Ransomware remains the single most disruptive cyber threat facing Australian organisations, and in 2026 it is more industrialised than ever. Ransomware-as-a-service lowers the barrier to entry so that criminals without technical skill can rent everything they need, while AI-assisted phishing and reconnaissance make intrusions faster and more convincing. Double and triple extortion, where attackers steal data and threaten to publish it before they even encrypt anything, means backups alone no longer make you safe. Preparedness, not luck, is what separates a contained incident from a business-ending one.
The good news is that ransomware follows a predictable pattern, and every stage of that pattern is an opportunity to prevent, detect or contain the attack. This guide sets out a proactive approach to ransomware preparedness built for the Australian context, covering the attack lifecycle, prevention, detection, resilient backups, incident response, tabletop testing and how to report readiness to your board.
Understand the Ransomware Attack Lifecycle
You cannot defend against what you do not understand. Modern ransomware is rarely a single event; it is a campaign that unfolds over hours or days, giving prepared defenders multiple chances to intervene.
A typical attack moves through:
- Initial access, often via phishing, stolen credentials, an exposed remote service or a compromised supplier
- Establishing a foothold and quietly escalating privileges
- Lateral movement across the network towards valuable systems and backups
- Data theft for extortion, before any encryption takes place
- Encryption and the ransom demand, usually timed for maximum disruption
Because the earlier stages happen quietly and well before encryption, organisations that can detect lateral movement and privilege escalation often stop an attack before it does real damage. That is why detection and response matters as much as prevention.
Prevention: Get the Foundations Right
Most successful ransomware attacks exploit known, preventable weaknesses. Prioritising fundamentals delivers the greatest return, and for Australian organisations the ASD Essential Eight is the natural baseline.
Focus on:
- Patching internet-facing services and applications promptly, since unpatched systems are a favourite entry point
- Enforcing phishing-resistant multi-factor authentication on all remote access, email and privileged accounts
- Restricting administrative privileges and removing standing local admin rights
- Application control and macro restrictions to stop malicious code executing
- Hardening and monitoring remote access, and retiring exposed legacy services
- Ongoing security awareness so staff can recognise and report phishing
Prevention should be validated, not assumed. Regular penetration testing confirms that the controls you believe are in place actually stop an attacker, and it surfaces the exposed services and misconfigurations that ransomware crews look for first.
Detection: Assume They Will Get In
Given AI-enabled attackers and the sheer volume of ransomware-as-a-service activity, some intrusions will get past prevention. The organisations that avoid catastrophe are the ones that detect the quiet middle stages of an attack.
Effective detection depends on:
- Well-tuned endpoint detection and response across every device, not just servers
- Centralised logging and monitoring that can surface unusual lateral movement, privilege escalation and mass file access
- Alerting on the behaviours that precede encryption, such as attempts to disable security tools or delete backups
- A security operations capability, in-house or managed, that can act on alerts around the clock
Testing detection directly is the best way to trust it. Assumed breach and adversary simulation exercises start from a foothold inside the network and measure exactly how quickly your team spots and contains an intruder following the same path ransomware would take.
Backups and Immutability: Your Last Line of Defence
Backups remain the most important recovery control, but modern ransomware actively hunts for and destroys them before encrypting. A backup an attacker can reach or delete is not a backup you can rely on.
Build resilience with:
- The 3-2-1 principle as a minimum: three copies of data, on two types of media, with one copy offsite
- Immutable or air-gapped copies that cannot be altered or deleted, even with stolen admin credentials
- Backups isolated from production identity, so a domain compromise does not equal a backup compromise
- Regular, tested restores, because a backup you have never restored is only a hope, not a plan
- Documented recovery time and recovery point objectives agreed with the business
Because attackers now steal data before encrypting, backups protect availability but not confidentiality. That makes prevention, detection and data protection equally important alongside your recovery strategy.
Ransomware Incident Response
When an attack lands, the speed and quality of your ransomware incident response determines the outcome. A rehearsed plan turns chaos into a sequence of clear decisions.
Core steps include:
- Contain: isolate affected systems and accounts quickly to stop the spread, without indiscriminately destroying forensic evidence.
- Assess: identify what was accessed, what was encrypted and whether data was exfiltrated, so decisions rest on facts.
- Engage experts: bring in specialist incident response support early to lead investigation, containment and recovery.
- Manage obligations: work with legal counsel on the Notifiable Data Breaches scheme, and note any sector duties under the SOCI Act or APRA CPS 234, including timely reporting to the ACSC.
- Weigh payment carefully: the ACSC and law enforcement advise against paying, since it funds crime and never guarantees recovery. Treat payment as a last resort and a legal decision, not a technical one.
- Recover and learn: restore from clean backups, rebuild affected systems, and run a post-incident review that feeds real improvements back into your defences.
Predefine your escalation paths, contacts and decision-makers now. In a live incident there is no time to work out who has the authority to disconnect a network or approve external help.
Test With Tabletop Exercises
A plan that has never been rehearsed will fail under pressure. Tabletop exercises walk your leadership, technical and communications teams through a realistic ransomware scenario to expose gaps before an attacker does.
Good exercises:
- Involve executives and legal and communications functions, not just IT and security
- Use a realistic scenario, such as double extortion during a busy trading period
- Test the hard decisions, including public communications, customer notification and whether to pay
- Produce a concrete action list with owners and deadlines, and are repeated regularly
Run tabletops at least annually, and refresh them whenever your environment, suppliers or threat profile change.
Report Readiness to the Board
Ransomware is a business risk, so directors need a clear, jargon-free view of preparedness. Board-level reporting turns technical work into governance decisions and, for regulated entities, supports obligations under APRA CPS 234 and the SOCI Act.
Report in terms leadership can act on:
- Maturity against the ASD Essential Eight, with a target level and progress towards it
- Results of the latest testing, including time to detect and time to respond
- Backup and recovery readiness, including the last successful restore test
- Outcomes and actions from the most recent tabletop exercise
- Residual risk in plain language, with the investment needed to reduce it
Ransomware preparedness is not a product you buy once; it is a discipline you sustain across prevention, detection, recovery and rehearsal. Australian organisations that treat it that way recover in hours or days while their unprepared peers lose weeks. StrikeCyber helps organisations across Australia test and strengthen their defences before an attack, and respond decisively when one happens. Call 1300 654 898 or get in touch to build ransomware preparedness that holds up under real pressure.
