Ransomware is the attack most likely to put a small business out of action for days or weeks: criminals encrypt your files, then demand payment to unlock them, often threatening to leak the data as well. Smaller organisations are targeted precisely because they tend to have valuable data and thinner defences. The good news is that the measures that stop most ransomware are well-established, affordable, and mapped out for Australian businesses by the Australian Signals Directorate.
Prevention: the controls that stop most attacks
Ransomware almost always gets in through one of a small number of doors — a phishing email, an unpatched internet-facing system, weak or reused credentials, or exposed remote access. The ASD's Essential Eight is the baseline worth working through, because it targets exactly these entry points:
- Multi-factor authentication on email, remote access, and any admin account. This single control blocks the majority of credential-based intrusions.
- Patch operating systems and applications promptly, especially anything exposed to the internet. Attackers scan for known, unpatched vulnerabilities constantly.
- Restrict administrative privileges — day-to-day accounts shouldn't have admin rights, so a compromised login can't do maximum damage.
- Application control and macro settings to stop malicious code executing, since many attacks arrive as booby-trapped Office documents.
- Regular, tested backups kept offline or otherwise isolated from your network.
Backups are the control that most directly determines whether ransomware is a bad day or a business-ending event, so they deserve their own section.
Backups that actually survive an attack
The mistake that turns a recoverable incident into a catastrophe is backups that are reachable from the network the ransomware infects — attackers deliberately hunt for and encrypt backups first. Follow the 3-2-1 principle: three copies of your data, on two different types of media, with one copy kept offsite and offline (or immutable, meaning it can't be altered or deleted for a set period). A backup you've never restored from is a hope, not a plan, so test a restore periodically and confirm it actually works and includes what you need.
Response: the first hour matters most
If you're hit, the instinct is to start deleting or paying. Slow down and work the sequence:
- Isolate affected devices — disconnect them from the network and from each other to stop the spread — but don't wipe or power them off blindly, as that can destroy evidence and recovery options.
- Assess the scope: which systems, which data, and whether it's still spreading.
- Report to the Australian Cyber Security Centre via ReportCyber. If personal information may have been accessed, the Notifiable Data Breaches scheme under the Privacy Act may require you to notify affected people and the OAIC — assess this early.
- Engage help — your IT provider and, for anything serious, an incident-response specialist and your insurer if you hold cyber cover.
On paying the ransom: Australian government guidance strongly discourages it. Payment doesn't guarantee you'll get your data back, marks you as a business willing to pay, and may carry legal risk. It should never be your recovery plan — good backups are.
Recovery and rebuilding safely
Recovery isn't just restoring files; it's making sure the attacker is genuinely gone before you reconnect. That means rebuilding compromised systems from clean images rather than trusting them, resetting credentials across the board, and confirming the entry point is closed before you restore from backup — otherwise you can be re-encrypted within days. Once you're operational, run a short review: how did they get in, what would have stopped it, and which Essential Eight gap does this close?
Make it part of how the business runs
Cybersecurity fails when it's a one-off project rather than a maintained discipline. Patching, backup testing, and access reviews belong on a recurring schedule with someone clearly accountable. If your back office is still held together by one person's memory and a few spreadsheets, that fragility extends to your security posture too — our Operations hub and the modern SME back office guide cover how to build that resilience in.
This is general information. For advice specific to your systems and obligations, consult a qualified IT security provider and refer to the ACSC's current guidance at cyber.gov.au.
About the author
Andrew Northcott
Founder & Chairman, Valont
Andrew is the founder and chairman of Valont and the parent group Wattlestone. He has spent two decades building and running Australian SMEs, and writes about the realities of ownership — cash, people, systems, and the decisions that compound.
LinkedIn →