News Security Technology

Australia Set To Enforce World’s First Mandatory Reporting Of Ransomware Payments 

Cyberattacks in India
As part of this strategy, the Cyber Security Bill introduces seven key initiatives intended to protect Australian businesses and citizens from cyber threats

Australia is on track to become the first country in the world to mandate that businesses report any ransomware payments they make to the government. The unprecedented requirement is part of the newly introduced Cyber Security Bill 2024, which seeks to combat rising cyber threats and secure the nation’s digital landscape.

The bill follows a string of high-profile cyberattacks on prominent Australian businesses, including telecommunications giant Optus, health insurer Medibank, and digital health company MediSecure. These incidents have pushed cybersecurity to the forefront of Australia’s policy agenda. The government’s updated national cybersecurity strategy, launched last November with a budget of AU dollar 587 million (dollar 382 million) over seven years, aims to mitigate AU$3 billion (dollar1.9 billion) in annual damages caused by ransomware attacks.

As part of this strategy, the Cyber Security Bill introduces seven key initiatives intended to protect Australian businesses and citizens from cyber threats. While several of these measures align Australia’s cybersecurity standards with international best practices, the new ransomware reporting obligations set Australia apart globally.

Under the proposed law, all businesses exceeding an annual turnover of AU$3 million (US$2 million) would be required to report any ransomware payments to the Department of Home Affairs within 72 hours of payment. This threshold would apply to approximately 6.56 per cent of all registered businesses in Australia, accounting for around half of the nation’s total annual turnover.

Businesses are only obligated to report if they or a third party acting on their behalf make a payment to ransomware attackers. Failure to report within the specified time frame could result in a fine of AU dollar 18,000 (dollar 12,000), equivalent to 60 penalty units under Australia’s civil penalty system.

In an accompanying memorandum, the Australian government underscored the urgent need for this legislation, describing ransomware attacks as “one of the most destructive types of cybercrime” and noting that “these attacks present a persistent threat to Australia.” The government acknowledged that current voluntary reporting mechanisms are significantly under-utilised, with the Australian Institute of Criminology reporting that only 20 per cent of ransomware victims come forward, leaving authorities in the dark about the true impact of these attacks.

“Mandatory reporting of ransomware payments will crystallise our picture of how much is being extorted from businesses via ransomware attacks, whom these payments are being made to and how,” said Tony Burke, Australia’s Minister for Cybersecurity. He added that, in 2023, businesses that paid ransoms to attackers spent an average of AU dollar 9.27 million (dollar 6 million) per incident.

This measure is intended not only to bolster government oversight but also to provide a clearer understanding of the economic and social toll ransomware takes on Australian businesses. If enacted, the Cyber Security Bill 2024 would represent a landmark step in the global fight against cybercrime, making Australia the first country to establish mandatory ransomware payment reporting.

Leave a Reply

Your email address will not be published. Required fields are marked *