Cyber Security
You paid the ransom. Now you have 72 hours.
Since May 2025 Australian businesses turning over more than $3 million, and critical infrastructure responsible entities at any turnover, must report a ransomware payment to the ASD within 72 hours. What the obligation covers, what it does not, and why it belongs in your incident response plan rather than your legal team’s inbox.
The answer, up front
The short answer: the clock starts at the payment, not at the breach. The duty sits with the business rather than with your lawyers, your insurer or your IT provider, and it is triggered by a payment made by anyone acting on your behalf, a negotiator or an incident-response firm included. It is a notification, not an approval: reporting does not make the payment lawful, and not reporting is a second problem on top of the first.
Seventy-two hours is an incident-response window, not a legal one, which is why the obligation belongs in the response plan rather than in someone’s inbox. Better still is never reaching the question. Cyber Security is about not arriving there, Disaster Recovery is about having a restore path that makes paying pointless, and a commercial builder’s security uplift is one version of that.
Seventy-two hours is an incident-response window, not a legal one. The obligation belongs in the response plan, not in someone’s inbox.
Why this matters now
For most Australian businesses, cyber security has quietly moved from a back-office concern to a board-level one. The tools people rely on every day now sit across cloud services, personal devices and a supply chain of third parties, and the gaps between them are exactly where problems appear.
The teams that stay ahead are not the ones with the biggest budgets. They are the ones that treat this as an ongoing operating discipline rather than a project that finishes. That shift in mindset is what separates a setup that holds up under pressure from one that only looks fine until the day it does not.
What good looks like
When cyber security is handled well, it tends to be invisible. The difference shows up in the details rather than the dashboards. A few markers to look for:
- Clear ownership, so there is never a question of whose job a given task is.
- Proactive maintenance and monitoring, so most issues are caught before anyone raises a ticket.
- Documented, tested procedures that a new team member could follow under pressure.
- Regular reporting in plain language, not a wall of metrics that hide the real story.
Want this handled for you?
Our engineers do this every day for businesses across Australia. Have a plain-English conversation about where you stand and what to fix first.
Where to start
You do not need to fix everything at once. Start with an honest assessment of where the real risk sits, then sequence the work so the highest-impact changes land first. That usually means shoring up the basics, closing the obvious gaps, and building the routine that keeps them closed.
From there, the work compounds. Each improvement makes the next one easier, and the environment gets steadily more resilient without a disruptive overhaul. If you would like a hand mapping that path for your business, we are happy to help.