Part 3—Ransomware reporting obligations
Read this container onlyDivision 1—Preliminary
Read this container only25 Simplified outline of this Part
:::box This Part imposes reporting obligations on certain entities who are impacted by a cyber security incident, and who have provided or are aware that another entity has provided, a payment or benefit (called a ransomware payment) to an entity that is seeking to benefit from the impact or the cyber security incident.
Particular information must be included in a ransomware payment report, including information relating to the cyber security incident, the demand made by the extorting entity and the ransomware payment.
An entity may be liable to a civil penalty if the entity fails to make a ransomware payment report as required by this Part. :::