Australia's mandatory ransomware reporting rules, which took effect under the Cyber Security Act 2024, are forcing small and medium enterprises to rethink how they handle cyberattacks, insurance claims, and director responsibilities. A recent analysis from Sutton Laurence King Lawyers Melbourne breaks down what these changes mean for SMEs, and the privacy implications deserve closer attention than they've received so far.

What the New Ransomware Reporting Rules Require

Under the new framework, businesses operating in Australia with an annual turnover above $3 million, along with critical infrastructure operators, are now required to report ransomware or cyber extortion payments. Reports typically go to the Australian Signals Directorate, and the obligation applies whether or not a business ultimately decides to pay a ransom demand.

For SMEs, this is a significant shift. Previously, many smaller businesses quietly resolved ransomware incidents behind closed doors, sometimes paying attackers without any formal disclosure to regulators. Now, that option is off the table for entities that meet the turnover threshold. The rules create a paper trail that didn't exist before, and that paper trail has consequences for privacy, liability, and insurance that extend well beyond the initial compliance headache.

The Privacy Implications SMEs Often Overlook

Mandatory reporting isn't just an administrative box to check. When a business reports a ransomware payment, it typically has to disclose details about the incident, including what data was accessed or exfiltrated, how the attack unfolded, and who was affected. That means SMEs need to have a clear picture of what customer, employee, and partner data was exposed, often under significant time pressure and while systems are still compromised.

This creates a tension that many business owners aren't prepared for. On one hand, transparency with regulators is now legally required. On the other, disclosing the scope of a data compromise can trigger separate notification obligations to affected individuals under privacy law, potential reputational damage, and scrutiny from customers and business partners who want to know exactly what happened to their information. The reporting requirement effectively removes the ability to manage an incident quietly, which changes the calculus for how SMEs prepare for and respond to attacks in the first place.

There's also a data-handling wrinkle: the information a business submits to report a ransomware payment, including technical details about the breach and how attackers gained access, becomes a record that regulators hold. Business owners should understand what happens to that information, who can access it, and whether it could be used in ways beyond the original reporting purpose. This isn't necessarily a red flag, but it's a governance question SMEs should be asking before an incident happens, not during one.

Insurance and Director Duties Under the New Regime

The reporting obligation also reshapes how cyber insurance claims play out. Insurers increasingly expect documented evidence of compliance with reporting rules before honoring claims related to ransomware incidents. That means SMEs without a clear incident response and reporting process could find themselves in a weaker position when they need their policy to pay out.

Directors face a parallel shift in responsibility. Failing to report a ransomware payment when required, or mishandling the privacy fallout from a breach, can expose directors to liability questions under existing corporate governance obligations. Given that ransomware attacks are becoming cheaper and easier for attackers to launch, as highlighted in coverage of AI-powered ransomware attacks now costing less than a coffee, the volume of incidents SMEs face is only likely to grow, making proactive compliance more urgent rather than less.

What This Means For You

If you run an SME in Australia, particularly one approaching or exceeding the $3 million turnover threshold, the new rules mean ransomware is no longer just a technical problem. It's a compliance, privacy, and governance issue that touches your insurance coverage, your legal exposure, and your relationship with customers whose data might be at risk. Waiting until an attack happens to figure out your reporting obligations is a recipe for confusion at exactly the moment you can least afford it.

Actionable Takeaways

Start by confirming whether your business meets the reporting threshold and understanding exactly what triggers a mandatory report. Build a clear incident response plan that accounts for both regulatory reporting and any separate privacy notification duties to affected customers or employees. Review your cyber insurance policy now to understand what documentation insurers will expect if you ever need to file a claim. Finally, talk to legal counsel about director obligations under the new rules so your leadership team isn't making these decisions for the first time in the middle of an active breach. The businesses that treat this as an ongoing compliance practice, rather than a one-time reaction, will be far better positioned when an attack eventually comes.