A reporting business entity that makes, or whose entity makes on its behalf, a ransomware or cyber-extortion payment in response to a cyber security incident must report the payment to the designated Commonwealth body within 72 hours of making the payment or becoming aware it was made.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.