Bill
Ransomware Payments Bill 2021 (No. 2)
lapsed, as at 2022-07-25.
- Sponsor
- KENEALLY, Sen Kristina
- Portfolio
- Not recorded
Recorded stages
- introduced — 2021-08-12
- second reading — 2021-08-12
- other — 2022-07-25
Divisions
No divisions recorded. Most questions are decided on the voices; this does not establish that a bill was unopposed.
Plain-language summary
Written by a model from the explanatory memorandum; not the record, as at 2021-08-12.
This bill would make it compulsory for most organisations that pay a ransom after a ransomware attack to tell the Australian Cyber Security Centre about the attack and payment.
The Australian Cyber Security Centre would collect the reports and could share de-identified information with the private sector and law enforcement.
Small businesses with an annual turnover below $10 million would be exempt from the reporting requirement.
- Creates a mandatory notification scheme for ransomware payments.
- Requires entities to provide details of the attack, attacker and payment to the Australian Cyber Security Centre.
- Sets a civil penalty for failing to notify.
- Allows the Australian Cyber Security Centre to share de-identified information for threat awareness and law enforcement.
- Excludes small businesses with turnover under $10 million from the scheme.
- Makes it an offence to disclose personal information from a report except for law enforcement purposes.
Commonwealth entities, state and territory agencies, and private businesses with an aggregate turnover of more than $10 million, but not small businesses, sole traders, unincorporated entities or charities.
Sources
em
billhome