The decision nobody wants to make
The ransom note is on every screen, the file shares are encrypted, and within a few hours a question lands with whoever runs the business: do we pay. Australian law does not flatly prohibit paying a ransom, and the Australian Signals Directorate's standing advice is to never pay, because payment funds the next campaign and guarantees nothing. The decision sits between those two facts. It is usually made under extreme time pressure, on incomplete information, by people who have never rehearsed it.
This note sets out what actually surrounds the decision for an Australian business: the sanctions exposure that can make a specific payment a crime, the mandatory reporting obligation that now applies above a turnover threshold, the position your insurer will take, and the reasons a payment so rarely ends the incident. The aim is a decision made with the whole picture in view. With the right preparation in place, the question rarely carries much weight when it actually arrives.
Where paying becomes a crime
There is no general offence of paying a ransom in Australia. The serious legal risk is specific, and it is sanctions. The Autonomous Sanctions Act 2011 and the Charter of the United Nations Act 1945 make it an offence to make an asset available, directly or indirectly, to a person or entity on a sanctions list, and Australia has used its cyber sanctions framework to designate individuals connected to ransomware attacks on Australian organisations. The penalties are criminal, they can attach to the company and to individuals, and they do not depend on the payment being large.
The practical problem is that you almost never know who you are paying. Ransomware operations run as affiliate schemes, groups dissolve and rebrand, and payments move through wallets and mixers built to defeat attribution. The word indirectly does a lot of work in the offence: routing the payment through a negotiator, a broker or an overseas intermediary does not change the legal position if the money reaches a designated person. Serious extortion responses therefore include sanctions due diligence run under legal advice before any payment is even contemplated, and that work can lower the risk without ever removing it. Depending on the facts, money laundering and terrorism financing offences under the Commonwealth Criminal Code can also be in play. None of this can be assessed for the first time at 11pm on the day of the demand.
If you pay, you must tell the government
The Cyber Security Act 2024 created a mandatory ransomware payment reporting obligation, and it has applied since 30 May 2025. It covers businesses carrying on business in Australia with annual turnover above a threshold set in the rules, which sits at three million dollars, the same line the Privacy Act uses to define a small business. It separately covers responsible entities for critical infrastructure assets under the SOCI Act. If your organisation is within scope and it, or anyone acting on its behalf, makes a ransomware payment in connection with a cyber security incident, a report must be given to the Australian Government within 72 hours of making the payment or becoming aware it was made.
Three details matter more than they first appear. A payment is defined broadly and includes benefits other than money. The obligation still lands on you when a third party pays, so an insurer or a negotiator settling the demand on your behalf starts your clock rather than stopping it. And the report has real content: the incident, the demand, the payment and the communications with the extortionist, which means an ad hoc negotiation someone ran from a personal phone becomes reportable material. Failing to report is a civil penalty matter. The Act wraps the report in a limited use regime that restricts how the Australian Government can use the information against the entity that provided it, which exists so businesses report honestly rather than staying silent. That regime does not remove any other legal obligation, including the sanctions regime that applies to the payment itself.
The insurer is in the room
If you carry cyber insurance with extortion cover, the policy shapes this decision more than most executives expect. Policies commonly require the insurer to be notified before external responders are engaged, and to give consent before any payment is made, and a payment made without that consent may simply not be covered. Insurers also bring their panel: breach counsel, forensic firms and specialist negotiators who handle communication with the attacker and run the sanctions checks, because everyone in the payment chain carries exposure of their own.
Two consequences follow. The first is that the policy needs reading before an incident: what the extortion cover includes, whose consent is required, where the hotline number lives, and what the policy assumed about your controls, because a control claimed at underwriting and absent in fact makes for a difficult claim. The second is that insurer consent settles the insurer's money and nothing else. The sanctions analysis and the 72-hour reporting obligation remain yours regardless of who signs the transfer.
What a payment actually buys
The commercial case for paying is usually framed as buying the business back. What arrives, if anything arrives, is a decryptor written by criminals, and it is software of about the quality you would expect: slow, sometimes broken, and applied machine by machine across an environment that is still compromised. Organisations holding a tested, isolated backup often recover faster by restoring than they would have by decrypting. The key does not evict the attacker either. Whatever accounts, access and tooling they planted are still present after you pay, so the containment, eradication and rebuild work remains in full.
Where data was stolen, payment buys a promise of deletion from an extortionist, and that promise cannot be verified. Copies persist, stolen data resurfaces, and groups have returned to re-extort businesses that paid. The legal position reflects this: the Notifiable Data Breaches assessment under the Privacy Act 1988 does not go away because you paid, and a criminal's assurance that data has been deleted is weak evidence that serious harm is no longer likely. Businesses do sometimes pay, lawfully and with careful advice, where the alternative is worse. The honest description of what they purchase is a possibility of faster recovery, at the price of funding the operator, marking themselves as willing payers, and taking on all of the legal work above.
The preparation that makes the question moot
Every part of this gets easier when it is decided in advance, and the strongest position is the one where the demand has no leverage. The organisations that decline to pay without agonising are the ones that can restore from a backup the attacker could not reach, and can prove it. The preparation is specific:
- A backup with an offline or immutable copy, and a restore that has actually been run end to end and timed against the systems the business cannot live without
- A pre-agreed decision path: who holds the payment decision, which legal counsel advises on sanctions and privilege, and the insurer hotline with the policy number, all on paper
- A position, established today, on whether the ransomware reporting obligation covers your organisation, with the 72-hour clock and the person who lodges the report written into the incident response plan
- A tabletop exercise that includes the pure extortion variant, where nothing is encrypted and the demand rests entirely on stolen data
- Identity hardening and segmentation, so one phished account cannot reach the backups or the rest of the estate
Decide it while nothing is on fire
Working the extortion scenario through a tabletop, proving the restore, and writing the decision path into a plan the leadership has actually read is standing work in Black Shard's incident response and vCISO engagements, because the depth each organisation needs turns on its systems, its data and its obligations. The self-test is short. Ask whether your business knows, today, who would decide on a payment, whether the reporting obligation applies to you, and how long a full restore takes. If any answer is a shrug, that is the place to start. This note is general information rather than legal advice, and a live extortion decision should be made with counsel and current government guidance, because it turns on facts no note can anticipate.
