What is ransomware?
Ransomware encrypts files and demands payment for recovery. Cyber extortion can also involve stolen data and a demand to prevent disclosure, with or without encryption.
In the Sophos 2026 global survey of 2,158 ransomware victims, 56 per cent of attacks encrypted data. Among cases involving encrypted data, 66 per cent used backups to recover. These are survey outcomes, not forecasts for an Australian business. They show that having a backup is only part of recovery: it must be clean, available and usable. Sophos State of Ransomware 2026.
Data theft can create an incident even if nothing is encrypted. An attacker may threaten to publish customer records, payroll or intellectual property. Backups restore availability; they cannot retrieve stolen copies. Investigate confidentiality and access alongside the work needed to restart operations.
ACSC position: do not pay
- No guarantee files are restored
- Stolen data often leaked anyway
- Payment funds further attacks and marks you as a paying target
- May breach sanctions law depending on the threat group
How attackers get in
In the same Sophos survey, respondents identified malicious email in 26 per cent of incidents, phishing in 24 per cent, compromised credentials in 23 per cent and exploited vulnerabilities in 18 per cent. These are separate reported root causes. Do not treat a global vendor survey as an Australian prevalence figure or assume one entry route explains every incident. Sophos State of Ransomware 2026.
Map the doors into your own environment: mailboxes, remote access, firewall administration, exposed applications, supplier accounts and management tools. Record who owns each service, how it authenticates and how quickly access can be revoked. A protected Microsoft 365 account does not compensate for an unprotected VPN or an abandoned vendor login.
Email and stolen credentials
A malicious attachment, fake sign-in or previously stolen credential can provide access. Cover mailboxes, VPNs and remote administration, not just one cloud service.
Exposed, unpatched services
Inventory internet-facing applications, VPNs and firewalls. Apply vendor mitigations promptly and verify deployment rather than assuming a patch job succeeded.
Remote desktop access
Avoid direct internet exposure. Restrict access through a controlled path with strong authentication, least privilege and monitored logs.
Supplier and management access
Review vendor accounts, remote-management tools and software delivery paths. Time-limit access and remove unused connections.
Internal misuse or excessive access
Limit administrative rights, separate duties and revoke access promptly when staff leave or change roles.
How ransomware spreads through a network
The sequence below is a common investigation pattern, not a mandatory order. A cloud-only business might have no domain controller; stolen SaaS sessions and excessive application permissions may be the main path instead. Watch for unusual use of administrative tools, not just a particular filename. Legitimate remote-management software becomes dangerous when the operator or credentials are compromised.
The initial foothold can let an attacker seek broader access, valuable data and recovery systems. The following stages explain what responders investigate, not a fixed timetable for every incident.
Credential theft and harvesting
The attacker may seek saved credentials, browser sessions or credentials held in memory. The result depends on privileges and device protections. Revoke compromised sessions as well as changing passwords.
Lateral movement through administration paths
Stolen accounts can be used through RDP, remote execution, WMI or management tools. These tools also have legitimate uses; suspicious context and behaviour are important signals for endpoint and identity monitoring.
Privilege escalation
In an Active Directory environment, an attacker may seek domain-level privileges. In cloud environments, privileged roles and application permissions can serve a similar purpose. Investigate elevated access before trusting restored systems.
Reconnaissance and target selection
The attacker searches for valuable data, backup platforms, shared storage and connected services. Restrict the reach of ordinary and privileged accounts so one foothold cannot access everything.
Backup attacks and data theft
An attacker may attempt to delete recovery copies, disable protection or export sensitive data. Monitor these actions and investigate outbound activity. Offline or correctly configured immutable copies can preserve a recovery option.
Encryption or extortion
The final visible action may encrypt multiple systems or demand payment over stolen data alone. A ransom note is not the start of the incident; reconstruct the earlier access and activity from available evidence.
Why this matters for Australian businesses
There is no safe assumption about how long you have before encryption. Monitoring and an agreed escalation route are needed to act on earlier identity, endpoint and backup signals. Do not wait for a ransom note or rely on a generic dwell-time average to plan containment.
The controls that stop lateral spread are the same ones in the ACSC Essential Eight: application control (stops unauthorised tools running), restricting administrative privileges (limits what a compromised account can do), patching operating systems (closes the exploits used for escalation), and multi-factor authentication (slows credential theft). Network segmentation between office IT and any operational technology adds another barrier. Read more in our Essential Eight guide.
Preventing access and limiting damage
Backups need a different trust boundary from production. Separate backup administration, restrict deletion rights, protect a copy with offline storage or an appropriate immutable retention policy, and rehearse restoration in an isolated environment. Include cloud data, application settings and credentials needed for recovery. A green job report does not prove the business can restart. ASD ransomware recovery guidance.
Reduce the damage a single login can cause. Remove unnecessary local administrator rights, separate privileged accounts from daily work, restrict remote access and retire unsupported exposed systems. Test emergency access and the response process without disabling the protections they are meant to support.
Address these control areas together:
ACSC Essential Eight
Application control, patching, Office macro hardening, user app hardening, admin restriction, OS patching, MFA, regular backups. See our full guide.
Read the guideIdentity and MFA
Phishing-resistant MFA for privileged accounts. Conditional Access. Disable legacy auth. Strong offboarding.
Read the guideEmail and web filtering
Configure malicious-link, attachment and impersonation protection. Enforce aligned email authentication and verify sensitive transactions through an independent channel.
Read the guideEndpoint protection
EDR not just antivirus. Microsoft Defender, Huntress, SentinelOne, CrowdStrike. Detection over blocking.
Read the guideDetecting suspicious activity early
Ransom notes and renamed files are late indicators. Earlier signals include backup deletion attempts, new remote-management tools, unusual privileged logins, disabled security agents and unexpected bulk exports. Correlate endpoint, identity, network and backup activity. Some tools are legitimate in normal administration, so the important evidence is an unusual user, time, destination or volume.
Define who receives the alert, who can isolate a device and how escalation works outside normal hours. Check that responders can still communicate if company email is compromised. Test a phone tree and keep the incident contacts available outside the affected systems.
First 24 hours: containment and reporting
Containment takes priority over a rigid clock. For a managed business network, CISA recommends disconnecting affected hosts or taking affected network segments offline. Power down if network isolation cannot be achieved; doing so loses volatile evidence. ASD public guidance also recommends shutdown to stop spread. Follow your responder-led plan rather than an unconditional rule to always shut down or never shut down. CISA business ransomware response checklist.
Use a clean phone or separate communication channel to coordinate. Name an incident lead, keep a timestamped decision log and preserve available identity, endpoint, firewall and backup logs. Do not wipe devices or reconnect backup storage before responders have agreed the evidence and containment steps. Check safety and service dependencies before isolating clinical, industrial or other critical systems.
Mandatory ransomware payment reporting commenced on 30 May 2025. Captured businesses and relevant critical-infrastructure entities must report within 72 hours of making a payment or becoming aware of one made on their behalf. Home Affairs specifies an AUD 3 million turnover threshold, with special rules for part-year businesses. A demand without a payment does not itself trigger this payment-reporting duty; other incident-reporting duties may still apply. Home Affairs payment-reporting factsheet.
Use this priority sequence without waiting for a particular hour. Review payment-reporting details in our Australian ransomware payment guide.
First
Isolate
Disconnect affected hosts or network segments. If isolation cannot be achieved, power down to stop spread, recognising the loss of volatile evidence. Follow the response lead.
In parallel
Record
Capture ransom notes, affected systems, timestamps and actions without delaying containment. Preserve available logs and avoid wiping devices.
Next
Protect recovery
Isolate backup access and protect clean recovery copies. Consider safety and service dependencies before disconnecting shared infrastructure.
Immediately
Notify
Contact the response provider, insurer, incident lead and legal adviser through a trusted channel outside compromised email.
Then
Assess
Establish the affected systems, identity exposure, possible data theft and usable recovery points. Do not assume encryption is the only impact.
Promptly
Escalate
Contact the Australian Cyber Security Hotline on 1300 292 371 and submit a ReportCyber report. Do not wait three hours to ask for help.
Ongoing
Communicate
Coordinate accurate updates and applicable notifications with legal and the incident lead. Keep a record of decisions and reporting deadlines.
Recovery: returning to business safely
Build a recovery order around business dependencies: identity and network services, core applications, data, then user access. Restore into a controlled environment from a recovery point validated against the intrusion timeline. Test logins, application transactions, file integrity and integrations before reconnecting users. Record actual restoration times against your agreed recovery objectives.
For organisations covered by the Privacy Act, the NDB scheme requires a prompt assessment of suspected eligible data breaches. Take all reasonable steps to finish that assessment within 30 days. Once there are reasonable grounds to believe an eligible breach occurred, notify the OAIC and affected individuals as soon as practicable. The assessment period is not permission to wait 30 days before notifying. Seek legal advice on your circumstances. OAIC data breach assessment and notification guidance.
Verify backup integrity
Validate the chosen recovery point against the intrusion timeline and test application data in an isolated environment before restoring widely.
Investigate the incident
Determine the entry route, affected identities, possible data theft and persistence. Preserve agreed evidence before rebuilding.
Rebuild affected systems safely
Use trusted images or a responder-approved recovery method. Do not reconnect recovered data to infrastructure that remains compromised.
Revoke and rotate access
Revoke compromised sessions and grants, then rotate affected account credentials and keys in a dependency-aware order.
Notify where required
Assess personal-information exposure promptly. Where the NDB scheme applies and an eligible breach is established, notify the OAIC and affected people as soon as practicable.
Post-incident hardening
Close the entry route before treating the recovery as complete. Revoke compromised sessions and tokens, remove unauthorised application grants, check new accounts and persistence, and rotate affected credentials in a planned order. Keep heightened monitoring after restoration. Assign each finding an owner, due date and evidence of completion rather than purchasing another tool without changing the exposed process.
Phishing-resistant MFA
Hardware keys or passkeys for admins. No more SMS.
An evidenced maturity target
Agree the target using business risk and scope. Track all eight strategies and their approved exceptions, rather than assuming every business needs ML3.
Immutable backups
If they were not immutable before, they must be now.
Staff training
Quarterly phishing simulations. Report-a-phish culture.
24/7 monitoring
MDR or SOC-as-a-service. Someone watching when you are not.
Tested IR plan
Runbook. Rehearsed annually. Board-level tabletop exercises.
Common mistakes
Confirm insurer notification requirements and approved response providers before an incident. Policy conditions vary, so do not rely on a generic 24-hour or 72-hour insurance deadline. Likewise, a ransom payment report is not a substitute for notifying customers, regulators or contractual partners where separate obligations apply.
Paying the ransom
No guarantee of recovery, funds further attacks, marks you as a paying target.
Restoring before forensics
You rebuild straight back into a compromised environment. Attackers return in days.
Only restoring files, not rebuilding systems
Persistence mechanisms survive in the OS, scheduled tasks, and service accounts.
Not engaging insurance early
Check your policy-specific notification conditions and approved response providers. Late notice can affect a claim, but requirements vary.
Communicating before legal review
Wrong messaging triggers regulatory, customer, and media problems that outlast the incident.
Common questions
Should we pay a ransomware demand?
Do working backups solve a ransomware incident?
Should I turn off a computer affected by ransomware?
When must an Australian business report a ransomware payment?
Do we have 30 days to notify the OAIC?
What reduces ransomware risk for a small business?
Active Incident? Call Now
We provide 24/7 incident response, containment, forensics, and recovery. We also harden your environment so it does not happen again.

Remote Support