Why ransomware remains the biggest cyber threat to Australian businesses

A Brisbane professional services firm we work with received a ransom demand on a Monday morning. Every file on their shared drives was encrypted. Their client records, contracts, billing data, all locked. The attacker wanted payment in cryptocurrency within 48 hours. The firm had no tested backup. They lost three weeks of billable time recovering what they could.
Ransomware is not a new threat. But the way it works and the scale of the damage it causes have changed significantly. If your business has not reviewed its position recently, this article covers what the current threat looks like and what practical steps reduce your exposure. Our IT security assessments are a good starting point if you want an objective view of where you stand.
What ransomware actually does to a business
Ransomware is malicious software that locks you out of your own data. Attackers encrypt your files, then demand payment to restore access. That is the original model, and it still happens. But the threat has evolved.
Most modern attacks now use a technique called double extortion. The ACSC describes ransomware as “effective, high-impact malware that can cripple an organisation’s ability to function.” Before encrypting anything, attackers quietly copy your data out of your network first. They then threaten to publish that data publicly if you refuse to pay, even if you can restore from backup. This means good backups protect you from the encryption, but not automatically from the extortion threat.
Ransomware spreads the same way as other malware. Phishing emails are the most common entry point, accounting for roughly 41% of incidents (bluefire-redteam research, 2026). Attackers also use compromised credentials, unpatched software, and exposed remote desktop connections. Once inside, the malware attempts to spread to shared storage, connected devices, and any accessible system before triggering the lock.
The scale of the problem in 2025 and 2026
The numbers from Australia’s own cyber security agency are sobering. The ACSC’s Annual Cyber Threat Report 2024-25 confirmed that ransomware remains the most disruptive cybercrime threat in Australia. The ACSC responded to 138 ransomware incidents in FY2024-25 alone, and 39% of those responses began because the ACSC had to contact the affected organisation first, the victim did not even know they had been hit.
Globally, Verizon’s 2025 Data Breach Investigations Report found ransomware was present in 44% of all confirmed breaches, a 37% increase on the prior year. For small and mid-sized businesses specifically, ransomware was involved in 88% of breaches. The total cost of a ransomware incident, including downtime, recovery, legal exposure, and reputational damage, can reach roughly $5 million per incident when all costs are counted. That figure dwarfs the ransom itself.
A new legal obligation Australian businesses need to know
Australia now has mandatory ransomware reporting under the Cyber Security Act 2024, which received Royal Assent in November 2024. The reporting obligation commenced on 30 May 2025, with full enforcement from 1 January 2026.
If your business has an annual turnover of $3 million or more, you must report any ransomware payment to the Australian Signals Directorate (ASD) within 72 hours of making or becoming aware of that payment. Non-compliance carries civil penalties of up to $19,800. The report goes through the cyber.gov.au portal and covers the nature of the demand, payment details, and the attacker’s communication. The intent is intelligence gathering, not punishing victims.
Even if your turnover sits below the $3 million threshold, the same preparation matters. If you sit in the supply chain of a larger organisation, an incident in your environment can trigger obligations upstream.
Should you pay the ransom?
TTA’s position is clear: do not pay. There is no guarantee paying the ransom will restore your data or your systems. Verizon’s 2025 research found 64% of businesses that experienced ransomware did not pay, relying instead on their incident response plans and backups to recover. Those businesses that had tested backups and a documented response plan fared far better than those that paid and hoped for the best.
Paying also signals to attackers that you are a willing payer. It can make you a repeat target. And under the new mandatory reporting regime, paying triggers a 72-hour reporting obligation anyway. The better path is to have the controls in place so you never face that choice.
How to reduce your ransomware risk
The good news is that the controls that protect against ransomware are well understood. The ASD’s Essential Eight framework covers the key mitigations. The businesses that recover quickly from attacks, or avoid them entirely, consistently apply these practices:
- Keep all software and operating systems patched and up to date. Attackers exploit known vulnerabilities in unpatched systems.
- Maintain tested offline or immutable backups. Backups connected to your network can be encrypted along with everything else. Offline backups cannot.
- Use multi-factor authentication (MFA) on all accounts, especially email, remote access, and admin accounts.
- Run up-to-date endpoint protection across all devices, including managed anti-virus and where possible, managed detection and response (MDR).
- Train your staff. Phishing is still the most common entry point. A well-prepared team is a genuine layer of defence.
- Have a documented incident response plan before you need it. Knowing who to call and what to isolate in the first 30 minutes can limit the spread significantly.
For practical backup options, we work with Acronis Cloud Backup and Datto Backup to give Queensland businesses immutable, regularly tested backup environments. Both are designed to get you back online quickly, not just to tick a compliance box.
Frequently asked questions
What is ransomware in simple terms?
Ransomware is software that attackers install on your systems to lock you out of your files. They then demand payment to restore access. Modern attacks often also steal your data before locking it, so attackers can threaten to publish it even if you can restore from a backup. The result is operational disruption, financial loss, and potential reputational damage.
Does ransomware only affect large businesses?
No. Small and mid-sized businesses are disproportionately targeted. Verizon’s 2025 research found ransomware was involved in 88% of breaches affecting smaller businesses. Attackers target smaller organisations because they often have weaker controls than large enterprises but still hold data worth encrypting or stealing.
Do I have to report a ransomware attack to the government in Australia?
If your business has an annual turnover of $3 million or more and you make a ransomware payment, you must report it to the Australian Signals Directorate within 72 hours under the Cyber Security Act 2024. This reporting obligation has been in full enforcement since 1 January 2026. Businesses below that threshold are not legally required to report payments, but voluntary reporting to the ACSC is encouraged.
Should we pay the ransom if we are hit?
TTA advises against paying. Paying the ransom does not guarantee your data will be restored, and it can make you a target for future attacks. Building tested backups and a documented response plan is a more reliable investment. Businesses that had offline backups and a clear response procedure consistently recover faster and with less total cost than those that paid.
What is the quickest way for a small business to improve its ransomware protection?
Start with three actions: enable multi-factor authentication on all accounts, ensure you have at least one offline or offsite backup that is tested regularly, and apply all outstanding software patches. These three steps address the most common attack vectors and significantly reduce the likelihood of a successful ransomware deployment in your environment.
Where can I get help assessing my ransomware risk in Brisbane?
TTA works with businesses across South-East Queensland to assess and strengthen cyber security posture. An IT security assessment will identify gaps in your current controls and give you a practical, prioritised plan. We can also help you set up tested backup environments, staff training, and incident response documentation.
How do we get started?
If you want to understand where your business stands on ransomware risk, we are glad to have that conversation. Get in touch with the TTA team and we can walk you through your current exposure and what a practical protection plan looks like for your size and industry.



