This is where non-technical owners get caught out. They assume one report covers everything. It rarely does. A business above the thresholds may need to report a payment to the Australian Signals Directorate, notify the OAIC and affected individuals, notify its insurer and notify customers under contract, each on a different timetable.
How Mandatory Ransomware Reporting Rules Affect Your Insurance
Cyber insurance policies typically require you to notify your insurer as soon as you become aware of an incident. They also require you to cooperate with the insurer’s chosen response team. If you notify late, or if you handle the incident yourself without telling the insurer, you risk having a claim declined.
Payment decisions matter too. Some policies will not cover a ransom payment at all. Others will only cover it if the payment was lawful, reported, and made with the insurer’s agreement. Paying first and asking questions later can lead your insurer to decline the claim.
There is a second insurance issue that catches SMEs. Many businesses assume their general liability or business interruption policy covers cyber events. It usually does not. Cyber cover is a separate product, and the terms vary widely. If you have not read your policy since you bought it, now is the time.
What insurers now expect
- A documented incident response plan that names who decides what
- Evidence of basic controls, such as multi-factor authentication and offline backups
- Prompt notification, often within hours rather than days
- A clear record of the ransom decision and the reasoning behind it
Insurers are increasingly asking for these things at the underwriting stage, not just at claim time. A business that cannot show basic controls may struggle to get cover at all, or may face a much higher premium.
Director Liability Is the Part Most Owners Miss
Company directors have a statutory duty to act with care and diligence. Regulators expect boards to oversee cyber risk, and courts now penalise companies that fail to manage it.
In the first civil penalty proceeding under the Privacy Act, the Federal Court ordered Australian Clinical Labs (ACL) to pay $5.8 million over a 2022 cyber attack on its Medlab Pathology business. The penalties included $1.6 million for failing to assess the breach promptly and failing to notify the OAIC as required. In February 2026, the Federal Court ordered FIIG Securities to pay $2.5 million following ASIC proceedings over cyber security failures. Our analysis of the Medlab case and director liability sets out why boards can no longer treat cyber as purely operational.
Both decisions penalised the company, not individual directors. The personal risk for directors is less direct, but it is real. If a ransomware attack causes harm that better governance would have prevented, directors may face scrutiny over whether they met their duty of care and diligence. That risk does not disappear because the business is small. Smaller businesses often have weaker controls, which makes the gap between what was reasonable and what was done easier to identify.
Reporting obligations feed into this. A failure to report a payment when required is itself a contravention. The ACL decision shows that the way a business assesses and notifies a breach can attract penalties separate from the breach itself.
Reducing Your Exposure Before an Incident
The cheapest time to deal with ransomware is before it happens. A few practical steps reduce both legal and commercial risk.
Cut down what you hold
You cannot lose data you do not have. Australian Privacy Principle 11.2 requires entities covered by the Privacy Act to destroy or de-identify personal information once they no longer need it for a permitted purpose, unless the law requires them to keep it. Our article on data minimisation and breach risk explains how reducing stored personal information lowers your liability if a breach occurs. It also reduces the number of people you may need to notify.
Get your contracts right
Check what your customer contracts say about breach notification. Some may require you to notify within tighter timeframes than the law requires. If you cannot meet those deadlines, you are in breach of contract even if you comply with the law.
The same applies to your suppliers. If a vendor holds your data, your contract should set out who reports what, and who pays for the response. If a negotiator or related company pays a ransom on your behalf, the obligation to report the payment remains yours.
Rehearse the decision
Decide now who has authority to approve a ransom payment, who calls the insurer, who handles regulator contact, and who lodges the payment report within 72 hours. These decisions are hard to make under pressure at 2am. Build a sanctions check into the plan. A payment to a sanctioned person or entity may breach Australian sanctions law and attract criminal penalties. A one-page plan is enough for most SMEs.
Learn from enforcement
Regulators are watching how businesses respond to data incidents. The ACL and FIIG decisions show that courts will penalise failures in preparation, assessment and notification. The Meta settlement and its lessons show that the regulator will pursue a privacy matter for years to reach an outcome.
Where This Leaves SME Owners
Mandatory ransomware reporting is not just another form to file. It adds a hard deadline to an incident that already carries privacy, insurance and contractual obligations. Regulators, insurers and courts will later examine the decisions you make in the first days, so record those decisions and your reasons as you go.
For owners, the practical response is straightforward. Confirm whether you meet the reporting thresholds, check your insurance cover, and put a short incident plan in place. If you handle personal information at scale, or you operate in healthcare, professional services or logistics, the risk is higher and the margin for improvisation is smaller.
If you would like to review your incident response plan, your cyber cover or your customer contracts before something goes wrong, our team can help you work through the options.
Book an appointment with one of our Lawyers to discuss your specific needs.
Book a ConsultationA Note on the Information We Share
Reading this information does not create a lawyer-client relationship between you and SLK Lawyers. This only occurs with a formal written agreement. Content is current at publication and applies to Victorian law unless stated otherwise. It is general information only and not a substitute for specific legal advice. Strict time limits apply to legal claims. You should seek immediate legal advice on your specific situation to ensure your rights are protected.