Ransomware locks your files and systems and demands payment to release them. Increasingly, attackers also copy your data first and threaten to publish it. This guide explains how ransomware gets into small and medium businesses, the controls that stop it, what to do in the first hour and what Australian law now asks you to report.
The short answer
Most ransomware gets in through a stolen password, a phishing email or a system that was not patched. Multi-factor authentication, prompt patching, endpoint detection watched 24/7 and backups that cannot be deleted stop the large majority of attacks, and protected backups are what let you recover without paying.
How big the problem is
In its Annual Cyber Threat Report 2024 to 25, ASD reported that 11% of the cyber security incidents it responded to involved ransomware, 138 incidents in the year, and that ransomware incidents against the healthcare sector doubled. The average self reported cost of cybercrime to a small business was $56,600, up 14%, and $97,200 for a medium business, up 55%, according to ASD’s business fact sheet. Ransomware is only part of that figure, but it is the part most likely to stop a business completely.
How ransomware gets in
- Stolen or guessed passwords on Microsoft 365, remote desktop or a VPN without multi-factor authentication.
- Phishing emails that trick someone into entering their password on a fake sign in page or opening a malicious file.
- Unpatched systems facing the internet, such as firewalls, VPNs and remote access servers with known weaknesses.
- Suppliers with remote access to your systems, whose own accounts are taken over.
Once inside, attackers usually spend days or weeks looking around: finding admin accounts, copying data and looking for backups to delete. That delay is the opportunity to catch them.
The controls that stop it
| Control | What it stops | Essential Eight strategy |
|---|---|---|
| Multi-factor authentication on email, remote access and admin accounts | Stolen passwords | Multi-factor authentication |
| Patching internet facing systems within days, and everything else within weeks | Known weaknesses | Patch applications and operating systems |
| Separate admin accounts that cannot read email or browse | Attackers taking over admin rights | Restrict administrative privileges |
| Application control and macro blocking | Malicious programs and documents | Application control, Office macros |
| Backups that cannot be changed or deleted, tested every quarter | Losing everything, and pressure to pay | Regular backups |
| Endpoint detection and response watched 24/7 | Attackers using legitimate tools after hours | Beyond the Essential Eight, and the control that catches what gets past it |
| Security awareness training and phishing tests | The click that starts the attack | Supports all of them |
ASD says the Essential Eight can prevent the majority of the incidents reported to it. Our Essential Eight checklist shows where you stand, and our guides on multi-factor authentication and patch management go deeper on the two controls that matter most.
Why backups decide the outcome
A business with recent, tested backups that the attacker could not reach can restore and carry on. A business without them is left choosing between weeks of rebuilding and a payment that may not work. Ransomware now looks for backups first, so at least one copy must be offline or immutable, locked against deletion for a set period. See our data backup and disaster recovery guide.
The first hour of an attack
- Disconnect affected computers from the network, by unplugging the cable or turning off Wi-Fi. Do not wipe or rebuild anything yet, because the evidence matters.
- Call your IT provider or an incident response team. The sooner they start, the more they can contain.
- Do not reply to the attacker or pay. ASD’s {ext(PLAY, ‘ransomware playbook’)} is clear that paying does not guarantee you get your data back.
- Change passwords for email, banking and admin accounts from a device you know is clean.
- Call your cyber insurer early. Many policies require you to use their response team.
- Record what you saw and when, including the ransom note.
If you are not a client and need help now, see cyber incident response.
What you must report
- Ransom payments. Since 30 May 2025, businesses with an annual turnover of $3 million or more must report a ransomware or extortion payment to ASD within 72 hours of making it. See our explainer on the ransom payment 72 hour rule.
- Personal information. If personal information may have been exposed, the Notifiable Data Breaches scheme requires you to assess the breach within 30 days and, if it is likely to cause serious harm, notify the OAIC and the people affected as soon as practicable.
- ReportCyber. Reporting every incident to ASD through ReportCyber is recommended and helps others.
Where Austin Technology fits
Every SecureShield plan includes endpoint detection and response watched by a 24/7 security operations centre, and our managed plans cover patching, multi-factor authentication, protected backups and restore testing. See managed security services, or call us on 1300 787 429.
Ransomware questions
Should we pay a ransom?
The Australian Government strongly discourages it. Paying does not guarantee you get your data back or that it will not be leaked, it funds further attacks and it may breach sanctions law. Get incident response help and legal advice before any decision.
Do we have to report a ransomware attack?
If your business turns over $3 million or more and makes a ransomware or extortion payment, it must be reported to ASD within 72 hours of the payment. If personal information may have been exposed, the Notifiable Data Breaches scheme requires you to assess the breach within 30 days and, if it is eligible, notify the OAIC and the people affected as soon as practicable. Reporting to ReportCyber is recommended in every case.
Are small businesses really targeted?
Yes. Most ransomware is not aimed at a particular business. Attackers scan for any system with a known weakness or buy stolen passwords in bulk, so small businesses are hit because they are easier to get into, not because anyone chose them.
Will antivirus stop ransomware?
Traditional antivirus stops known malicious files. Modern ransomware attacks often use stolen accounts and legitimate admin tools, which antivirus does not flag. Endpoint detection and response, watched by people 24/7, is what catches that behaviour.
Does cyber insurance cover ransomware?
Many policies do, but most now require controls such as multi-factor authentication, protected backups and endpoint detection before they will pay. Check the conditions and the first steps your insurer expects you to take.
How quickly can a business recover?
With protected backups and a tested plan, most systems can be back within a day or two. Without them, recovery can take weeks and some data may be lost for good.


