Three shifts happened this quarter, and once you line them up, they tell a simple story.
There's a specific moment that shows up in most board packs, somewhere between the budget line and the risk register. Someone asks, almost in passing, whether anything's changed on compliance. This quarter, the answer is yes, and it's a reassuring one to have on hand.
Across the past few months, a pattern starts to emerge. Three separate pieces of regulation, three different parts of government, and all of them are moving toward the same idea: it's less about whether you have a policy, and more about whether you can show it's working when someone asks.
Quick version, if you're skimming before the meeting:
- Ransomware payment reporting moved from legislation to active enforcement on 1 January 2026. Entities over AUD $3 million turnover have 72 hours to report a payment to the Australian Signals Directorate.
- The Privacy Act's automated decision-making disclosure requirement takes effect 10–11 December 2026. If AI or automated tools make decisions that affect people in your organisation, your privacy policy will need to say so.
- The Essential Eight is evolving into ASD's new Essentials series over roughly two years. We've covered that one in full elsewhere, so treat this as a pointer.
The first shift: reporting is now actively enforced
Ransomware payment reporting has been law since May 2025. What's changed is that it's now actively enforced.
Any organisation carrying on business in Australia with an annual turnover of AUD $3 million or more, along with entities responsible for critical infrastructure, counts as a "reporting business entity" under the Cyber Security Act 2024. If that entity makes a ransomware or cyber extortion payment, or becomes aware one's been made on its behalf, it has 72 hours to report it to the Australian Signals Directorate. For the first seven months, the approach focused on education rather than enforcement. From 1 January 2026, the Department of Home Affairs moved to active compliance and enforcement, and that's been the operating reality for more than half a year now.
A lot of NFP, NDIS and care sector organisations sit above that $3 million threshold without realising it, since it's common territory for an established provider. It's worth checking whether your incident response plan already names who owns that 72-hour reporting window.
The second shift: easy to miss
If reporting is about showing what happened after the fact, the next shift is about showing what you're doing before anyone asks.
Australia's privacy reforms have been rolling out in stages since late 2024, and most of the headline changes, like the statutory tort for serious invasions of privacy, are already in force. The one to put on the calendar now is the automated decision-making disclosure requirement, which takes effect on 10–11 December 2026. From that date, organisations need to disclose in their privacy policies what kinds of decisions get made using personal information through automated means, AI included.
AI is reshaping both sides of the security equation at once, and Australian regulators are moving to keep pace. For any organisation exploring AI tools for intake, triage or eligibility assessment, this applies directly. The disclosure requirement is worth building into project planning well ahead of December, while there's still plenty of runway.
The third shift: one you may already know
You may recognise this pattern from a piece we published in July: Essential Eight Retirement: What Changes for You. In short, ASD is retiring the Essential Eight over roughly two years in favour of a broader, outcomes-based Essentials series. Your existing investment carries straight across, building on what you've already done rather than replacing it. Read the full piece if a maturity level has come up in a tender, grant application or insurance renewal lately.
What that looks like day to day
Once you see the pattern, the response to it stops feeling like three separate problems, and starts looking like one consistent habit.
In practice, that's the same tools and configuration held across every environment, multi-factor authentication enforced as standard, backups tested on a regular cadence, and open conversations about which AI tools a team is actually using day to day. Small, ongoing habits like these are what make questions like this quarter's easy to answer, because there's already something solid to show.
Take what's useful
So if someone in your next board pack asks whether anything's changed, you've now got a proper answer instead of a slide of headlines.
We handle the tech-aches so you can stay focused on the mission. Take what's useful here, and if you want to talk through the rest, we're happy to.
FAQ
Does the ransomware payment reporting rule apply to my organisation? It applies if your organisation carries on business in Australia with an annual turnover of AUD $3 million or more in the last financial year, or if you're responsible for a critical infrastructure asset. Reporting is only required if a payment is made, not simply because you received a demand.
What happens if we don't report a ransomware payment in time? Non-compliance can attract a civil penalty of up to 60 penalty units (currently AUD $19,800). Reports go to the Australian Signals Directorate within 72 hours of the payment being made or discovered.
Do we need to update our privacy policy before December 2026? If your organisation uses AI or automated tools to make decisions affecting individuals, such as eligibility, triage or intake decisions, yes. The disclosure requirement takes effect 10–11 December 2026, so it's worth actioning well ahead of that date.
Is the Essential Eight still relevant if it's being retired? Yes. ASD has confirmed the transition will take roughly two years, and existing Essential Eight investment carries across to the new Essentials series. It remains the current, supported framework in the meantime.



.png)
.png)





