Cyber Incident Reporting Obligations for Australian Businesses
When a cyber attack hits a small business, the first few hours are chaotic. You are trying to get systems back, calm staff and work out what was taken. In the middle of all that, many owners do not realise the clock may already be ticking on legal reporting obligations.
In Australia, two obligations matter most for small and medium businesses: the Notifiable Data Breaches scheme under the Privacy Act, and the ransomware payment reporting requirement in the Cyber Security Act 2024. Alongside them sits ReportCyber, the government’s channel for reporting cybercrime. This guide explains who each one applies to, what triggers it and how quickly you need to act. It is general information, not legal advice, so check your own situation with your lawyer or insurer.
The three reporting channels at a glance
- Notifiable Data Breaches (NDB) scheme: notify the Office of the Australian Information Commissioner (OAIC) and affected people when a data breach is likely to cause serious harm.
- Ransomware payment reporting: report to the Australian Signals Directorate (ASD) within 72 hours if your business makes a ransomware or cyber extortion payment.
- ReportCyber: report cybercrime and cyber security incidents to ASD so you can get advice and help others avoid the same attack.
These are separate. Reporting to one does not satisfy the others.
The Notifiable Data Breaches scheme
Who it applies to
The NDB scheme applies to organisations covered by the Privacy Act 1988. In general that means businesses with an annual turnover of more than $3 million. However, many smaller businesses are covered regardless of turnover, including:
- health service providers, such as a GP practice, physio or allied health clinic
- businesses that trade in personal information
- businesses providing services under a Commonwealth contract
- credit reporting businesses and reporting entities under anti-money laundering laws
- businesses related to a larger organisation covered by the Act
- businesses that have chosen to opt in
If you are unsure whether you are covered, the OAIC website has a small business section that walks through the exceptions.
What counts as an eligible data breach
A breach becomes notifiable when three things are true:
- Personal information was accessed or disclosed without authorisation, or lost.
- That is likely to result in serious harm to one or more people.
- You have not been able to prevent the likely serious harm with remedial action.
Typical examples include a hacked mailbox containing client records, a stolen laptop that was not encrypted, or a spreadsheet of customer details emailed to the wrong person.
How quickly you must act
If you suspect an eligible data breach, you must take all reasonable steps to complete an assessment within 30 calendar days of becoming aware of the grounds for suspicion. If the assessment confirms an eligible breach, you must notify the affected individuals and give a statement to the OAIC as soon as practicable. The OAIC provides an online form for this, and your notice to individuals needs to include recommendations about the steps they should take.
The OAIC describes the response in four steps: contain, assess, notify and review. Containing the breach quickly, such as resetting passwords and revoking access, can sometimes prevent serious harm altogether.
Ransomware payment reporting under the Cyber Security Act 2024
Since 30 May 2025, the Cyber Security Act 2024 has required certain businesses to report ransomware and cyber extortion payments. It applies to:
- businesses carrying on business in Australia with an annual turnover of more than $3 million
- responsible entities for critical infrastructure assets
If you make a payment, the report must be lodged with ASD within 72 hours of making the payment, or of becoming aware that it has been made. The report form is on cyber.gov.au and asks for your contact and business details, information about the incident and its impact, the extortion demand, the payment, and any communications with the attacker. Civil penalties can apply for failing to report.
Note that the trigger is the payment, not the attack. A business that is hit by ransomware but does not pay has no payment report to make, although it may still have NDB obligations if personal information was involved. Paying also does not guarantee you get your data back or that stolen data will be deleted, which is why tested backups matter so much. Our guide to simple backup and recovery plans explains how to set them up.
ReportCyber: when to use it
ReportCyber is ASD’s online portal on cyber.gov.au for reporting cybercrime, cyber security incidents and vulnerabilities. Use it when your business is affected by things such as:
- ransomware or other malware
- business email compromise, including fake invoices or changed bank details
- hacked Microsoft 365 or other online accounts
- theft of business or customer data
For urgent help, call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371). If you have lost money, call your bank straight away, because speed gives the best chance of stopping or recovering a transfer. Scams that do not involve a compromise of your systems can also be reported to Scamwatch.
Businesses below the $3 million threshold are not required to file a ransomware payment report, but they can still report the incident through ReportCyber and get advice.
Others you may need to tell
- Your cyber insurer. Most policies require prompt notice and may require you to use their incident response team. Our article on what cyber insurance really covers explains common conditions.
- Clients and suppliers whose contracts require you to notify them of incidents.
- Industry regulators if your sector has its own rules.
Quick checklist: be ready before it happens
- Confirm whether the Privacy Act covers your business and whether your turnover is above $3 million.
- Write a one-page incident response plan that names who decides on notification and payment.
- Keep a contact list: your IT provider, insurer, lawyer, bank, the OAIC and 1300 CYBER1.
- Turn on logging in Microsoft 365 so you can work out what was accessed. Without logs, assessing a breach in 30 days is much harder.
- Reduce the chance of an incident in the first place with multi-factor authentication, patching and backups. Our Essential Eight checklist for small business is a good starting point.
If you would like help putting this in place, our managed IT security service combines 24/7 monitoring with practical security controls for small businesses.
Would you know what to report, and to whom, after a cyber incident?
Our free IT Health Check reviews your security, logging and backups, and helps you build a simple incident response plan that covers your reporting obligations.
Or call 1300 133 770.




