Why decision-readiness belongs alongside controls in every Australian organisation’s security posture
What Australia’s Latest Data Actually Shows
Australia’s 2024–25 cyber data points to a familiar but uncomfortable pattern: more reported cybercrime, more incident response activity, and more cases where ASD’s ACSC detected threats before the affected organisation did. ASD recorded more than 84,700 cybercrime reports, roughly one every six minutes, and responded to more than 1,200 cyber security incidents, an 11 per cent increase. Proactive notifications to organisations about potentially malicious cyber activity also rose sharply, up 83 per cent.
The ransomware figures should sit uncomfortably with security leaders: in 39 per cent of incidents, the affected organisation learned of the breach from the ACSC, not from their own monitoring. For more than one in three victims, external detection came first.
Financial exposure is significant and likely understated. Average self-reported cybercrime costs for Australian businesses rose 50 per cent to $80,850, with large organisations averaging $202,700, up 219 per cent, even as they filed fewer reports. ASD has also noted the broader problem of under-reporting, which means reported loss figures should be read as a partial view rather than the full economic impact.
Healthcare remains a useful warning for other sectors. Sophos’ 2025 healthcare ransomware research found that while encryption rates had fallen, recovery still carried material cost and operational impact. Its broader 2025 ransomware research also put average recovery costs at around US$1.53 million, excluding any ransom payment.
Prevention Still Matters. It Is Not the Whole Answer
Strong identity management, patching, network segmentation and active monitoring all lower the probability of an intrusion becoming a crisis, and prevention is still where the bulk of spending belongs. But Business Aspect Principal Consultant, Shaun Moran believes prevention only reduces probability; it does not eliminate it.
Sophos’ 2025 research found that compromised credentials were a common initial access method in data-encryption incidents: valid accounts used to log in, rather than vulnerabilities that needed to be exploited. That matters because an adversary with patience and a harvested credential set can sometimes move around controls that were designed to stop a different kind of attack. The practical lesson is not to assume compromise is inevitable, but to plan for the possibility. In Moran’s experience working with customers on their incident response capabilities, organisations that have already worked through what they would do tend to respond better when an incident moves from theoretical to real.
The Decisions That Often Slow the Response
In many ransomware incidents, the delay is not purely technical. It comes from uncertainty about who is authorised to make decisions quickly enough.
In the first hours, the questions that shape the outcome are often about authority, risk and timing. Who can authorise taking a core platform offline if that disrupts operations? Who can approve emergency spend on external responders before normal procurement catches up? Who decides whether to communicate with the threat actor? Who signs the notification to ASD, OAIC or another regulator, and on what advice? If a payment is being considered, who owns that decision and who briefs the board?

In many organisations, those authorities are assumed rather than written down. The right person may be unavailable, the backup delegate may be unclear, or the team may not know which decisions require legal, executive, insurer or board input before action can be taken.
It is also worth remembering what kind of failure traditional disaster recovery planning protects against. Business continuity and DR frameworks are usually built for a random, non-adversarial event: a flood, a hardware failure, a power outage. Ransomware is different in a meaningful way. The attacker has often been inside the environment for days, understands the organisation’s schedule and dependencies, and chooses the moment to trigger encryption deliberately. Recovery time objectives were modelled against accidents. They behave differently against an opponent who picked the date.
The Regulatory Clock That is Already Ticking

Australia has now put a hard deadline on one of these decisions.
Under the Cyber Security Act 2024, since 30 May 2025, businesses with annual turnover above $3 million and critical infrastructure entities must report a ransomware payment to the Australian Signals Directorate within 72 hours of making it, or of becoming aware that a payment has been made on their behalf. There is no grace period.
Civil penalties for non-compliance are currently set at up to $19,800, a figure that is deliberately modest. The government has kept penalties low to encourage reporting rather than deter it, prioritising visibility into ransomware payments over punishment. For most organisations, the more meaningful consequence of a missed report is reputational: the exposure that comes from a compliance failure becoming known to customers, regulators, and the market can dwarf the financial penalty itself.
The 72-hour window does not start when the systems are restored. It starts at the moment of payment. That means the question of whether to pay, who authorises it, how it is structured, and who files the report, must be pre-agreed and immediately actionable, not worked out in the middle of a response that is already underway.
What Decision-readiness Looks Like in Practice
Moran suggests decision-readiness means doing the pre-work: assigning clear authority for the decisions that must be made under pressure, before the incident happens rather than during it. The matrix below maps seven decisions that tend to matter most in the first hours of a ransomware event:
| Decision | Typical owner | Why it needs to be agreed early |
| Take systems or services offline | CIO / technology executive, with business owner input | May reduce spread but can interrupt critical operations and revenue. |
| Engage external incident responders | CISO / CIO, procurement and legal support | Delays can cost hours while contracts, scope and authority are resolved. |
| Notify ASD, OAIC, sector regulators or customers | Legal, privacy, communications and executive sponsor | Regulatory timeframes and public messaging need to be coordinated. |
| Communicate with the threat actor | Executive crisis team, legal adviser and insurer where applicable | Engagement can affect legal, operational, insurance and reputational risk. |
| Consider or reject payment | CEO / board delegate, with legal, finance and insurer advice | The decision may trigger mandatory reporting and wider governance scrutiny. |
| Restore from backups or rebuild | Technology recovery lead and business continuity lead | Recovery choices affect downtime, evidence preservation and confidence in restored systems. |
| Brief the board and external stakeholders | CEO / executive sponsor and communications lead | Leaders need a clear, current view of impact, decisions made and next steps. |
The matrix is not a document to write once and file. It becomes useful only when the people in those roles have tested it together, under some realistic time pressure. Otherwise, the gaps tend to appear when they are hardest to fix: systems down, customers asking questions, and the response team already stretched.
Where to Start
Decision-readiness does not require a large program to get moving. It requires a defined starting point: understanding which of these calls have an agreed owner, which do not, and what a realistic response looks like when the people who would actually run it are in the room together.
A structured readiness assessment is usually the right first step. It maps current authority and response capability against what a real ransomware incident would demand. From there, a tested incident response plan and at least one facilitated first-hour exercise give an organisation something a written policy alone cannot: confidence that the plan works with real people, under real pressure, before the day they need it.
Prevention reduces the chance of an incident. Clear authority, tested escalation paths and rehearsed decisions determine how well the organisation responds when prevention is not enough.
If you are unsure how your organisation would respond in the first hours or days of a ransomware incident, Business Aspect can help assess your current ransomware readiness, identify practical gaps in decision-making and response capability, and support a clear path to improved resilience.
Sources
- ASD Annual Cyber Threat Report 2024–25 (October 2025)
- Department of Home Affairs, Ransomware Payment Reporting Guidance
- Cyber Security Act 2024 (Cth), Part 3
- Sophos, The State of Ransomware 2025 and The State of Ransomware in Healthcare 2025
About the Author
Shaun is a Principal Consultant and trusted advisor with a 36-year track record of delivering results through strategic planning, digital/business transformation, and cybersecurity. He has held senior roles within both the Business and IT Delivery side, with real-life practical experience in technical, governance, risk, and executive leadership.
