Skip to content
Legislation
Skip to legislation

Cyber Security Act 2024 · Version 2024-11-29

Part 3—Ransomware reporting obligations

Register source version C2024A00098 · Source observation:

Reading presentation · Verification limits and dated status · No live currency check

Part 3—Ransomware reporting obligations

Read this container only

Division 1—Preliminary

Read this container only

25 Simplified outline of this Part

:::box This Part imposes reporting obligations on certain entities who are impacted by a cyber security incident, and who have provided or are aware that another entity has provided, a payment or benefit (called a ransomware payment) to an entity that is seeking to benefit from the impact or the cyber security incident.

Particular information must be included in a ransomware payment report, including information relating to the cyber security incident, the demand made by the extorting entity and the ransomware payment.

An entity may be liable to a civil penalty if the entity fails to make a ransomware payment report as required by this Part. :::

Division 2—Reporting obligations

Read this container only

26 Application of this Part

  • (1) This Part applies if:
  • (a) an incident has occurred, is occurring or is imminent; and
  • (b) the incident is a cyber security incident; and
  • (c) the incident has had, is having, or could reasonably be expected to have, a direct or indirect impact on a reporting business entity; and
  • (d) an entity (the extorting entity) makes a demand of the reporting business entity, or any other entity, in order to benefit from the incident or the impact on the reporting business entity; and
  • (e) the reporting business entity provides, or is aware that another entity has provided on their behalf, a payment or benefit (a ransomware payment) to the extorting entity that is directly related to the demand.
  • (2) An entity is a reporting business entity if, at the time the ransomware payment is made:
  • (a) the entity:
    • (i) is carrying on a business in Australia with an annual turnover for the previous financial year that exceeds the turnover threshold for that year; and
    • (ii) is not a Commonwealth body or a State body; and
    • (iii) is not a responsible entity for a critical infrastructure asset; or
  • (b) the entity is a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies.
  • (3) For the purposes of subparagraph (2)(a)(i), the turnover threshold is:
  • (a) if a business has been carried on for only part of the previous financial year—the amount worked out in the manner prescribed by the rules; or
  • (b) in any other case—the amount prescribed by, or worked out in the manner prescribed by, the rules.

Presumption

  • (4) For the purposes of paragraph (1)(b), an incident (other than an incident covered by paragraph 9(2)(a) or (b)) is presumed to be a cyber security incident if:
  • (a) the incident was probably effected, is probably being effected or could reasonably be expected to be effected, by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
  • (b) the incident has probably impeded or impaired, or is probably impeding or impairing or could reasonably be expected to impede or impair, the ability of a computer to connect to such a service; or
  • (c) the incident has probably seriously prejudiced, is probably seriously prejudicing, or could reasonably be expected to prejudice:
    • (i) the social or economic stability of Australia or its people; or
    • (ii) the defence of Australia; or
    • (iii) national security.

Note: Paragraphs 9(2)(a) and (b) cover incidents involving critical infrastructure assets or the activities of corporations to which paragraph 51(xx) of the Constitution applies.

  • (5) However, subsection (4) does not make an entity liable to a civil penalty under this Part if the incident:
  • (a) was not in fact effected by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
  • (b) did not in fact impede or impair the ability of a computer to connect to such a service; or
  • (c) did not in fact seriously prejudice:
    • (i) the social or economic stability of Australia or its people; or
    • (ii) the defence of Australia; or
    • (iii) national security.

27 Obligation to report following a ransomware payment

  • (1) The reporting business entity must give the designated Commonwealth body a report (a ransomware payment report) that complies with the requirements of this section within 72 hours of making the ransomware payment or becoming aware that the ransomware payment has been made (whichever is applicable).

Note: For the definition of designated Commonwealth body: see section 8.

  • (2) The ransomware payment report must contain information relating to the following, in accordance with any requirements prescribed by the rules, that, at the time of making the report, the reporting business entity knows or is able, by reasonable search or enquiry, to find out:
  • (a) if the reporting business entity made the payment—the reporting business entity’s contact and business details;
  • (b) if another entity made the payment—that entity’s contact and business details;
  • (c) the cyber security incident, including its impact on the reporting business entity;
  • (d) the demand made by the extorting entity;
  • (e) the ransomware payment;
  • (f) communications with the extorting entity relating to the incident, the demand and the payment.
  • (3) The reporting business entity may include other information relating to the cyber security incident in the ransomware payment report.
  • (4) The ransomware payment report must be given:
  • (a) in the form approved by the Secretary (if any); and
  • (b) in the manner (if any) prescribed by the rules.
  • (5) An entity is liable to a civil penalty if the entity contravenes subsection (1).

Civil penalty: 60 penalty units.

  • (6) Subsection 93(2) of the Regulatory Powers Act does not apply in relation to a contravention of subsection (1) of this section.

28 Liability

  • (1) An entity is not liable to an action or other proceeding for damages for or in relation to an act done or omitted in good faith in compliance with section 27.
  • (2) An officer, employee or agent of an entity is not liable to an action for damages for or in relation to an act done or omitted in good faith in connection with an act done or omitted by the entity as mentioned in subsection (1).
  • (3) An entity that wishes to rely on subsection (1) in relation to an action or other proceeding bears an evidential burden (within the meaning of the Regulatory Powers Act) in relation to that matter.

Division 3—Protection of information

Read this container only

29 Ransomware payment reports may only be used or disclosed for permitted purposes

Permitted use and disclosure

  • (1) A designated Commonwealth body may make a record of, use or disclose information provided in a ransomware payment report by a reporting business entity, but only for the purposes of one or more of the following:
  • (a) assisting the reporting business entity, and other entities acting on behalf of the reporting business entity, to respond to, mitigate or resolve the cyber security incident;
  • (b) performing functions or exercising powers under this Part or Part 6 as it applies to this Part;
  • (c) proceedings under, or arising out of, section 137.1 or 137.2 of the Criminal Code (false and misleading information and documents) that relate to this Act;
  • (d) proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
  • (e) the performance of the functions of a Commonwealth body relating to responding to, mitigating or resolving a cyber security incident;
  • (f) the performance of the functions of a State body relating to responding to, mitigating or resolving a cyber security incident;
  • (g) the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to a cyber security incident;
  • (h) informing and advising the Minister, and other Ministers of the Commonwealth, about a cyber security incident;
    • (i) the performance of the functions of an intelligence agency.

Note: Certain information must not be disclosed to a State body under Parts of this Act unless a Minister of the State or Territory has consented to those Parts applying to the State body: see section 11.

Restriction on use and disclosure for civil or regulatory action

  • (2) However, the designated Commonwealth body must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention by the reporting business entity of a Commonwealth, State or Territory law other than:
  • (a) a contravention by the reporting business entity of this Part; or
  • (b) a contravention by the reporting business entity of a law that imposes a penalty or sanction for a criminal offence.

Note: See also section 32 in relation to admissibility of the information in proceedings against the reporting business entity.

Interaction with the Privacy Act 1988

  • (3) Subsection (1) does not authorise the designated Commonwealth body to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.

Information not covered by the prohibitions in this section

  • (4) Subsection (1) does not prohibit the recording, use or disclosure of the following information:
  • (a) information that has been provided to the designated Commonwealth body by, or on behalf of, the entity to the Commonwealth to comply with:
    • (i) a requirement in Part 2B of the Security of Critical Infrastructure Act 2018; or
    • (ii) a requirement under the Telecommunications Act 1997; or
    • (iii) a requirement under a law prescribed by the rules;
  • (b) information that has already been lawfully made available to the public.

30 Limitations on secondary use and disclosure of information in ransomware payment reports

  • (1) This section applies to information that:
  • (a) has been provided in a ransomware payment report by a reporting business entity; and
  • (b) has been obtained by another entity, Commonwealth body or State body under subsection 29(1) or this section; and
  • (c) is held by the other entity, Commonwealth body or State body.

Note: This section does not apply to the information to the extent that it has been otherwise obtained by the other entity, Commonwealth body or State body.

Permitted use and disclosure

  • (2) The other entity, Commonwealth body or State body may make a record of, use or disclose the information but only for the purposes of one or more of the following:
  • (a) assisting the reporting business entity, and other entities acting on behalf of the reporting business entity, to respond to, mitigate or resolve the cyber security incident;
  • (b) performing functions or exercising powers under this Part or Part 6 as it applies to this Part;
  • (c) proceedings under, or arising out of, section 137.1 or 137.2 of the Criminal Code (false and misleading information and documents) that relate to this Act;
  • (d) proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
  • (e) the performance of the functions of a Commonwealth body relating to responding to, mitigating or resolving a cyber security incident;
  • (f) the performance of the functions of a State body relating to responding to, mitigating or resolving a cyber security incident;
  • (g) the performance of the functions of the National Cyber Security Coordinator under Part 4 relating to a cyber security incident;
  • (h) informing and advising the Minister, and other Ministers of the Commonwealth, about a cyber security incident;
    • (i) the performance of the functions of an intelligence agency.

Restriction on use and disclosure for civil or regulatory action

  • (3) However, the other entity, Commonwealth body or State body must not make a record of, use or disclose the information for the purposes of investigating or enforcing, or assisting in the investigation or enforcement of, any contravention, by the reporting business entity, of a Commonwealth, State or Territory law other than:
  • (a) a contravention by the reporting business entity of this Part; or
  • (b) a contravention by the reporting business entity of a law that imposes a penalty or sanction for a criminal offence.

Interaction with the Privacy Act 1988

  • (4) Subsection (2) does not authorise the other entity, Commonwealth body or State body to record, use or disclose the information to the extent that it is prohibited or restricted by or under the Privacy Act 1988.

Information not covered by the prohibitions in this section

  • (5) Subsection (2) does not prohibit:
  • (a) recording, use or disclosure of information referred to in subsection 29(4); or
  • (b) if the other entity is an individual—recording, use or disclosure of personal information about the individual; or
  • (c) recording, use or disclosure of the reporting business entity’s own information, with the consent of the reporting business entity, by another entity, a Commonwealth body or a State body; or
  • (d) recording, use or disclosure of information for the purposes of carrying out a State’s constitutional functions, powers or duties.

Civil penalty for contravention of this section

  • (6) An entity is liable to a civil penalty if:
  • (a) the entity contravenes subsection (2); and
  • (b) the entity is not a Commonwealth officer; and
  • (c) any of the following applies:
    • (i) the information is sensitive information about an individual and the individual has not consented to the record, use or disclosure of the information;
    • (ii) the information is confidential or commercially sensitive;
    • (iii) the record, use or disclosure of the information would, or could reasonably be expected to, cause damage to the security, defence or international relations of the Commonwealth.

Note 1: See the Criminal Code for offences for Commonwealth officers.

Note 2: This Act does not make the Crown (other than an authority of the Crown) liable to a civil penalty.

Civil penalty: 60 penalty units.

32 Admissibility of information in ransomware payment report against reporting business entity

  • (1) This section applies to information that:
  • (a) has been provided in a ransomware payment report by a reporting business entity; and
  • (b) has been obtained by a Commonwealth body or State body under section 27, subsection 29(1) or section 30; and
  • (c) is held by the Commonwealth body or State body.

Note: This section does not apply to information held by the Commonwealth body or State body to the extent that it has been otherwise obtained.

  • (2) That information is not admissible in evidence against the reporting business entity in any of the following proceedings:
  • (a) criminal proceedings for an offence against a Commonwealth, State or Territory law, other than:
    • (i) proceedings for an offence against section 137.1 or 137.2 of the Criminal Code (which deal with false or misleading information or documents) that relates to this Act; or
    • (ii) proceedings for an offence against section 149.1 of the Criminal Code (which deals with obstruction of Commonwealth public officials) that relates to this Act;
  • (b) civil proceedings for a contravention of a civil penalty provision of a Commonwealth, State or Territory law, other than a civil penalty provision of this Part;
  • (c) proceedings for a breach of any other Commonwealth, State or Territory law (including the common law);
  • (d) proceedings before a tribunal of the Commonwealth, a State or a Territory.
  • (3) However, this section does not apply to the following:
  • (a) the proceedings of a coronial inquiry or a Royal Commission in Australia;
  • (b) proceedings in a federal court exercising original jurisdiction in which a writ of mandamus or prohibition or an injunction is sought against an officer or officers of the Commonwealth.

Note: For federal court, see section 2B of the Acts Interpretation Act 1901.

  • (4) This section does not limit or affect any right, privilege or immunity that the reporting business entity has, apart from this section, as a defendant in any proceedings.