All Guides
Crisis Prevention

Ransomware prevention and recovery for Australian businesses

Ransomware can stop operations and expose data even when backups work. This guide covers entry routes, containment, clean recovery and Australian reporting duties, using current research and government guidance.

Last updated 4 October 202618 min read

What is ransomware?

Ransomware encrypts files and demands payment for recovery. Cyber extortion can also involve stolen data and a demand to prevent disclosure, with or without encryption.

In the Sophos 2026 global survey of 2,158 ransomware victims, 56 per cent of attacks encrypted data. Among cases involving encrypted data, 66 per cent used backups to recover. These are survey outcomes, not forecasts for an Australian business. They show that having a backup is only part of recovery: it must be clean, available and usable. Sophos State of Ransomware 2026.

Data theft can create an incident even if nothing is encrypted. An attacker may threaten to publish customer records, payroll or intellectual property. Backups restore availability; they cannot retrieve stolen copies. Investigate confidentiality and access alongside the work needed to restart operations.

ACSC position: do not pay

  • No guarantee files are restored
  • Stolen data often leaked anyway
  • Payment funds further attacks and marks you as a paying target
  • May breach sanctions law depending on the threat group

How attackers get in

In the same Sophos survey, respondents identified malicious email in 26 per cent of incidents, phishing in 24 per cent, compromised credentials in 23 per cent and exploited vulnerabilities in 18 per cent. These are separate reported root causes. Do not treat a global vendor survey as an Australian prevalence figure or assume one entry route explains every incident. Sophos State of Ransomware 2026.

Map the doors into your own environment: mailboxes, remote access, firewall administration, exposed applications, supplier accounts and management tools. Record who owns each service, how it authenticates and how quickly access can be revoked. A protected Microsoft 365 account does not compensate for an unprotected VPN or an abandoned vendor login.

Email and stolen credentials

A malicious attachment, fake sign-in or previously stolen credential can provide access. Cover mailboxes, VPNs and remote administration, not just one cloud service.

Exposed, unpatched services

Inventory internet-facing applications, VPNs and firewalls. Apply vendor mitigations promptly and verify deployment rather than assuming a patch job succeeded.

Remote desktop access

Avoid direct internet exposure. Restrict access through a controlled path with strong authentication, least privilege and monitored logs.

Supplier and management access

Review vendor accounts, remote-management tools and software delivery paths. Time-limit access and remove unused connections.

Internal misuse or excessive access

Limit administrative rights, separate duties and revoke access promptly when staff leave or change roles.

How ransomware spreads through a network

The sequence below is a common investigation pattern, not a mandatory order. A cloud-only business might have no domain controller; stolen SaaS sessions and excessive application permissions may be the main path instead. Watch for unusual use of administrative tools, not just a particular filename. Legitimate remote-management software becomes dangerous when the operator or credentials are compromised.

The initial foothold can let an attacker seek broader access, valuable data and recovery systems. The following stages explain what responders investigate, not a fixed timetable for every incident.

1

Credential theft and harvesting

The attacker may seek saved credentials, browser sessions or credentials held in memory. The result depends on privileges and device protections. Revoke compromised sessions as well as changing passwords.

2

Lateral movement through administration paths

Stolen accounts can be used through RDP, remote execution, WMI or management tools. These tools also have legitimate uses; suspicious context and behaviour are important signals for endpoint and identity monitoring.

3

Privilege escalation

In an Active Directory environment, an attacker may seek domain-level privileges. In cloud environments, privileged roles and application permissions can serve a similar purpose. Investigate elevated access before trusting restored systems.

4

Reconnaissance and target selection

The attacker searches for valuable data, backup platforms, shared storage and connected services. Restrict the reach of ordinary and privileged accounts so one foothold cannot access everything.

5

Backup attacks and data theft

An attacker may attempt to delete recovery copies, disable protection or export sensitive data. Monitor these actions and investigate outbound activity. Offline or correctly configured immutable copies can preserve a recovery option.

6

Encryption or extortion

The final visible action may encrypt multiple systems or demand payment over stolen data alone. A ransom note is not the start of the incident; reconstruct the earlier access and activity from available evidence.

Why this matters for Australian businesses

There is no safe assumption about how long you have before encryption. Monitoring and an agreed escalation route are needed to act on earlier identity, endpoint and backup signals. Do not wait for a ransom note or rely on a generic dwell-time average to plan containment.

The controls that stop lateral spread are the same ones in the ACSC Essential Eight: application control (stops unauthorised tools running), restricting administrative privileges (limits what a compromised account can do), patching operating systems (closes the exploits used for escalation), and multi-factor authentication (slows credential theft). Network segmentation between office IT and any operational technology adds another barrier. Read more in our Essential Eight guide.

Preventing access and limiting damage

Backups need a different trust boundary from production. Separate backup administration, restrict deletion rights, protect a copy with offline storage or an appropriate immutable retention policy, and rehearse restoration in an isolated environment. Include cloud data, application settings and credentials needed for recovery. A green job report does not prove the business can restart. ASD ransomware recovery guidance.

Reduce the damage a single login can cause. Remove unnecessary local administrator rights, separate privileged accounts from daily work, restrict remote access and retire unsupported exposed systems. Test emergency access and the response process without disabling the protections they are meant to support.

Address these control areas together:

ACSC Essential Eight

Application control, patching, Office macro hardening, user app hardening, admin restriction, OS patching, MFA, regular backups. See our full guide.

Read the guide

Identity and MFA

Phishing-resistant MFA for privileged accounts. Conditional Access. Disable legacy auth. Strong offboarding.

Read the guide

Email and web filtering

Configure malicious-link, attachment and impersonation protection. Enforce aligned email authentication and verify sensitive transactions through an independent channel.

Read the guide

Endpoint protection

EDR not just antivirus. Microsoft Defender, Huntress, SentinelOne, CrowdStrike. Detection over blocking.

Read the guide

Detecting suspicious activity early

Ransom notes and renamed files are late indicators. Earlier signals include backup deletion attempts, new remote-management tools, unusual privileged logins, disabled security agents and unexpected bulk exports. Correlate endpoint, identity, network and backup activity. Some tools are legitimate in normal administration, so the important evidence is an unusual user, time, destination or volume.

Define who receives the alert, who can isolate a device and how escalation works outside normal hours. Check that responders can still communicate if company email is compromised. Test a phone tree and keep the incident contacts available outside the affected systems.

Sudden slowness across multiple systems
Files renamed with unusual extensions (.locked, .encrypted, .lockbit)
Ransom notes appearing on screens or file shares
Shared drives or backups inaccessible
Unusual outbound traffic or bandwidth spikes
Mass failed logins in audit logs
New admin accounts created outside business hours
EDR alerts for known ransomware tooling (PsExec, Cobalt Strike, RClone)
Backup jobs failing silently
Unexpected reboots or blue screens across many machines

First 24 hours: containment and reporting

Containment takes priority over a rigid clock. For a managed business network, CISA recommends disconnecting affected hosts or taking affected network segments offline. Power down if network isolation cannot be achieved; doing so loses volatile evidence. ASD public guidance also recommends shutdown to stop spread. Follow your responder-led plan rather than an unconditional rule to always shut down or never shut down. CISA business ransomware response checklist.

Use a clean phone or separate communication channel to coordinate. Name an incident lead, keep a timestamped decision log and preserve available identity, endpoint, firewall and backup logs. Do not wipe devices or reconnect backup storage before responders have agreed the evidence and containment steps. Check safety and service dependencies before isolating clinical, industrial or other critical systems.

Mandatory ransomware payment reporting commenced on 30 May 2025. Captured businesses and relevant critical-infrastructure entities must report within 72 hours of making a payment or becoming aware of one made on their behalf. Home Affairs specifies an AUD 3 million turnover threshold, with special rules for part-year businesses. A demand without a payment does not itself trigger this payment-reporting duty; other incident-reporting duties may still apply. Home Affairs payment-reporting factsheet.

Use this priority sequence without waiting for a particular hour. Review payment-reporting details in our Australian ransomware payment guide.

First

Isolate

Disconnect affected hosts or network segments. If isolation cannot be achieved, power down to stop spread, recognising the loss of volatile evidence. Follow the response lead.

In parallel

Record

Capture ransom notes, affected systems, timestamps and actions without delaying containment. Preserve available logs and avoid wiping devices.

Next

Protect recovery

Isolate backup access and protect clean recovery copies. Consider safety and service dependencies before disconnecting shared infrastructure.

Immediately

Notify

Contact the response provider, insurer, incident lead and legal adviser through a trusted channel outside compromised email.

Then

Assess

Establish the affected systems, identity exposure, possible data theft and usable recovery points. Do not assume encryption is the only impact.

Promptly

Escalate

Contact the Australian Cyber Security Hotline on 1300 292 371 and submit a ReportCyber report. Do not wait three hours to ask for help.

Ongoing

Communicate

Coordinate accurate updates and applicable notifications with legal and the incident lead. Keep a record of decisions and reporting deadlines.

Recovery: returning to business safely

Build a recovery order around business dependencies: identity and network services, core applications, data, then user access. Restore into a controlled environment from a recovery point validated against the intrusion timeline. Test logins, application transactions, file integrity and integrations before reconnecting users. Record actual restoration times against your agreed recovery objectives.

For organisations covered by the Privacy Act, the NDB scheme requires a prompt assessment of suspected eligible data breaches. Take all reasonable steps to finish that assessment within 30 days. Once there are reasonable grounds to believe an eligible breach occurred, notify the OAIC and affected individuals as soon as practicable. The assessment period is not permission to wait 30 days before notifying. Seek legal advice on your circumstances. OAIC data breach assessment and notification guidance.

Verify backup integrity

Validate the chosen recovery point against the intrusion timeline and test application data in an isolated environment before restoring widely.

Investigate the incident

Determine the entry route, affected identities, possible data theft and persistence. Preserve agreed evidence before rebuilding.

Rebuild affected systems safely

Use trusted images or a responder-approved recovery method. Do not reconnect recovered data to infrastructure that remains compromised.

Revoke and rotate access

Revoke compromised sessions and grants, then rotate affected account credentials and keys in a dependency-aware order.

Notify where required

Assess personal-information exposure promptly. Where the NDB scheme applies and an eligible breach is established, notify the OAIC and affected people as soon as practicable.

Post-incident hardening

Close the entry route before treating the recovery as complete. Revoke compromised sessions and tokens, remove unauthorised application grants, check new accounts and persistence, and rotate affected credentials in a planned order. Keep heightened monitoring after restoration. Assign each finding an owner, due date and evidence of completion rather than purchasing another tool without changing the exposed process.

Phishing-resistant MFA

Hardware keys or passkeys for admins. No more SMS.

An evidenced maturity target

Agree the target using business risk and scope. Track all eight strategies and their approved exceptions, rather than assuming every business needs ML3.

Immutable backups

If they were not immutable before, they must be now.

Staff training

Quarterly phishing simulations. Report-a-phish culture.

24/7 monitoring

MDR or SOC-as-a-service. Someone watching when you are not.

Tested IR plan

Runbook. Rehearsed annually. Board-level tabletop exercises.

Common mistakes

Confirm insurer notification requirements and approved response providers before an incident. Policy conditions vary, so do not rely on a generic 24-hour or 72-hour insurance deadline. Likewise, a ransom payment report is not a substitute for notifying customers, regulators or contractual partners where separate obligations apply.

Paying the ransom

No guarantee of recovery, funds further attacks, marks you as a paying target.

Restoring before forensics

You rebuild straight back into a compromised environment. Attackers return in days.

Only restoring files, not rebuilding systems

Persistence mechanisms survive in the OS, scheduled tasks, and service accounts.

Not engaging insurance early

Check your policy-specific notification conditions and approved response providers. Late notice can affect a claim, but requirements vary.

Communicating before legal review

Wrong messaging triggers regulatory, customer, and media problems that outlast the incident.

Common questions

Should we pay a ransomware demand?
ASD advises against paying because payment does not guarantee recovery or prevent stolen data from being disclosed. Contain the incident, contact your response provider and insurer, and seek legal advice. The Australian Cyber Security Hotline is 1300 292 371.
Do working backups solve a ransomware incident?
Working backups help restore systems but do not undo data theft or remove attacker access. Validate the recovery point, close the entry route and check for persistence before reconnecting restored systems. Assess exposed personal information separately from availability recovery.
Should I turn off a computer affected by ransomware?
Isolate it promptly and follow the incident response plan. CISA business guidance prioritises disconnecting hosts or network segments, with shutdown if isolation is not possible because shutdown loses volatile evidence. ASD public guidance also recommends shutdown to stop spread. A responder should direct the choice in a managed business environment.
When must an Australian business report a ransomware payment?
A captured entity must report within 72 hours of paying or becoming aware of a payment made on its behalf. The regime commenced on 30 May 2025 and uses an AUD 3 million turnover threshold, with specific critical-infrastructure and part-year-business rules. A demand without payment does not trigger this payment-reporting duty.
Do we have 30 days to notify the OAIC?
No. The 30-day period relates to assessing a suspected eligible breach, not a general notification deadline. Covered organisations must take all reasonable steps to assess within that period and notify the OAIC and affected individuals as soon as practicable once an eligible breach is established.
What reduces ransomware risk for a small business?
Combine prompt patching, phishing-resistant authentication, restricted administrative access, monitored endpoints and protected, tested backups. Apply the Essential Eight to the relevant environment and document who responds outside business hours. No single product prevents every ransomware incident.

Active Incident? Call Now

We provide 24/7 incident response, containment, forensics, and recovery. We also harden your environment so it does not happen again.