Insights › Backups & Ransomware

Ransomware Explained: How Australian Businesses Can Prevent and Recover

Conceptual illustration of a glowing padlock and chains encrypting data files on a navy background.

Ransomware is one of the most disruptive cyber threats facing Australian businesses today. In minutes, it can lock you out of your own files, halt your operations, and leave you staring at a demand for payment, usually in cryptocurrency, in exchange for getting your data back. For a small or medium business, the fallout can be brutal: days of downtime, lost revenue, damaged customer trust, and in many cases a reportable data breach.

The encouraging news is that ransomware is largely preventable, and a business that prepares in advance can recover from an attack without paying a cent. This guide explains, in plain English, how ransomware works, what it really costs, and the practical steps you can take right now.

What is ransomware, and how does it get in?

Ransomware is malicious software that encrypts your files so nothing will open, then demands payment for the key to unlock them. Increasingly, attackers steal a copy of your data first and threaten to publish it (a tactic known as “double extortion”) so that even businesses with solid backups feel pressure to pay.

Most attacks begin in one of a few predictable ways:

The real cost of an attack

The ransom itself is often the smallest part of the bill. The bigger costs are downtime and recovery: systems offline for days, staff unable to work, orders unfulfilled, and the slow, expensive job of rebuilding servers and restoring data. On top of that sit reputational damage and potential legal obligations if personal information is exposed.

An important legal change to be aware of: since 30 May 2025, Australian businesses with an annual turnover of $3 million or more must report any ransomware payment to the Australian Signals Directorate (ASD) within 72 hours of making it, or of becoming aware a payment was made on their behalf. Paying a ransom is not illegal, but this reporting obligation is now law, and many businesses don’t yet know it exists.

How to prevent ransomware

Prevention doesn’t require a big security budget; it requires doing the fundamentals consistently. These measures align closely with the Australian Government’s ACSC Essential Eight:

What to do if you’re hit

If ransomware does get through, a calm, prepared response makes all the difference:

  1. Isolate. Disconnect affected devices from the network immediately to stop the spread, but avoid switching them off if you can, as that can destroy useful evidence.
  2. Don’t rush to pay. Engage your IT provider or an incident response specialist first. Paying doesn’t guarantee you get your data back, and it funds further crime.
  3. Report it. Report the attack through ReportCyber at cyber.gov.au. If your turnover is $3 million or more and you make a payment, remember the 72-hour reporting obligation to the ASD.
  4. Check for a data breach. If personal information may have been accessed, you may have obligations under the Notifiable Data Breaches scheme to notify the OAIC and affected individuals.
  5. Recover from backups. Once systems are clean, restore from known-good backups rather than paying for a decryption key.

Recovery comes down to preparation

The businesses that survive ransomware with the least pain are almost always the ones that prepared before anything went wrong: reliable, tested backups; MFA on every account; up-to-date systems; and a simple written plan for who does what if the worst happens. None of it is exotic, and all of it is far cheaper than a serious incident.

Related reading: for a focused plan on backups, recovery and the ransom question, see our guide to backups and ransomware recovery, and the complete guide to cyber security for small business in Australia.

Not sure where your business stands? Take our free cyber security assessment to see how well protected you are against ransomware and other common threats, and get clear, practical steps to close the gaps.

Discover more from Security Score

Subscribe now to keep reading and get access to the full archive.

Continue reading