Skip to content
Legislation
Skip to legislation

Cyber Security Act 2024 · Version 2024-11-29

Division 2—Reporting obligations

Register source version C2024A00098 · Source observation:

Reading presentation · Verification limits and dated status · No live currency check

Part 3—Ransomware reporting obligations

Read this container only

Division 2—Reporting obligations

Read this container only

26 Application of this Part

  • (1) This Part applies if:
  • (a) an incident has occurred, is occurring or is imminent; and
  • (b) the incident is a cyber security incident; and
  • (c) the incident has had, is having, or could reasonably be expected to have, a direct or indirect impact on a reporting business entity; and
  • (d) an entity (the extorting entity) makes a demand of the reporting business entity, or any other entity, in order to benefit from the incident or the impact on the reporting business entity; and
  • (e) the reporting business entity provides, or is aware that another entity has provided on their behalf, a payment or benefit (a ransomware payment) to the extorting entity that is directly related to the demand.
  • (2) An entity is a reporting business entity if, at the time the ransomware payment is made:
  • (a) the entity:
    • (i) is carrying on a business in Australia with an annual turnover for the previous financial year that exceeds the turnover threshold for that year; and
    • (ii) is not a Commonwealth body or a State body; and
    • (iii) is not a responsible entity for a critical infrastructure asset; or
  • (b) the entity is a responsible entity for a critical infrastructure asset to which Part 2B of the Security of Critical Infrastructure Act 2018 applies.
  • (3) For the purposes of subparagraph (2)(a)(i), the turnover threshold is:
  • (a) if a business has been carried on for only part of the previous financial year—the amount worked out in the manner prescribed by the rules; or
  • (b) in any other case—the amount prescribed by, or worked out in the manner prescribed by, the rules.

Presumption

  • (4) For the purposes of paragraph (1)(b), an incident (other than an incident covered by paragraph 9(2)(a) or (b)) is presumed to be a cyber security incident if:
  • (a) the incident was probably effected, is probably being effected or could reasonably be expected to be effected, by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
  • (b) the incident has probably impeded or impaired, or is probably impeding or impairing or could reasonably be expected to impede or impair, the ability of a computer to connect to such a service; or
  • (c) the incident has probably seriously prejudiced, is probably seriously prejudicing, or could reasonably be expected to prejudice:
    • (i) the social or economic stability of Australia or its people; or
    • (ii) the defence of Australia; or
    • (iii) national security.

Note: Paragraphs 9(2)(a) and (b) cover incidents involving critical infrastructure assets or the activities of corporations to which paragraph 51(xx) of the Constitution applies.

  • (5) However, subsection (4) does not make an entity liable to a civil penalty under this Part if the incident:
  • (a) was not in fact effected by means of a telegraphic, telephonic or other like service within the meaning of paragraph 51(v) of the Constitution (including, for example, by means of the internet); or
  • (b) did not in fact impede or impair the ability of a computer to connect to such a service; or
  • (c) did not in fact seriously prejudice:
    • (i) the social or economic stability of Australia or its people; or
    • (ii) the defence of Australia; or
    • (iii) national security.

27 Obligation to report following a ransomware payment

  • (1) The reporting business entity must give the designated Commonwealth body a report (a ransomware payment report) that complies with the requirements of this section within 72 hours of making the ransomware payment or becoming aware that the ransomware payment has been made (whichever is applicable).

Note: For the definition of designated Commonwealth body: see section 8.

  • (2) The ransomware payment report must contain information relating to the following, in accordance with any requirements prescribed by the rules, that, at the time of making the report, the reporting business entity knows or is able, by reasonable search or enquiry, to find out:
  • (a) if the reporting business entity made the payment—the reporting business entity’s contact and business details;
  • (b) if another entity made the payment—that entity’s contact and business details;
  • (c) the cyber security incident, including its impact on the reporting business entity;
  • (d) the demand made by the extorting entity;
  • (e) the ransomware payment;
  • (f) communications with the extorting entity relating to the incident, the demand and the payment.
  • (3) The reporting business entity may include other information relating to the cyber security incident in the ransomware payment report.
  • (4) The ransomware payment report must be given:
  • (a) in the form approved by the Secretary (if any); and
  • (b) in the manner (if any) prescribed by the rules.
  • (5) An entity is liable to a civil penalty if the entity contravenes subsection (1).

Civil penalty: 60 penalty units.

  • (6) Subsection 93(2) of the Regulatory Powers Act does not apply in relation to a contravention of subsection (1) of this section.

28 Liability

  • (1) An entity is not liable to an action or other proceeding for damages for or in relation to an act done or omitted in good faith in compliance with section 27.
  • (2) An officer, employee or agent of an entity is not liable to an action for damages for or in relation to an act done or omitted in good faith in connection with an act done or omitted by the entity as mentioned in subsection (1).
  • (3) An entity that wishes to rely on subsection (1) in relation to an action or other proceeding bears an evidential burden (within the meaning of the Regulatory Powers Act) in relation to that matter.