Cyber Security Act 2024: Why Australian Small Businesses Should Pay Attention
Cybersecurity regulation in Australia is changing.
For many small and mid-sized business owners, new cyber legislation can sound like something designed for banks, government departments, telecommunications companies and large enterprises.
But Australia’s Cyber Security Act 2024 is worth understanding even if you run a relatively small organisation.
The Act is Australia’s first standalone Cyber Security Act and introduces new measures covering ransomware payments, consumer smart devices, information sharing during major cyber incidents and post-incident reviews. It received Royal Assent on 29 November 2024.
Some obligations only apply to businesses meeting specific criteria. Others can affect smaller manufacturers, suppliers and retailers directly.
More importantly, the legislation reflects a broader shift in Australian cybersecurity: businesses are increasingly expected to know what they would do before a cyber incident occurs.
So what actually applies to an Australian SMB?
What Is the Cyber Security Act 2024?
The Cyber Security Act 2024 introduces four major measures:
- Minimum cybersecurity standards for certain consumer smart devices.
- Mandatory reporting of ransomware and cyber-extortion payments by certain businesses.
- Limited-use protections for some information voluntarily provided to the National Cyber Security Coordinator during a cyber incident.
- The establishment of a Cyber Incident Review Board to review significant incidents and share lessons with industry.
For most ordinary SMBs, the two areas that deserve immediate attention are ransomware reporting and smart-device security.
Does the Cyber Security Act Apply to Small Businesses?
The answer is: potentially, yes — but it depends on which part of the Act you are looking at.
There is no blanket rule saying every Australian small business suddenly has the same obligations.
For example, the mandatory ransomware-payment reporting regime generally captures businesses carrying on business in Australia with annual turnover at or above the prescribed threshold, as well as certain entities responsible for critical-infrastructure assets.
The current threshold is $3 million in annual turnover. Home Affairs guidance says captured businesses that make a ransomware or cyber-extortion payment, or become aware that one has been made on their behalf, generally need to report it within 72 hours.
That $3 million figure is important.
A business does not need to be a large enterprise to reach $3 million in annual turnover.
A growing accounting firm, medical practice, retailer, construction company, professional-services firm, technology provider or e-commerce business could potentially cross that threshold while still thinking of itself as a small or medium-sized business.
The $3 Million Ransomware Reporting Threshold
Mandatory ransomware and cyber-extortion payment reporting commenced on 30 May 2025. Home Affairs subsequently moved from its initial education-first period to what it describes as a more active compliance and education approach from 1 January 2026 onwards.
Broadly, the reporting requirement can apply when:
- the organisation is a reporting business entity under the Act;
- it has been directly or indirectly affected by a ransomware or cyber-extortion incident; and
- it makes a payment, or becomes aware that a payment has been made on its behalf.
The report generally needs to be made within 72 hours of the payment being made, or the business becoming aware that a payment was made on its behalf.
This creates an important operational question:
Could your business gather the required information within 72 hours while simultaneously dealing with a ransomware attack?
That is where preparedness becomes critical.
What Information Could a Business Need After a Ransomware Payment?
The reporting regime can require information about the organisation, the cyber incident, the demand, the payment and communications with the threat actor.
Home Affairs guidance includes information such as:
- when the incident occurred;
- when the organisation became aware of it;
- how the business and its customers were affected;
- ransomware or malware involved, where known;
- vulnerabilities believed to have been exploited;
- details of the demand;
- details of the payment;
- communications with the extorting party; and
- relevant information that could assist government response or mitigation.
Trying to reconstruct all of that after an attack has already encrypted systems, disabled email or disrupted operations can be extremely difficult.
That is why an incident-response plan should include more than simply:
“Call IT if something goes wrong.”
The business needs to know who makes decisions, who preserves evidence, who contacts cyber specialists, who communicates with insurers and legal advisers, and who is responsible for any required regulatory notifications.
What About Businesses Under $3 Million?
This is where some commentary around the Cyber Security Act can become misleading.
A business below the ransomware-reporting turnover threshold is not automatically subject to that particular mandatory reporting obligation simply because it suffers ransomware.
But that does not mean the Cyber Security Act is irrelevant.
There are several reasons smaller businesses should still understand it.
1. You May Grow Into the Threshold
A company turning over $2.5 million today may exceed $3 million next year.
Cybersecurity governance should not suddenly begin the day revenue crosses a legislative threshold.
Putting basic incident-response procedures, logging and escalation processes in place beforehand makes the transition far easier.
2. Your Customers May Expect More From You
SMBs increasingly operate inside larger organisations’ supply chains.
Customers may ask suppliers to demonstrate cybersecurity controls, incident-response capabilities, cyber insurance, staff training or security monitoring regardless of whether legislation imposes the same direct obligations on every supplier.
A business can therefore feel the impact of Australia’s changing cybersecurity environment indirectly through procurement and contractual requirements.
3. Cyber Incidents Do Not Respect Revenue Thresholds
Ransomware operators do not check whether a company falls within a legislative reporting threshold before attacking it.
A ten-person business can still lose access to Microsoft 365, accounting systems, customer records, backups or operational systems.
Whether reporting is mandatory or voluntary, the underlying incident still needs to be contained and investigated.
Small Retailers and Technology Businesses Should Pay Attention to the Smart-Device Rules
Another important part of the Act relates to consumer-grade smart devices.
The Cyber Security (Security Standards for Smart Devices) Rules 2025 commenced on 4 March 2026, following a 12-month transition period. The rules apply to many smart devices manufactured from that date and intended for personal, domestic or household use.
This can matter to smaller businesses because the obligations are not only relevant to giant electronics manufacturers.
An Australian SMB could potentially be involved as a:
- manufacturer;
- importer;
- distributor;
- supplier; or
- retailer of connected consumer devices.
Examples might include connected security cameras, smart-home devices, network-connected appliances or other Internet of Things products, subject to the detailed scope and exemptions in the legislation.
The government requirements include measures addressing:
- universal default passwords;
- mechanisms for reporting security vulnerabilities;
- publication of the period for which a device will receive security support; and
- statements of compliance for products within scope.
Certain products, including laptops, desktop computers, smartphones and tablets, are excluded from these particular rules.
For suppliers of in-scope devices, the legislation also includes requirements relating to supplying products with a statement of compliance.
That means a relatively small online retailer or technology distributor should not assume these obligations only sit with multinational manufacturers.
Why This Matters Beyond Compliance
The bigger lesson from the Cyber Security Act is not simply that businesses have another piece of legislation to read.
It is that cybersecurity is increasingly becoming part of normal business governance.
Consider what would happen if ransomware affected your business tomorrow.
Would you know:
- which systems were compromised?
- when the intrusion started?
- whether customer data had been accessed?
- whether your backups were safe?
- who was authorised to speak to an attacker?
- who could approve a payment?
- whether your insurer had to be contacted first?
- whether government reporting obligations applied?
- who would preserve forensic evidence?
- how customers and employees would be informed?
Those are operational questions, not purely technical questions.
A business that waits until an attack to answer them will be making high-pressure decisions while its systems may already be unavailable.
Seven Practical Steps SMBs Can Take
You do not need an enterprise-sized cyber team to become better prepared.
Start with these seven areas.
1. Know Whether the Legislation Applies to You
Confirm your annual turnover and determine whether your organisation has any obligations associated with critical infrastructure, ransomware reporting or smart-device manufacturing and supply.
If your position is unclear, obtain appropriate legal or compliance advice.
2. Create a Cyber Incident Response Plan
Document exactly what happens when a serious cyber incident is discovered.
Include internal decision-makers, IT providers, cybersecurity responders, legal advisers, insurers and relevant government reporting channels.
3. Establish an External Incident-Response Contact Before an Attack
The middle of a ransomware incident is a poor time to start searching for a digital-forensics company.
Know who you will call before you need them.
4. Improve Logging and Monitoring
If an incident occurs, investigators may need to establish what happened, when it happened and which systems were affected.
Appropriate endpoint, identity, cloud and network monitoring can make that process substantially easier.
5. Protect Administrative Accounts
Use multi-factor authentication, restrict privileged access and remove unnecessary administrator accounts.
Compromised privileged credentials can turn an isolated attack into a business-wide incident.
6. Test Your Backups
Having backups is different from knowing they can be restored.
Backups should be appropriately protected from the production environment and recovery procedures should be tested.
7. Run an Incident Exercise
Sit your management team around a table and ask:
“Microsoft 365 is unavailable, files are encrypted and an attacker is demanding $200,000. What happens next?”
The gaps become obvious very quickly.
Cybersecurity Regulation Is Moving Downstream
For years, cybersecurity compliance was largely viewed as an enterprise issue.
That distinction is becoming less useful.
Technology supply chains, cyber insurance, privacy obligations, customer contracts and new cyber-specific legislation increasingly connect businesses of every size.
Australia’s Cyber Security Act 2024 does not impose identical requirements on every small business.
But it does reinforce an important direction of travel:
Australian businesses are being expected to take cyber resilience, incident response and secure technology more seriously.
For an SMB, that does not necessarily mean building a security operations centre or hiring a large internal cybersecurity team.
It means knowing your risks, preparing for incidents and having access to the right expertise when something goes wrong.
Frequently Asked Questions
Does the Cyber Security Act 2024 apply to every Australian small business?
No. Different parts of the Act have different scopes and eligibility criteria. For example, mandatory ransomware-payment reporting generally applies to businesses meeting the prescribed turnover threshold or certain critical-infrastructure entities, while smart-device provisions can apply to manufacturers and suppliers of relevant consumer devices.
What is the ransomware reporting threshold in Australia?
The Cyber Security (Ransomware Payment Reporting) Rules 2025 specify a $3 million annual-turnover threshold, subject to the detailed provisions and calculation rules.
How long does a business have to report a ransomware payment?
For businesses captured by the mandatory regime, a ransomware or cyber-extortion payment generally needs to be reported within 72 hours of making the payment or becoming aware that a payment was made on the business’s behalf.
Do you have to report a ransom demand if you do not pay?
Under the mandatory payment-reporting regime, Home Affairs states that an incident where a demand is made but no payment is provided does not trigger that particular mandatory reporting requirement. Businesses are nevertheless encouraged to report cyber incidents voluntarily through the Australian Signals Directorate.
Does the Cyber Security Act cover smart devices?
Yes. New mandatory standards for many consumer-grade smart devices commenced on 4 March 2026. The requirements address areas including default passwords, vulnerability reporting, security-support periods and statements of compliance.
Is Your Business Ready for a Cyber Incident?
Cyber regulations will continue to evolve, but businesses do not need to wait for another regulatory change before improving their security posture.
CyberSure helps Australian small and mid-sized businesses strengthen cyber resilience through proactive monitoring, threat detection, cyber awareness, incident preparedness and access to specialist incident-response capabilities.
The objective is simple: identify risks earlier, respond faster and minimise the financial and operational impact when something goes wrong.
Cybersecurity should not begin after the breach.
Prepare before you need to respond.
This article provides general information only and does not constitute legal advice. Businesses should obtain advice appropriate to their circumstances when determining whether particular obligations under the Cyber Security Act 2024 apply to them.