Skip to main content

CyberSure Community

Cyber Security Act 2024: Why Australian Small Businesses Should Pay Attention

Cybersecurity regulation in Australia is changing.

For many small and mid-sized business owners, new cyber legislation can sound like something designed for banks, government departments, telecommunications companies and large enterprises.

But Australia’s Cyber Security Act 2024 is worth understanding even if you run a relatively small organisation.

The Act is Australia’s first standalone Cyber Security Act and introduces new measures covering ransomware payments, consumer smart devices, information sharing during major cyber incidents and post-incident reviews. It received Royal Assent on 29 November 2024.

Some obligations only apply to businesses meeting specific criteria. Others can affect smaller manufacturers, suppliers and retailers directly.

More importantly, the legislation reflects a broader shift in Australian cybersecurity: businesses are increasingly expected to know what they would do before a cyber incident occurs.

So what actually applies to an Australian SMB?

What Is the Cyber Security Act 2024?

The Cyber Security Act 2024 introduces four major measures:

  1. Minimum cybersecurity standards for certain consumer smart devices.
  2. Mandatory reporting of ransomware and cyber-extortion payments by certain businesses.
  3. Limited-use protections for some information voluntarily provided to the National Cyber Security Coordinator during a cyber incident.
  4. The establishment of a Cyber Incident Review Board to review significant incidents and share lessons with industry.

For most ordinary SMBs, the two areas that deserve immediate attention are ransomware reporting and smart-device security.

Does the Cyber Security Act Apply to Small Businesses?

The answer is: potentially, yes — but it depends on which part of the Act you are looking at.

There is no blanket rule saying every Australian small business suddenly has the same obligations.

For example, the mandatory ransomware-payment reporting regime generally captures businesses carrying on business in Australia with annual turnover at or above the prescribed threshold, as well as certain entities responsible for critical-infrastructure assets.

The current threshold is $3 million in annual turnover. Home Affairs guidance says captured businesses that make a ransomware or cyber-extortion payment, or become aware that one has been made on their behalf, generally need to report it within 72 hours.

That $3 million figure is important.

A business does not need to be a large enterprise to reach $3 million in annual turnover.

A growing accounting firm, medical practice, retailer, construction company, professional-services firm, technology provider or e-commerce business could potentially cross that threshold while still thinking of itself as a small or medium-sized business.

The $3 Million Ransomware Reporting Threshold

Mandatory ransomware and cyber-extortion payment reporting commenced on 30 May 2025. Home Affairs subsequently moved from its initial education-first period to what it describes as a more active compliance and education approach from 1 January 2026 onwards.

Broadly, the reporting requirement can apply when:

  • the organisation is a reporting business entity under the Act;
  • it has been directly or indirectly affected by a ransomware or cyber-extortion incident; and
  • it makes a payment, or becomes aware that a payment has been made on its behalf.

The report generally needs to be made within 72 hours of the payment being made, or the business becoming aware that a payment was made on its behalf.

This creates an important operational question:

Could your business gather the required information within 72 hours while simultaneously dealing with a ransomware attack?

That is where preparedness becomes critical.

What Information Could a Business Need After a Ransomware Payment?

The reporting regime can require information about the organisation, the cyber incident, the demand, the payment and communications with the threat actor.

Home Affairs guidance includes information such as:

  • when the incident occurred;
  • when the organisation became aware of it;
  • how the business and its customers were affected;
  • ransomware or malware involved, where known;
  • vulnerabilities believed to have been exploited;
  • details of the demand;
  • details of the payment;
  • communications with the extorting party; and
  • relevant information that could assist government response or mitigation.

Trying to reconstruct all of that after an attack has already encrypted systems, disabled email or disrupted operations can be extremely difficult.

That is why an incident-response plan should include more than simply:

“Call IT if something goes wrong.”

The business needs to know who makes decisions, who preserves evidence, who contacts cyber specialists, who communicates with insurers and legal advisers, and who is responsible for any required regulatory notifications.

What About Businesses Under $3 Million?

This is where some commentary around the Cyber Security Act can become misleading.

A business below the ransomware-reporting turnover threshold is not automatically subject to that particular mandatory reporting obligation simply because it suffers ransomware.

But that does not mean the Cyber Security Act is irrelevant.

There are several reasons smaller businesses should still understand it.

1. You May Grow Into the Threshold

A company turning over $2.5 million today may exceed $3 million next year.

Cybersecurity governance should not suddenly begin the day revenue crosses a legislative threshold.

Putting basic incident-response procedures, logging and escalation processes in place beforehand makes the transition far easier.

2. Your Customers May Expect More From You

SMBs increasingly operate inside larger organisations’ supply chains.

Customers may ask suppliers to demonstrate cybersecurity controls, incident-response capabilities, cyber insurance, staff training or security monitoring regardless of whether legislation imposes the same direct obligations on every supplier.

A business can therefore feel the impact of Australia’s changing cybersecurity environment indirectly through procurement and contractual requirements.

3. Cyber Incidents Do Not Respect Revenue Thresholds

Ransomware operators do not check whether a company falls within a legislative reporting threshold before attacking it.

A ten-person business can still lose access to Microsoft 365, accounting systems, customer records, backups or operational systems.

Whether reporting is mandatory or voluntary, the underlying incident still needs to be contained and investigated.

Small Retailers and Technology Businesses Should Pay Attention to the Smart-Device Rules

Another important part of the Act relates to consumer-grade smart devices.

The Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced on 4 March 2026, following a 12-month transition period. The rules apply to many smart devices manufactured from that date and intended for personal, domestic or household use.

This can matter to smaller businesses because the obligations are not only relevant to giant electronics manufacturers.

An Australian SMB could potentially be involved as a:

  • manufacturer;
  • importer;
  • distributor;
  • supplier; or
  • retailer of connected consumer devices.

Examples might include connected security cameras, smart-home devices, network-connected appliances or other Internet of Things products, subject to the detailed scope and exemptions in the legislation.

The government requirements include measures addressing:

  • universal default passwords;
  • mechanisms for reporting security vulnerabilities;
  • publication of the period for which a device will receive security support; and
  • statements of compliance for products within scope.

Certain products, including laptops, desktop computers, smartphones and tablets, are excluded from these particular rules.

For suppliers of in-scope devices, the legislation also includes requirements relating to supplying products with a statement of compliance.

That means a relatively small online retailer or technology distributor should not assume these obligations only sit with multinational manufacturers.

Why This Matters Beyond Compliance

The bigger lesson from the Cyber Security Act is not simply that businesses have another piece of legislation to read.

It is that cybersecurity is increasingly becoming part of normal business governance.

Consider what would happen if ransomware affected your business tomorrow.

Would you know:

  • which systems were compromised?
  • when the intrusion started?
  • whether customer data had been accessed?
  • whether your backups were safe?
  • who was authorised to speak to an attacker?
  • who could approve a payment?
  • whether your insurer had to be contacted first?
  • whether government reporting obligations applied?
  • who would preserve forensic evidence?
  • how customers and employees would be informed?

Those are operational questions, not purely technical questions.

A business that waits until an attack to answer them will be making high-pressure decisions while its systems may already be unavailable.

Seven Practical Steps SMBs Can Take

You do not need an enterprise-sized cyber team to become better prepared.

Start with these seven areas.

1. Know Whether the Legislation Applies to You

Confirm your annual turnover and determine whether your organisation has any obligations associated with critical infrastructure, ransomware reporting or smart-device manufacturing and supply.

If your position is unclear, obtain appropriate legal or compliance advice.

2. Create a Cyber Incident Response Plan

Document exactly what happens when a serious cyber incident is discovered.

Include internal decision-makers, IT providers, cybersecurity responders, legal advisers, insurers and relevant government reporting channels.

3. Establish an External Incident-Response Contact Before an Attack

The middle of a ransomware incident is a poor time to start searching for a digital-forensics company.

Know who you will call before you need them.

4. Improve Logging and Monitoring

If an incident occurs, investigators may need to establish what happened, when it happened and which systems were affected.

Appropriate endpoint, identity, cloud and network monitoring can make that process substantially easier.

5. Protect Administrative Accounts

Use multi-factor authentication, restrict privileged access and remove unnecessary administrator accounts.

Compromised privileged credentials can turn an isolated attack into a business-wide incident.

6. Test Your Backups

Having backups is different from knowing they can be restored.

Backups should be appropriately protected from the production environment and recovery procedures should be tested.

7. Run an Incident Exercise

Sit your management team around a table and ask:

“Microsoft 365 is unavailable, files are encrypted and an attacker is demanding $200,000. What happens next?”

The gaps become obvious very quickly.

Cybersecurity Regulation Is Moving Downstream

For years, cybersecurity compliance was largely viewed as an enterprise issue.

That distinction is becoming less useful.

Technology supply chains, cyber insurance, privacy obligations, customer contracts and new cyber-specific legislation increasingly connect businesses of every size.

Australia’s Cyber Security Act 2024 does not impose identical requirements on every small business.

But it does reinforce an important direction of travel:

Australian businesses are being expected to take cyber resilience, incident response and secure technology more seriously.

For an SMB, that does not necessarily mean building a security operations centre or hiring a large internal cybersecurity team.

It means knowing your risks, preparing for incidents and having access to the right expertise when something goes wrong.

Frequently Asked Questions

Does the Cyber Security Act 2024 apply to every Australian small business?

No. Different parts of the Act have different scopes and eligibility criteria. For example, mandatory ransomware-payment reporting generally applies to businesses meeting the prescribed turnover threshold or certain critical-infrastructure entities, while smart-device provisions can apply to manufacturers and suppliers of relevant consumer devices.

What is the ransomware reporting threshold in Australia?

The Cyber Security (Ransomware Payment Reporting) Rules 2025 specify a $3 million annual-turnover threshold, subject to the detailed provisions and calculation rules.

How long does a business have to report a ransomware payment?

For businesses captured by the mandatory regime, a ransomware or cyber-extortion payment generally needs to be reported within 72 hours of making the payment or becoming aware that a payment was made on the business’s behalf.

Do you have to report a ransom demand if you do not pay?

Under the mandatory payment-reporting regime, Home Affairs states that an incident where a demand is made but no payment is provided does not trigger that particular mandatory reporting requirement. Businesses are nevertheless encouraged to report cyber incidents voluntarily through the Australian Signals Directorate.

Does the Cyber Security Act cover smart devices?

Yes. New mandatory standards for many consumer-grade smart devices commenced on 4 March 2026. The requirements address areas including default passwords, vulnerability reporting, security-support periods and statements of compliance.

Is Your Business Ready for a Cyber Incident?

Cyber regulations will continue to evolve, but businesses do not need to wait for another regulatory change before improving their security posture.

CyberSure helps Australian small and mid-sized businesses strengthen cyber resilience through proactive monitoring, threat detection, cyber awareness, incident preparedness and access to specialist incident-response capabilities.

The objective is simple: identify risks earlier, respond faster and minimise the financial and operational impact when something goes wrong.

Cybersecurity should not begin after the breach.

Prepare before you need to respond.

This article provides general information only and does not constitute legal advice. Businesses should obtain advice appropriate to their circumstances when determining whether particular obligations under the Cyber Security Act 2024 apply to them.

Post Your Comment

Privacy Overview

Our Privacy Policy

CyberSure Community is committed to providing quality services to you and this policy outlines our ongoing obligations to you in respect of how we manage your Personal Information.

We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The NPPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information.

A copy of the Australian Privacy Principles may be obtained from the website of The Office of the Australian Information Commissioner at https://www.oaic.gov.au/.

What is Personal Information and why do we collect it?

Personal Information is information or an opinion that identifies an individual. Examples of Personal Information we collect includes names, addresses, email addresses, phone and facsimile numbers.

This Personal Information is obtained in many ways including interviews, correspondence, by telephone, by email, via our website ‘www.cybersure.community’, from media and publications, from other publicly available sources, from cookies and from third parties. We don’t guarantee website links or policy of authorised third parties.

We collect your Personal Information for the primary purpose of providing our services to you, providing information to our clients and marketing. We may also use your Personal Information for secondary purposes closely related to the primary purpose, in circumstances where you would reasonably expect such use or disclosure. You may unsubscribe from our mailing/marketing lists at any time by contacting us in writing.

When we collect Personal Information we will, where appropriate and where possible, explain to you why we are collecting the information and how we plan to use it.

Sensitive Information

Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.

Sensitive information will be used by us only:

• For the primary purpose for which it was obtained

• For a secondary purpose that is directly related to the primary purpose

• With your consent; or where required or authorised by law.

Third Parties

Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.

Disclosure of Personal Information

Your Personal Information may be disclosed in a number of circumstances including the following:

• Third parties where you consent to the use or disclosure; and

• Where required or authorised by law.

Security of Personal Information

Your Personal Information is stored in a manner that reasonably protects it from misuse and loss and from unauthorized access, modification or disclosure.

When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify your Personal Information. However, most of the Personal Information is or will be stored in client files which will be kept by us for a minimum of 7 years.

Access to your Personal Information

You may access the Personal Information we hold about you and to update and/or correct it, subject to certain exceptions. If you wish to access your Personal Information, please contact us in writing.

CyberSure Community will not charge any fee for your access request, but may charge an administrative fee of $149 + gst per request for providing a copy of your Personal Information.

In order to protect your Personal Information we may require identification from you before releasing the requested information.

Maintaining the Quality of your Personal Information

It is an important to us that your Personal Information is up to date. We will take reasonable steps to make sure that your Personal Information is accurate, complete and up-to-date. If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.

Policy Updates

This Policy may change from time to time and is available on our website.

Privacy Policy Complaints and Enquiries

If you have any queries or complaints about our Privacy Policy please contact us at:

[email protected]