AI and Australia's Cyber Security Act 2024

What changed, and why it lands on Australian businesses
For most of the last decade, ransomware was a problem you handled quietly. You either paid, restored from backup, or absorbed the loss, and you decided for yourself whether to tell anyone. That era is over.
Australia's first standalone cyber security law, the Cyber Security Act 2024, introduced a mandatory ransomware and cyber extortion payment reporting regime. The obligation became effective on 30 May 2025, and according to the Australian Government there is no grace period. If your business makes a ransomware payment, or becomes aware that one was made on your behalf, you have 72 hours to report it to the Australian Signals Directorate through the Australian Cyber Security Centre.
The threshold is what pulls a lot of organisations into scope. Under the Cyber Security (Ransomware Reporting) Rules 2025, the obligation applies to businesses carrying on a business in Australia with an annual turnover above $3 million in the previous financial year, plus responsible entities for critical infrastructure assets under the Security of Critical Infrastructure Act 2018. A $3 million turnover threshold captures a very large slice of Australian business.
This reaches a long way past banks and telcos. It is a default-on duty for almost every established Australian company sitting above that turnover line, and most of them have not updated their incident response plans to match.
The headline facts
- Reporting is triggered by a payment, not by the attack itself.
- You have 72 hours from making the payment, or from becoming aware a payment was made on your behalf.
- The turnover threshold is $3 million, set by the Cyber Security (Ransomware Reporting) Rules 2025.
- Reports go to the Australian Signals Directorate via the ACSC.
- There is no minimum payment value. A non-monetary benefit (data, services, goods) still counts.
The threat picture is getting more expensive, not less
The case for taking this seriously is not abstract. The ASD Annual Cyber Threat Report 2024-25 records that ASD's ACSC received more than 84,700 cybercrime reports through ReportCyber and responded to over 1,200 cyber security incidents, an 11 per cent increase on the prior year. It responded to 138 ransomware incidents, and described ransomware as the most disruptive cybercrime threat of the year.
The cost trend is the part that should worry a board. The same report found that the average self-reported cost of cybercrime for medium-sized businesses rose 55 per cent to $97,200 in FY2024-25. Small businesses averaged $56,600, up 14 per cent, and larger organisations averaged $202,700.
Average self-reported cost of cybercrime per report (ASD 2024-25)
Those figures are the cost of the incident itself. They sit on top of the new compliance exposure: civil penalties of up to 60 penalty units (currently around $19,800) for failing to report a payment inside the window. Of the two, the reporting failure is the avoidable cost. The attack might be bad luck. Missing the 72-hour clock is a process failure.
Do you actually have to report? A quick filter
The obligation is narrower than the panic around it suggests. It is triggered by a payment, not by an intrusion. If you never pay, the ransomware reporting duty in the Cyber Security Act 2024 does not bite, though other obligations may (see the section on overlapping duties below).
Does the ransomware payment reporting duty apply to you?
The trap is the phrase "made on your behalf". If an incident response retainer, a managed security provider, an insurer or a parent company makes the payment for you, the clock still runs for your business. That is why the reporting obligation has to be wired into your contracts and your incident playbook as well as your finance approvals.
The 72-hour clock is an operations problem, not a legal one
Lawyers can tell you what the form requires. They cannot tell you, at 2am on a Saturday, which systems were touched, what data left the building, and whether a payment has already been authorised by your offshore IT contractor. That is an operations and detection problem, and it is exactly where the 72-hour clock breaks down for under-prepared businesses.
Here is the realistic sequence of events that the law now wraps a deadline around.
The ransomware reporting clock
The compliance failure mode is almost always "we could not assemble the facts in time because nobody could see across the environment fast enough", and almost never a refusal to report. That is the gap where AI earns its place, and also where badly governed AI creates new exposure.
Where AI genuinely helps
Used well, AI shrinks the time between detection and a defensible understanding of what happened. What you get is faster, more consistent investigation under pressure. Prevention remains a separate problem with its own toolset. For a deeper treatment of automated investigation patterns, see our write-up on building an AI agent for support and incident investigation.
Detection and anomaly triage. Behavioural detection models flag the lateral movement, mass file changes and unusual data egress that precede an extortion demand. This is the same class of pattern-matching we covered in AI-powered fraud detection for Australian business: the model learns normal, then surfaces the abnormal for a human to judge.
Investigation acceleration. When the clock is running, an AI investigation agent can correlate logs, endpoint telemetry, identity events and database access far faster than an analyst working alone, then assemble a draft timeline of what was touched and when. That draft is what a human responder needs to answer the report's questions accurately. This is the core idea behind our on-premise investigation tool RootCauseAI, which keeps investigation data inside the environment rather than shipping it to a third-party cloud.
Report drafting. Once the facts are scoped, a constrained AI assistant can pre-fill the factual narrative for the ASD report and the separate OAIC assessment, leaving humans to verify and approve. The win is consistency and speed, with the human sign-off left exactly where it was.
Manual vs AI-assisted incident response under the 72-hour clock
| Metric | Manual only | AI-assisted, human-approved | Improvement |
|---|---|---|---|
| Time to scope affected systems | 12-48 hours | Hours | Faster |
| Log correlation across sources | Manual, partial | Automated draft | Broader |
| Consistency of report facts | Analyst-dependent | Templated and checked | Higher |
| Human judgement on pay or report | Required | Still required | Unchanged |
The point of the last row matters. AI does not decide whether to pay, and it does not file the report on its own authority. It compresses the investigation so humans can make those calls inside the legal window.
Where AI adds risk if you are not careful
The Cyber Security Act 2024 is not the only law in the room. The moment you point AI at security telemetry, three governance issues appear.
Privacy. Security logs, identity records and forensic captures routinely contain personal information. Feeding that into an AI system is a use of personal information governed by the Privacy Act 1988 and the Australian Privacy Principles. We unpack this in detail in Privacy Act compliance for AI in Australia. Sending forensic data to an offshore model can also create data sovereignty problems precisely when you are trying to demonstrate control.
Data residency during an incident. An incident is the worst time to discover that your investigation tooling exfiltrates sensitive logs to a vendor cloud in another jurisdiction. For regulated and government-adjacent businesses, keeping investigation workloads on infrastructure you control is often the safer posture. This is the argument for private AI infrastructure over general-purpose public models for sensitive security work.
Governance and human override. An AI agent with broad read access to your environment is itself an attack surface and a control problem. Decision rights, audit trails and a kill switch are not optional. Our AI agent governance framework covering data access, privacy and human override sets out how to deploy these agents without creating a new single point of failure.
The honest summary: AI that lives inside a governed environment, with scoped access and human approval, is an asset under the 72-hour clock. An ungoverned AI agent with standing access to everything is a liability that a regulator, an insurer or an attacker can each exploit.
Overlapping duties you must not confuse
A common and dangerous mistake is to assume the ransomware payment report discharges all your obligations. It does not. These are separate regimes with separate triggers and separate recipients.
Three separate obligations from one incident
The notifiable data breach scheme administered by the OAIC is triggered by likely serious harm from unauthorised access to personal information, regardless of whether you pay anyone. The SOCI Act imposes its own incident reporting timeframes on responsible entities for critical infrastructure assets. A healthcare, finance or essential-services business can easily be inside two or three of these regimes at once from a single event.
The Cyber Security Act 2024 also introduced a limited use provision, designed to encourage businesses to engage candidly with ASD and the National Cyber Security Coordinator by restricting how information shared during an incident can be used against them. It is a meaningful protection, but it does not remove your reporting duties, and it does not cover information you give to other regulators.
What the report actually asks for
A surprising number of businesses freeze at the deadline not because they refuse to report, but because they cannot answer the questions accurately. The ASD ransomware payment report is built around the facts of the incident and the payment: who you are and your contact details, a description of the cyber security incident, details of the demand and the entity that made it where known, the impact on your business, and details of the payment or benefit provided. The Australian Government has published a factsheet on ransomware payment reporting that sets out the expected content.
Read that list again and notice what it demands: a coherent account of what happened to which systems and what data was affected. That is forensic knowledge. If your environment is a patchwork of cloud apps, on-premise servers and unmanaged endpoints with no central visibility, assembling that account inside 72 hours under crisis conditions is genuinely hard. The form is the easy part. The investigation behind it is the work.
This is the single most useful reframing for a board: the law is asking you to be able to know what happened to your own business quickly, and the form is only how you evidence it. Investing in that capability pays off whether or not you ever make a payment, because the same visibility shortens every incident, supports your separate privacy assessment, and improves your negotiating position with insurers.
Building investigation capability without a bank-sized SOC
Most businesses cannot justify a 24/7 security operations centre, and they do not need one to be compliant. What they need is enough instrumentation and enough rehearsed process that the facts can be assembled when it matters. Three foundations get you most of the way.
Centralised, retained logging. You cannot investigate what you did not record. Identity events, endpoint telemetry and the application logs that matter should flow to one place and be retained long enough to reconstruct an incident. This is unglamorous plumbing, and it is the precondition for everything else, including any AI assistance.
A defined investigation runbook. When the demand lands, nobody should be inventing the process. A short runbook that names the steps, the owners and the decision points removes the panic. The 72-hour clock is survivable when the path is already mapped.
Scoped, governed tooling that can correlate fast. This is where AI investigation tooling earns its keep, by correlating across those log sources and drafting a timeline a human can verify. The governance caveat from earlier applies in full: scoped access, human approval, audit trail, and a clear answer to where the data goes.
The businesses that handle a ransomware event well are the ones who can answer "what happened?" quickly and honestly, because they built the plumbing and rehearsed the play before the bad day arrived. Prevention spend on its own rarely gets a business to that point.
A practical 30-day readiness plan
You do not need a security operations centre the size of a bank's to be compliant. You need a defensible, written, rehearsed process. For most businesses, the work breaks into four moves.
1. Confirm whether you are in scope. Check your prior-year turnover against the $3 million threshold and confirm whether you are a responsible entity under the SOCI Act. If you are in scope, write it down and tell the board.
2. Wire the 72-hour clock into your incident plan. Name the person who can authorise a payment, the person who owns the ASD report, and the trigger that starts the clock. Just as important, extend this to your contracts: if a managed security provider, insurer or parent could pay on your behalf, your playbook must capture that the clock starts for you.
3. Decide your AI posture before the incident. Choose now whether investigation workloads run on infrastructure you control. Scope AI access to least privilege, require human approval for the pay-or-report decisions, and keep an audit trail. Retrofitting governance during a live incident is how businesses turn one breach into two.
4. Rehearse it. A 90-minute tabletop exercise that walks a simulated ransomware payment through detection, scoping, the pay decision, the ASD report and the parallel OAIC assessment will expose more gaps than any policy document. Run it before you need it.
For the broader control environment that wraps all of this together, our AI governance framework for Australian business maps the standards regulators and insurers already recognise to a staged rollout.
The bottom line
The Cyber Security Act 2024 did not make ransomware more likely. It made silence more expensive. The businesses that will handle this well are the ones that decided, in advance, who starts the clock, who can stop the bleeding, and how they will assemble the facts fast enough to report honestly inside 72 hours. The size of the security budget is not what separates them.
AI is a genuine accelerant for that last part, provided it lives inside a governed, sovereign environment with humans holding the decisions. Pointed at the problem carelessly, it becomes one more thing a regulator will ask you to account for.
If you want help building investigation and detection capability that respects Australian data sovereignty, start a conversation with our team. We would rather help you rehearse the plan than help you explain a missed deadline.