Australian businesses might soon be required to report any ransom payments made to cybercriminals to the government.
Previously, the Australian government explored an outright prohibition on ransom payments, but this proposal did not advance. Instead, a more moderate approach was suggested in the national cybersecurity strategy released last November. In a single, discreet sentence within the strategy, the government indicated its intention to “co-design with industry a no-fault, no-liability ransomware reporting obligation for businesses.”
This new requirement will be integrated into the forthcoming Cyber Security Act, which is set to be introduced in parliament in the next few weeks. Under the proposed legislation, companies with annual revenues exceeding $3 million AUD (approximately $1.96 million USD) will be obligated to report any ransom payments they make.
Beth Burgin Waller, chair of the Cybersecurity & Data Privacy practice at Woods Rogers Vandeventer Black (WRVB), elaborates, “The aim of such legislation is to provide governments with visibility into the flow of funds to malicious actors, facilitating the tracking of these payments and aiding in the pursuit of criminals.”
She notes that the proposed Australian bill resembles the U.S. CIRCIA (Cyber Incident Reporting for Critical Infrastructure Act of 2022), which mandates that covered entities report ransom payments to CISA within 24 hours. However, the Australian proposal is broader, applying to all businesses making ransom payments, unlike CIRCIA which applies to a more narrowly defined group of entities.
Will Mandated Ransom Disclosure Be Effective?
Australia has faced several significant cyberattacks in recent years. In 2022, Optus, a major telecommunications provider, suffered a breach affecting millions of consumer records. Soon after, health insurance provider Medibank experienced a similar breach. Last year, a cyberattack disrupted four major ports across the country for a weekend, among other incidents.
The financial impact on Australia’s economy has been substantial. Former minister O’Neil highlighted in the 2023–2030 Australian Cyber Security Strategy that a cyber incident is reported to the government every six minutes. Ransomware alone causes about $3 billion in damage annually to Australian organizations, with cyberattack costs increasing by 14% each year.
The new regulations will affect different types of organizations in various ways. Larger corporations are better equipped to manage compliance costs and stand to benefit from clearer regulations.
Waller points out, “As similar laws emerge globally, multinational companies with operations in Australia face a complex compliance landscape, creating a patchwork of regulations.”
Conversely, smaller organizations, which often have fewer resources, might struggle with the financial and administrative burdens of compliance. The Australian Chamber of Commerce and Industry (ACCI) supports parts of the Cyber Security Act but suggests raising the revenue threshold for affected businesses to $10 million. Reports also indicate that non-compliance fines will be set at $15,000.
Encouraging Better Cybersecurity Practices
The anticipated benefits of the law include increased transparency for law enforcement and enhanced incentives for businesses to improve their cybersecurity practices. A spokesperson from the Australian Department of Home Affairs stated, “Improved visibility into ransomware and cyber extortion threats is crucial for enhancing risk mitigation and preparedness across the economy. Timely reporting will help tailor victim support and strengthen collective security against future attacks.”
Anne Cutler, cybersecurity advocate at Keeper Security, adds, “Mandatory disclosures may lead companies to rethink their strategies regarding negotiations with cybercriminals. Knowing that they must report ransom payments could motivate business leaders to invest more in preventative measures and robust incident response plans to avoid the scrutiny of public disclosure.”
This article was updated on August 2, 2024, at 10:15 a.m. ET to include comments from the Australian Department of Home Affairs.



