Why Australian businesses keep paying cyber ransoms (and how to avoid the decision entirely)

Ransomware has become one of the most reliable earners in organised cybercrime, partly because Australian businesses have proven willing to pay. A December 2025 study by Rubrik Zero Labs found that Australian organisations experienced the highest rate of ransomware attacks of any country surveyedwith 95% of those hit reporting they paid a ransom to recover systems or halt the attack. Only Singapore recorded a higher payment rate.
That figure is a long way from the old belief that “we’d never pay criminals”. The pattern we see at TTA is the same one the data describes: when a business is staring at locked systems and a clock ticking on their client data being published online, the decision stops feeling like a principle and starts feeling like maths. Our cyber insurance compliance work with Queensland businesses shows that preparation, not willpower, is what keeps the maths in your favour.
Here is what the current threat looks like, why paying rarely ends well, and what actually works.
The ransomware landscape in Australia right now
The Australian Signals Directorate’s (ASD) Annual Cyber Threat Report for FY2024-25 confirmed that ransomware remains the most disruptive cybercrime threat in Australia. The ASD’s Australian Cyber Security Centre (ACSC) responded to 138 ransomware incidents in that period, and 39% of those were only discovered because the ACSC proactively alerted the affected organisation. That means a significant share of businesses had no idea they were compromised.
The broader numbers are sobering. Over 84,700 cybercrime reports were submitted to the ACSC in FY2024-25, one every six minutes. The average reported financial loss per cybercrime incident for businesses jumped 50% to $80,850. For large organisations, losses rose 219%. Healthcare was hit hardest: ransomware incidents against the sector doubled compared to the previous year.
Professional services, legal, accounting, and construction firms were specifically targeted by groups including Qilin, Akira, and Lynx. These are not random opportunistic attacks. They are deliberate, industry-targeted campaigns.
What modern ransomware actually does
The old version of ransomware was simpler: files got encrypted, a ransom note appeared, you either paid or restored from backup. That model still exists, but it is no longer the whole story.
In 2025 and into 2026, the dominant approach is double extortion. Attackers spend days or weeks inside a network before triggering any ransom demand. During that time, they locate and copy sensitive data, disable or delete backup systems, and move laterally to maximise the damage they can threaten. By the time the ransom note appears, the attacker typically holds your client files, financial records, or employee data and threatens to publish them if you do not pay.
Research from BlackFog found that 96% of ransomware attacks in Q3 2025 involved data exfiltration alongside encryption. A separate figure from Australian sources puts it at 87% for 2025 overall. The point is the same: a good backup strategy protects you from the encryption side of the attack. It does not protect you from the extortion of your client data.
This matters a great deal for businesses that hold sensitive client information, which describes most professional services firms we work with across Brisbane and South-East Queensland.
Paying rarely solves the problem
The case against paying is stronger than most businesses realise when they are in the middle of an incident.
- Only 13% of victims who pay receive all of their data back.
- Around 69-70% of organisations that paid were attacked again, often by the same group or an affiliate.
- The average recovery cost for a medium-sized Australian business in 2025 was around $97,000, excluding any ransom payment. The ransom itself is only part of the total cost.
- The median ransom paid by Australian small and medium businesses in 2025 was around $54,000. Paying does not guarantee a faster or more complete recovery.
There is also a newer legal dimension. Since May 2025, Australia’s Cyber Security Act 2024 has required businesses with annual turnover exceeding $3 million to report any ransomware payment to the ASD within 72 hours. From January 2026, the Department of Home Affairs moved to active enforcement. Paying a ransom is no longer a quiet private decision for businesses above that threshold. It is a reportable event with potential penalties for non-compliance.
What businesses should have in place before an attack
The businesses that recover quickly from ransomware share a few consistent characteristics. They patch promptly. They enforce multi-factor authentication (MFA). They maintain tested, offline backups. And they have a documented incident response plan ready before anything goes wrong.
The ASD’s Essential Eight framework covers all of these controls. Organisations at Maturity Level 2 are significantly more resilient against ransomware. For most Queensland SMEs we work with, reaching Level 1 or 2 across the eight controls makes a material difference to both the likelihood of an incident and the cost of recovering from one.
For a practical starting point, our IT security assessments identify where a business sits against these controls and what the most cost-effective steps are to improve. You do not need to do everything at once. A sequenced plan targeting the highest-risk gaps first is more achievable and still delivers meaningful protection.
Backup remains essential, but the approach needs updating
A solid backup strategy is still the single most important recovery tool a business can have. But the design of that backup matters more than it used to.
Attackers now specifically target backup systems before triggering encryption. They know that a business with working backups is less likely to pay. So they delete or encrypt the backups first. The answer is offline or immutable backups stored separately from your main network, backups that ransomware cannot reach even when it has access to your primary systems.
TTA’s data backup solutions are designed around exactly this problem. Scheduled backups run automatically, with copies replicated to cloud environments outside the reach of local network compromise. Data can be recovered from multiple points in time, and cloud virtualisation can restore lost servers quickly. The goal is to remove “pay or shut down” as the only available options.
Keep in mind that even with excellent backups, a double-extortion attack still leaves you with a data exposure problem. The backup solves the encryption half. Containing client data theft requires earlier detection. This is why managed detection and response (MDR) tools that monitor for unusual data movement, not just malware signatures, are becoming a baseline expectation for any serious cyber security posture. TTA uses Huntress Managed EDR to provide this visibility for our clients.
A quick check: how exposed is your business?
These five questions give a working sense of your current ransomware exposure:
- Are your backups stored offline or in an immutable environment separate from your network?
- Have you tested a full restore in the last six months?
- Is MFA enforced on every account that can access your business systems remotely?
- Do you have a written incident response plan, and does your team know the first steps?
- If your systems were encrypted tomorrow, how long would recovery actually take?
If any of these questions are uncomfortable to answer, that is the starting point. Our IT audit service works through these gaps methodically, without the pressure of an active incident.
Frequently asked questions about ransomware for Australian businesses
Should my business pay a ransomware demand?
The Australian Government does not condone paying ransoms, and the data supports that position. Only around 13% of victims who pay get all their data back, and roughly 70% are attacked again. Paying funds future attacks and does not guarantee recovery. The better position is having backups and a response plan that make payment unnecessary. If you do pay and your turnover exceeds $3 million, you must report the payment to the ASD within 72 hours under the Cyber Security Act 2024.
What is double extortion ransomware?
Double extortion means attackers steal your data before encrypting it. They then threaten to publish the stolen data publicly if you do not pay, even if you can restore from backup. This affects businesses that hold sensitive client or employee data, which includes most professional services firms. In 2025, the vast majority of ransomware attacks used this approach, so backups alone are no longer a complete defence.
How much does a ransomware attack cost an Australian SME?
The median ransom paid by Australian small and medium businesses in 2025 was around $54,000. Average recovery costs for medium businesses reached approximately $97,000, not including the ransom. Total costs, factoring in downtime, lost productivity, legal fees, and reputational damage, often run well above these figures. The ASD’s FY2024-25 report found the average reported loss across all cybercrime incidents rose 50% to $80,850.
What is the mandatory ransomware reporting law in Australia?
Under the Cyber Security Act 2024, businesses with annual turnover above $3 million and operators of critical infrastructure must report any ransomware payment to the Australian Signals Directorate within 72 hours of making it. This took effect in May 2025, with active enforcement from January 2026. Non-compliance can result in civil penalties. The law applies whether the ransom is paid in currency, cryptocurrency, or another form of value.
Can a good backup strategy stop a ransomware attack?
A good backup strategy is essential and removes the pressure to pay when files are encrypted. But it does not stop data theft, which is now part of most ransomware attacks. Attackers often delete or encrypt backup systems before triggering the ransom demand. Offline or immutable backups that are stored separately from your network solve the first problem. Detecting unusual data movement early, before encryption is triggered, addresses the second.
Where do I start with ransomware protection for my business?
Start with the Australian Signals Directorate’s Essential Eight controls: application control, patching applications, patching operating systems, restricting Microsoft Office macros, user application hardening, limiting admin privileges, multi-factor authentication, and regular backups. These eight controls, applied consistently, address the most common ransomware entry points. An independent IT security assessment can identify which controls are missing or weak and help you prioritise the highest-risk gaps first.
How do we get started?
If you are not confident about your current ransomware exposure, the right first step is a conversation. TTA works with small and medium businesses across Brisbane and South-East Queensland to put the right protections in place before an incident, not after. Get in touch with us and we can talk through where your business stands and what practical steps make sense.



