Cyber Security Act 2024 Australia — What Businesses Need to Know
· By Paul Harvey
The Australian Cyber Security Act 2024 is a federal law that strengthens Australia's cyber security framework — it introduces mandatory ransomware payment reporting, new obligations for critical infrastructure operators, and a voluntary cyber health check program for businesses. For most Australian SMBs, the Act reinforces the importance of already implementing the ASD Essential Eight.
What is the Australian Cyber Security Act 2024?
The Cyber Security Act 2024 is the first standalone cyber security law in Australia, passed by the Federal Parliament in late 2024 as the legislative centrepiece of the 2023–2030 Australian Cyber Security Strategy. It rests on five pillars: mandatory ransomware and cyber extortion payment reporting for larger entities, expanded obligations for operators of critical infrastructure, a limited-use protection for information voluntarily shared with the National Cyber Security Coordinator, minimum security standards for smart devices sold in Australia, and the establishment of an independent Cyber Incident Review Board to conduct no-fault post-incident reviews. Most operative provisions commenced in phases from mid-2025. The Act applies directly to Commonwealth entities, designated critical infrastructure operators under the Security of Critical Infrastructure Act 2018 (SOCI), manufacturers and suppliers of connectable products, and businesses above a defined revenue threshold that pay ransoms.
Does the Cyber Security Act 2024 apply to my business?
There are three practical categories. Critical infrastructure operators — in electricity, gas, water, ports, aviation, telecommunications, financial services, food and grocery, higher education, healthcare, defence industry, data storage and processing, and space technology — are covered directly by SOCI and the Act's expanded obligations. Larger businesses (broadly, those above $3 million annual turnover) that experience a cyber incident and pay a ransom fall inside the mandatory reporting regime. Australian small and medium businesses below the turnover threshold are not directly mandated, but they are strongly encouraged to participate in the voluntary cyber health check program and to align with the ASD Essential Eight. In practice, if you supply services to any critical infrastructure entity, contractual flow-down means you will feel the same obligations even if the Act does not name you.
What is the mandatory ransomware payment reporting requirement?
Reporting entities that make a ransomware or cyber extortion payment — including cryptocurrency, gift cards, or any other benefit provided to a threat actor — must submit a ransomware payment report to the Department of Home Affairs within 72 hours of the payment being made or knowing that a payment has been made on their behalf. The report must include the entity's details, a description of the incident, the ransom demand, the actual payment amount and currency, any cryptocurrency wallet addresses used, and any known details about the threat actor. Importantly, paying a ransom is not itself an offence under the Act, and information provided in a payment report is protected from being used against the entity in most regulatory or civil proceedings. The Australian Signals Directorate uses aggregated reports to track threat actors, disrupt payment infrastructure, and inform national response.
How should Australian businesses prepare for the Cyber Security Act 2024?
Start by implementing the ASD Essential Eight as your baseline — patching applications and operating systems, application control, restricting administrative privileges, multi-factor authentication, macro settings, user application hardening, regular backups, and daily backup testing. Commission a cyber security gap assessment against Essential Eight Maturity Level 1 or 2, or an equivalent framework such as ISO 27001, so you know exactly where you stand. Document an incident response plan that names decision makers, external notification obligations, and the 72-hour ransomware reporting workflow — and rehearse it at least annually. Finally, map your supply chain: if you are a supplier to any critical infrastructure entity you should expect security schedules in your contracts requiring evidence of Essential Eight uplift, breach notification within tight timeframes, and cooperation with post-incident reviews conducted by the Cyber Incident Review Board.
How does Microsoft 365 and Azure help businesses meet the Act's requirements?
The Microsoft stack covers most of what an Australian business needs to satisfy both the Essential Eight and the Cyber Security Act's practical expectations. Microsoft Defender for Endpoint, Defender for Office 365, and Defender for Cloud provide ransomware detection, automated containment, and forensic timelines that support 72-hour reporting. Microsoft Sentinel aggregates logs across identity, endpoint, email, and cloud workloads to give you a single incident record admissible in regulatory reporting. Entra ID Conditional Access enforces MFA and device-based access controls that satisfy Essential Eight Mitigation Strategies 6 and 7. Azure Backup with immutable vaults and soft delete provides the recoverable backups Essential Eight requires and that materially reduce the pressure to pay a ransom. Microsoft Purview classifies and labels sensitive data so you can quickly assess what was accessed during an incident and meet notification obligations under the Privacy Act as well as the Cyber Security Act.
How Mycelium 365 helps Australian businesses with Cyber Security Act compliance
Mycelium 365 runs Essential Eight advisory engagements that translate the Act's expectations into concrete Microsoft 365 and Azure controls, with a documented maturity target and a 12–24 month roadmap. Our cyber security gap assessments compare your current tenant against Essential Eight ML1 and ML2 and produce a prioritised remediation plan. We deploy and manage Microsoft Defender end-to-end so incident detection, response, and evidence collection are ready before you need them. And through our Governance, Compliance and Readiness advisory service we help you align board reporting, incident response plans, and supplier contracts to the Cyber Security Act 2024.
Key dates and phased commencement
Not every part of the Cyber Security Act 2024 turned on at once. Ransomware payment reporting obligations for reporting business entities took effect from mid-2025, with a six-month grace period where the Department of Home Affairs focused on education rather than enforcement. Security standards for smart devices — covering internet-connectable consumer products such as routers, cameras, and smart speakers — commenced separately and are enforced by the Australian Communications and Media Authority. The Cyber Incident Review Board began operating from 2025 and can be convened by the Minister to conduct a no-fault review of a significant cyber incident, with findings published to lift sector-wide practice. Amendments to the Security of Critical Infrastructure Act, made in the same package, expanded the definition of critical assets, introduced consequence-management powers for government during a major incident, and clarified the treatment of secondary assets such as customer databases. If you are unsure which provisions apply from which date, the Department of Home Affairs publishes a plain-English implementation guide, and Mycelium 365 can map the timeline against your Microsoft 365 and Azure environment during a governance readiness engagement.
Board directors and executives should also note that ASIC has publicly stated cyber resilience is a director's duty under the Corporations Act, and APRA-regulated entities face parallel obligations under CPS 234. The Cyber Security Act 2024 does not replace these regimes — it layers on top, so a bank, insurer, or superannuation fund can now face concurrent obligations under APRA CPS 234, the Privacy Act notifiable data breach scheme, the SOCI Act, and the Cyber Security Act 2024 for a single incident.
If you are unsure whether the Act applies to your business, or you want a defensible position before your next contract renewal or board meeting, get in touch with Mycelium 365 — we will scope a gap assessment and a practical technology roadmap aligned to Essential Eight and the Cyber Security Act 2024.
Frequently asked questions
Is my business required to report ransomware payments under the Cyber Security Act 2024?
Only if you are a reporting business entity — broadly, an Australian business above the $3 million annual turnover threshold, or a Commonwealth entity or designated critical infrastructure operator. If you fall inside that scope and pay a ransomware or cyber extortion demand, you must submit a payment report to the Department of Home Affairs within 72 hours.
What is the difference between the Cyber Security Act 2024 and the Essential Eight?
The Essential Eight is the Australian Signals Directorate's baseline set of eight technical mitigation strategies. The Cyber Security Act 2024 is federal legislation that creates legal obligations such as ransomware payment reporting and smart-device standards. Implementing the Essential Eight is the practical way most Australian businesses satisfy the Act's expectations.
What are the penalties for not complying with the Cyber Security Act 2024?
Civil penalties apply for failing to submit a ransomware payment report on time, for breaching smart-device security standards, and for non-compliance with directions issued to critical infrastructure operators. Penalties scale with entity size and the seriousness of the breach; paying the ransom itself is not an offence.
Does the Cyber Security Act 2024 apply to businesses in all Australian states?
Yes — it is Commonwealth legislation, so it applies uniformly across all states and territories. State-based privacy, health records, and public sector laws continue to operate alongside it, but the ransomware reporting, smart-device, and Cyber Incident Review Board provisions are national.