Ransomware is malicious software that encrypts your business files and demands a ransom payment in exchange for the decryption key. You cannot open your documents, access your systems, or serve your customers until you either pay the attackers or restore from backups. It is one of the most disruptive cyber threats facing Australian businesses today, and it does not discriminate by size or industry.
This guide covers what ransomware actually is, how it gets into a business, what happens during an attack, and the practical steps that protect you. If you want to understand your risk and do something about it, this is where to start. You can also read our overview of what a cyber attack is and how it affects Australian businesses for broader context.
How Ransomware Gets Into Your Business
Ransomware does not appear out of nowhere. Attackers need a way in. These are the four most common entry points.
Phishing Emails
A staff member receives an email that looks legitimate, maybe a fake invoice, a delivery notification, or a message from a supplier. They click a link or open an attachment, and malware is silently installed on their machine. Phishing remains the number one delivery method for ransomware globally, and the emails have become significantly harder to identify.
Remote Desktop Protocol (RDP) Vulnerabilities
RDP allows staff to connect to office systems remotely. When RDP is exposed to the internet with weak credentials or without multi-factor authentication, attackers can brute-force their way in. This is a particularly common entry point for small and mid-sized businesses.
Compromised Credentials
Staff reuse passwords across personal and work accounts. When a personal account is breached in an unrelated data leak, those credentials are sold on the dark web and tested against business systems. If your staff member used the same password for their email and a compromised gaming site, your business may already be exposed.
Unpatched Software Vulnerabilities
Outdated software contains known security flaws. Attackers actively scan the internet for businesses running vulnerable versions of operating systems, firewalls, and applications. Failing to apply patches promptly gives attackers an open window.
What Actually Happens During a Ransomware Attack
Understanding the attack timeline matters because most of the damage happens before anyone notices anything is wrong.
Initial Access (Day 0)
The attacker gets a foothold inside your network. This could be through a phishing link clicked at 9am on a Tuesday, an RDP brute-force that succeeded over the weekend, or credentials purchased from another breach.
Reconnaissance and Lateral Movement (Days 1 to 14)
Modern ransomware attacks are not automated smash-and-grab jobs. Attackers spend days or weeks quietly moving through your network, mapping your systems, identifying your backups, and escalating their privileges. You will likely see nothing unusual during this phase.
Backup Deletion and Staging (Hours Before)
Before encrypting anything, attackers often delete or corrupt your backups. They also identify your most critical systems and stage the ransomware for simultaneous deployment across multiple machines.
Encryption and Ransom Demand (The Moment of Impact)
Files across your network are encrypted simultaneously. Staff arrive at work or return from lunch to find they cannot open anything. A ransom note appears on screens with payment instructions and a countdown timer. The demand is usually in cryptocurrency and ranges from thousands to millions of dollars.
At this point, your options depend entirely on what you had in place before the attack began.
Should You Pay the Ransom?
The short answer is no. Here is why that answer matters.
The Australian Cyber Security Centre (ACSC) advises businesses not to pay ransoms. Paying does not guarantee you will get your files back. In many cases, decryption tools provided by attackers are incomplete or broken. Paying also marks your business as a willing payer, which increases the likelihood of a follow-up attack. Beyond that, ransomware groups are often criminal organisations or state-sponsored actors. Payment funds further attacks on other Australian businesses.
If you have tested, isolated backups, a payment decision should not even be a conversation. Restore your systems and report the incident to the ACSC at cyber.gov.au/report. If you do not have adequate backups, that is the gap to fix now, not during an incident.
Real Australian Ransomware Incidents
Ransomware is not a theoretical risk for Australian businesses. These publicly reported cases demonstrate the real-world impact.
Medibank Private (2022): Attackers accessed sensitive health data belonging to millions of Australians after compromising credentials. The attackers demanded a ransom payment. Medibank refused to pay. Data was subsequently published online. The incident resulted in significant regulatory scrutiny and remediation costs.
Toll Group (2020): The transport and logistics company was hit by ransomware twice within three months. The attacks disrupted freight tracking systems and customer-facing operations across multiple business units. The incidents highlighted the risk of operational technology being connected to business networks.
Eastern Health (2021): Four Melbourne hospitals operated by Eastern Health were forced to postpone elective surgeries after a ransomware attack took down clinical systems. Staff reverted to manual processes while IT teams worked to restore systems. The impact on patient care was direct and measurable.
These are not isolated events. The ACSC’s Annual Cyber Threat Report consistently identifies ransomware as one of the most significant threats to Australian organisations across all sectors.
The 5 Controls That Actually Protect Against Ransomware
There is no single tool that eliminates ransomware risk. What works is layering these five controls so that attackers face multiple barriers at every stage of an attack.
1. Multi-Factor Authentication (MFA)
MFA requires a second verification step beyond a password. Even if an attacker has your staff member’s credentials, they cannot access your systems without that second factor. Enable MFA on email, remote access, cloud platforms, and any internet-facing system. This single control stops the majority of credential-based attacks.
2. Patch Management
Apply security patches promptly, particularly for operating systems, browsers, and any software exposed to the internet. Attackers actively exploit known vulnerabilities. A patched system removes those opportunities. The Essential Eight framework lists patching as a core mitigation strategy for exactly this reason.
3. Tested, Isolated Backups
Backups are your recovery option when everything else fails. However, backups connected to your live network can be encrypted or deleted by attackers before they deploy ransomware. Your backups need to be isolated, ideally offline or in immutable cloud storage, and tested regularly. If you have never practised restoring from a backup, you do not actually have a backup strategy.
4. Endpoint Detection and Response (EDR)
EDR software monitors devices for suspicious behaviour patterns rather than just known malware signatures. When ransomware begins encrypting files or an attacker starts moving laterally through your network, EDR can detect and respond to those behaviours before the damage escalates. This is significantly more effective than traditional antivirus alone.
5. Network Segmentation
Segmentation divides your network into separate zones so that if one area is compromised, attackers cannot freely move across everything else. Your finance systems, operational systems, and guest Wi-Fi should not all sit on the same flat network. Segmentation limits the blast radius of any breach.
What to Do in the First 60 Minutes If You Are Hit
Speed matters, but panic makes things worse. Follow this sequence.
Minutes 0 to 10 – Isolate: Disconnect affected machines from the network immediately. Unplug the ethernet cable or disable Wi-Fi. Do not turn machines off, as forensic evidence may be needed. Isolate, do not destroy.
Minutes 10 to 20 – Escalate: Contact your IT team or managed service provider immediately. If you have a cyber incident response retainer, activate it now. Do not attempt to resolve this internally without expertise.
Minutes 20 to 40 – Assess: Determine which systems are affected and which are not. Identify whether backups are intact and isolated. Do not pay any ransom demand without taking legal and expert advice.
Minutes 40 to 60 – Report: Report the incident to the ACSC at cyber.gov.au/report. If personal data has been compromised, you may have notification obligations under the Privacy Act. Your legal and compliance team needs to be across this from the start.
If you want experienced support available before an incident happens, our managed cybersecurity services include incident response planning and 24/7 monitoring.
The Role of Cyber Insurance
Cyber insurance can cover costs associated with ransomware incidents, including forensic investigation, business interruption, legal fees, and notification costs. It is a legitimate risk management tool, and many Australian businesses are now required to carry it by clients or regulators.
However, cyber insurance is not a substitute for prevention. Insurers are increasingly requiring businesses to demonstrate baseline security controls before a policy is issued or before a claim is paid. If you do not have MFA in place and you suffer a ransomware attack, your insurer may dispute the claim. Read your policy carefully, and do not assume coverage means you are protected.
How Microsoft Copilot Helps During and After a Ransomware Incident
Microsoft Copilot is not a ransomware prevention tool. However, it plays a practical role in incident response for businesses already using Microsoft 365.
During a ransomware incident, clear communication is critical and difficult. Staff are stressed, leadership wants answers, and customers or partners may need to be notified. Copilot can help your team quickly draft stakeholder communications, summarise what happened for leadership briefings, and document the incident timeline in real time. When you are managing a crisis, having a tool that removes the blank-page problem for written communications has genuine operational value.
After an incident, Copilot can help compile the incident report, identify gaps in your response process, and draft updated policies or staff communications.
Frequently Asked Questions
Is ransomware only a problem for large businesses?
No. Smaller businesses are frequently targeted because they are less likely to have strong security controls in place. Attackers use automated tools to find and exploit vulnerable systems at scale, regardless of the organisation’s size.
How long does it take to recover from a ransomware attack?
Recovery time depends on how well-prepared you are. Businesses with tested, isolated backups and a rehearsed incident response plan can restore operations within days. Businesses without those controls may face weeks or months of disruption, or may never fully recover some data.
What is the most important thing I can do right now?
Enable multi-factor authentication across your key systems today. It is the single highest-impact control you can implement immediately, and it stops the majority of ransomware attacks before they start.
Does paying the ransom mean I get my files back?
Not necessarily. Decryption tools provided by attackers are often incomplete or unreliable. The ACSC advises against paying ransoms, and payment does not guarantee recovery. Your best path to recovery is always through clean, tested backups.
What should I look for in a cybersecurity provider?
Look for a provider who offers 24/7 monitoring, incident response capability, and practical experience with Australian compliance requirements including the Essential Eight. They should be able to demonstrate how they would respond to a ransomware incident on your behalf, not just describe their technology stack.
Next Steps
Ransomware is a manageable risk with the right preparation in place. The businesses that recover quickly are the ones who built their defences before the attack, not during it.
If you want to understand where your business stands and what gaps exist in your current security posture, we can help. Book a security assessment with our team and get a clear picture of your exposure and your options.
managed it support articles
Related Blog Articles
Discover more insights to optimise your business with the latest IT trends and best practices. Stay ahead of the curve by learning how to leverage cutting-edge technology for success. Explore expert advice and valuable guidance to navigate the evolving world of IT solutions