Australia passed the Cyber Security Act 2024 in late 2024, introducing the most significant legislative change to Australian cyber security obligations in years. The Act implements several recommendations from the 2023 Cyber Security Strategy, including mandatory ransomware payment reporting, minimum security standards for smart devices, and a new cyber incident review board. For NZ businesses with Australian operations, customers, or data flows, the implications are material.
This post covers what the Act requires, which NZ businesses are in scope, and the practical steps to take now.
---
What the Act Introduces
Mandatory ransomware payment reporting. Entities that meet the threshold — broadly, businesses with annual turnover exceeding AUD $3 million — must report ransomware payments to the Australian Signals Directorate within 72 hours of making or becoming aware of a payment. The reporting obligation includes the amount paid, the cryptocurrency wallet or payment method used, and the circumstances of the attack. Failure to report carries civil penalties.
This does not prohibit paying ransomware — it requires disclosure when a payment is made. The intent is to build a national intelligence picture of ransomware payment flows to inform disruption efforts.
Minimum security standards for connectable products. Smart devices sold in Australia — IoT devices, consumer electronics, anything with a network connection — must meet minimum security standards. Manufacturers and importers are affected. For NZ businesses that sell hardware into Australia, this is a direct product compliance obligation.
Cyber Incident Review Board. A new independent board with powers to review significant cyber incidents, similar to the NTSB model in aviation and transport safety. The Board can require organisations to cooperate with reviews. Its findings are not admissible in legal proceedings, which is intended to encourage honest disclosure.
Limited use obligations on government cyber incident sharing. When organisations share incident information with government under the Act, that information has restricted use — it cannot be used for regulatory action against the sharing organisation. This addresses a longstanding barrier to voluntary incident reporting.
Who Is In Scope
The ransomware reporting obligation applies to entities operating in Australia with turnover above the threshold. The practical scope includes:
- Australian entities above the threshold — direct obligation
- NZ companies with Australian subsidiaries or branches — the Australian entity is in scope
- NZ companies that operate Australian-facing websites, hold Australian customer data, or process payments in Australia — subject to legal analysis, but potentially in scope
NZ businesses that have assessed themselves as outside Australian jurisdiction on privacy grounds should reassess. The Cyber Security Act uses a broader definition of "carrying on business in Australia" than some had anticipated.
The Ransomware Reporting Obligation in Practice
The 72-hour reporting window runs from when the entity becomes aware of the payment, not from when the ransom demand arrived. Practical implications:
- The entity needs to know it has made or is about to make a ransomware payment — obvious in a direct payment, less obvious if a managed service provider or insurer negotiates and pays on the entity's behalf
- The 72-hour clock aligns with the NCSC NZ notification window under the NZ Cyber Security and Resilience Bill — entities with obligations under both regimes should wire the notifications together
- The report must be made to ASD through the ReportCyber portal — this is a different channel from CERT NZ
For businesses that have cyber insurance with ransomware negotiation coverage, the insurance policy and the legal reporting obligation need to be explicitly reconciled. Some policies provide incident response support that may make the payment on the insured's behalf — the obligation to report does not transfer to the insurer.
For NZ Businesses Selling Devices Into Australia
The connectable products security standard applies to any product that connects to the internet, a network, or another device and is sold in Australia. For NZ manufacturers and importers this means:
- Security-by-design requirements embedded in the product from manufacture
- Minimum password and authentication standards
- Disclosure of the minimum security update support period
- Vulnerability disclosure processes that meet Australian standards
The compliance timeline for existing products sold in Australia is staggered, but new products entering the market after the standard takes effect need to be compliant from day one.
NZ and Australia Alignment
The NZ Cyber Security and Resilience Bill and the Australian Cyber Security Act reflect coordinated policy between the two countries. Both introduce mandatory incident reporting, both align on 72-hour notification windows, and both draw on the same AUKUS-aligned threat intelligence framework. For businesses operating in both jurisdictions, the practical approach is a single incident response process that satisfies both notification obligations simultaneously.
The NZ SME implications of the domestic Cyber Security and Resilience Bill are covered in NZ Cyber Resilience Bill: What SMEs Must Prepare For.
Practical Steps for NZ Businesses With AU Operations
- Confirm whether the Australian entity or operations meet the ransomware reporting threshold
- Map the incident response process to include ASD notification alongside CERT NZ and NCSC notification
- Review cyber insurance policies to clarify who makes ransomware payments and who bears the reporting obligation
- If selling connectable products in Australia, assess current product security against the minimum standards
- Brief the board on the personal liability implications of the Cyber Incident Review Board's powers
- Update the business continuity and incident response documentation to reference the Act
Start your free SecureAZ trial to train your team on ransomware response, incident reporting obligations, and the controls that reduce the likelihood of ever needing to make a ransomware payment.
External references: