When Ransomware Hits, the Slowest System is Usually the Org Chart

Why decision-readiness belongs alongside controls in every Australian organisation’s security posture

What Australia’s Latest Data Actually Shows

Australia’s 2024–25 cyber data points to a familiar but uncomfortable pattern: more reported cybercrime, more incident response activity, and more cases where ASD’s ACSC detected threats before the affected organisation did. ASD recorded more than 84,700 cybercrime reports, roughly one every six minutes, and responded to more than 1,200 cyber security incidents, an 11 per cent increase. Proactive notifications to organisations about potentially malicious cyber activity also rose sharply, up 83 per cent.

The ransomware figures should sit uncomfortably with security leaders: in 39 per cent of incidents, the affected organisation learned of the breach from the ACSC, not from their own monitoring. For more than one in three victims, external detection came first.

Financial exposure is significant and likely understated. Average self-reported cybercrime costs for Australian businesses rose 50 per cent to $80,850, with large organisations averaging $202,700, up 219 per cent, even as they filed fewer reports. ASD has also noted the broader problem of under-reporting, which means reported loss figures should be read as a partial view rather than the full economic impact.

Healthcare remains a useful warning for other sectors. Sophos’ 2025 healthcare ransomware research found that while encryption rates had fallen, recovery still carried material cost and operational impact. Its broader 2025 ransomware research also put average recovery costs at around US$1.53 million, excluding any ransom payment.

Prevention Still Matters. It Is Not the Whole Answer

Strong identity management, patching, network segmentation and active monitoring all lower the probability of an intrusion becoming a crisis, and prevention is still where the bulk of spending belongs. But Business Aspect Principal Consultant, Shaun Moran believes prevention only reduces probability; it does not eliminate it.

Sophos’ 2025 research found that compromised credentials were a common initial access method in data-encryption incidents: valid accounts used to log in, rather than vulnerabilities that needed to be exploited. That matters because an adversary with patience and a harvested credential set can sometimes move around controls that were designed to stop a different kind of attack. The practical lesson is not to assume compromise is inevitable, but to plan for the possibility. In Moran’s experience working with customers on their incident response capabilities, organisations that have already worked through what they would do tend to respond better when an incident moves from theoretical to real.

The Decisions That Often Slow the Response

In many ransomware incidents, the delay is not purely technical. It comes from uncertainty about who is authorised to make decisions quickly enough.

In the first hours, the questions that shape the outcome are often about authority, risk and timing. Who can authorise taking a core platform offline if that disrupts operations? Who can approve emergency spend on external responders before normal procurement catches up? Who decides whether to communicate with the threat actor? Who signs the notification to ASD, OAIC or another regulator, and on what advice? If a payment is being considered, who owns that decision and who briefs the board?

In many organisations, those authorities are assumed rather than written down. The right person may be unavailable, the backup delegate may be unclear, or the team may not know which decisions require legal, executive, insurer or board input before action can be taken.

It is also worth remembering what kind of failure traditional disaster recovery planning protects against. Business continuity and DR frameworks are usually built for a random, non-adversarial event: a flood, a hardware failure, a power outage. Ransomware is different in a meaningful way. The attacker has often been inside the environment for days, understands the organisation’s schedule and dependencies, and chooses the moment to trigger encryption deliberately. Recovery time objectives were modelled against accidents. They behave differently against an opponent who picked the date.

The Regulatory Clock That is Already Ticking

Australia has now put a hard deadline on one of these decisions.

Under the Cyber Security Act 2024, since 30 May 2025, businesses with annual turnover above $3 million and critical infrastructure entities must report a ransomware payment to the Australian Signals Directorate within 72 hours of making it, or of becoming aware that a payment has been made on their behalf. There is no grace period.

Civil penalties for non-compliance are currently set at up to $19,800, a figure that is deliberately modest. The government has kept penalties low to encourage reporting rather than deter it, prioritising visibility into ransomware payments over punishment. For most organisations, the more meaningful consequence of a missed report is reputational: the exposure that comes from a compliance failure becoming known to customers, regulators, and the market can dwarf the financial penalty itself.

The 72-hour window does not start when the systems are restored. It starts at the moment of payment. That means the question of whether to pay, who authorises it, how it is structured, and who files the report, must be pre-agreed and immediately actionable, not worked out in the middle of a response that is already underway.

What Decision-readiness Looks Like in Practice

Moran suggests decision-readiness means doing the pre-work: assigning clear authority for the decisions that must be made under pressure, before the incident happens rather than during it. The matrix below maps seven decisions that tend to matter most in the first hours of a ransomware event:

DecisionTypical ownerWhy it needs to be agreed early
Take systems or services offlineCIO / technology executive, with business owner inputMay reduce spread but can interrupt critical operations and revenue.
Engage external incident respondersCISO / CIO, procurement and legal supportDelays can cost hours while contracts, scope and authority are resolved.
Notify ASD, OAIC, sector regulators or customersLegal, privacy, communications and executive sponsorRegulatory timeframes and public messaging need to be coordinated.
Communicate with the threat actorExecutive crisis team, legal adviser and insurer where applicableEngagement can affect legal, operational, insurance and reputational risk.
Consider or reject paymentCEO / board delegate, with legal, finance and insurer adviceThe decision may trigger mandatory reporting and wider governance scrutiny.
Restore from backups or rebuildTechnology recovery lead and business continuity leadRecovery choices affect downtime, evidence preservation and confidence in restored systems.
Brief the board and external stakeholdersCEO / executive sponsor and communications leadLeaders need a clear, current view of impact, decisions made and next steps.

The matrix is not a document to write once and file. It becomes useful only when the people in those roles have tested it together, under some realistic time pressure. Otherwise, the gaps tend to appear when they are hardest to fix: systems down, customers asking questions, and the response team already stretched.

Where to Start

Decision-readiness does not require a large program to get moving. It requires a defined starting point: understanding which of these calls have an agreed owner, which do not, and what a realistic response looks like when the people who would actually run it are in the room together.

A structured readiness assessment is usually the right first step. It maps current authority and response capability against what a real ransomware incident would demand. From there, a tested incident response plan and at least one facilitated first-hour exercise give an organisation something a written policy alone cannot: confidence that the plan works with real people, under real pressure, before the day they need it.

Prevention reduces the chance of an incident. Clear authority, tested escalation paths and rehearsed decisions determine how well the organisation responds when prevention is not enough.

If you are unsure how your organisation would respond in the first hours or days of a ransomware incident, Business Aspect can help assess your current ransomware readiness, identify practical gaps in decision-making and response capability, and support a clear path to improved resilience.

Sources

About the Author

Shaun is a Principal Consultant and trusted advisor with a 36-year track record of delivering results through strategic planning, digital/business transformation, and cybersecurity. He has held senior roles within both the Business and IT Delivery side, with real-life practical experience in technical, governance, risk, and executive leadership.