
Ransomware is one of the most disruptive cyber threats facing Australian businesses today. In minutes, it can lock you out of your own files, halt your operations, and leave you staring at a demand for payment, usually in cryptocurrency, in exchange for getting your data back. For a small or medium business, the fallout can be brutal: days of downtime, lost revenue, damaged customer trust, and in many cases a reportable data breach.
The encouraging news is that ransomware is largely preventable, and a business that prepares in advance can recover from an attack without paying a cent. This guide explains, in plain English, how ransomware works, what it really costs, and the practical steps you can take right now.
What is ransomware, and how does it get in?
Ransomware is malicious software that encrypts your files so nothing will open, then demands payment for the key to unlock them. Increasingly, attackers steal a copy of your data first and threaten to publish it (a tactic known as “double extortion”) so that even businesses with solid backups feel pressure to pay.
Most attacks begin in one of a few predictable ways:
- Phishing emails that trick a staff member into opening a malicious attachment or clicking a link.
- Stolen or weak passwords that let attackers log straight into remote access tools, email or VPNs.
- Unpatched software with known vulnerabilities an attacker can exploit.
- Compromised suppliers whose systems connect to yours.
The real cost of an attack
The ransom itself is often the smallest part of the bill. The bigger costs are downtime and recovery: systems offline for days, staff unable to work, orders unfulfilled, and the slow, expensive job of rebuilding servers and restoring data. On top of that sit reputational damage and potential legal obligations if personal information is exposed.
An important legal change to be aware of: since 30 May 2025, Australian businesses with an annual turnover of $3 million or more must report any ransomware payment to the Australian Signals Directorate (ASD) within 72 hours of making it, or of becoming aware a payment was made on their behalf. Paying a ransom is not illegal, but this reporting obligation is now law, and many businesses don’t yet know it exists.
How to prevent ransomware
Prevention doesn’t require a big security budget; it requires doing the fundamentals consistently. These measures align closely with the Australian Government’s ACSC Essential Eight:
- Patch quickly. Keep operating systems and applications up to date so known holes are closed before attackers use them.
- Turn on multi-factor authentication (MFA) everywhere you can, especially email and remote access.
- Back up regularly and keep one copy offline or immutable, following the 3-2-1 rule, so backups can’t be encrypted along with everything else.
- Restrict administrator privileges to the people who genuinely need them.
- Filter email and train staff to recognise phishing, because your people are the first line of defence.
What to do if you’re hit
If ransomware does get through, a calm, prepared response makes all the difference:
- Isolate. Disconnect affected devices from the network immediately to stop the spread, but avoid switching them off if you can, as that can destroy useful evidence.
- Don’t rush to pay. Engage your IT provider or an incident response specialist first. Paying doesn’t guarantee you get your data back, and it funds further crime.
- Report it. Report the attack through ReportCyber at cyber.gov.au. If your turnover is $3 million or more and you make a payment, remember the 72-hour reporting obligation to the ASD.
- Check for a data breach. If personal information may have been accessed, you may have obligations under the Notifiable Data Breaches scheme to notify the OAIC and affected individuals.
- Recover from backups. Once systems are clean, restore from known-good backups rather than paying for a decryption key.
Recovery comes down to preparation
The businesses that survive ransomware with the least pain are almost always the ones that prepared before anything went wrong: reliable, tested backups; MFA on every account; up-to-date systems; and a simple written plan for who does what if the worst happens. None of it is exotic, and all of it is far cheaper than a serious incident.
Related reading: for a focused plan on backups, recovery and the ransom question, see our guide to backups and ransomware recovery, and the complete guide to cyber security for small business in Australia.
Not sure where your business stands? Take our free cyber security assessment to see how well protected you are against ransomware and other common threats, and get clear, practical steps to close the gaps.