Ransomware used to be something we wrote about happening to hospitals, pipeline operators and government departments overseas. In 2026, the businesses actually getting hit in Australia look a lot more familiar: the accounting firm down the road, the regional logistics company, the family-run medical practice, the online retailer running a small warehouse out the back of Melbourne or Brisbane. Small and medium enterprises are now the bulk of ransomware victims in this country, and the gap between “it won’t happen to us” and “it happened to us on a Tuesday morning” has never been thinner.
We’ve covered the broader shift in the top cybersecurity threats facing Australians this year, and ransomware sits right at the pointy end of that list for one simple reason: it’s profitable, it’s largely automated, and small businesses keep making it easy. This piece is about two things. First, why SMEs specifically have become the preferred target rather than an afterthought. Second, and more importantly, exactly what to do in the first 24 hours if it happens to you, because how you respond in that window has more influence over the outcome than almost anything you did beforehand.
Why criminals prefer small businesses
It’s tempting to assume ransomware gangs go after the biggest possible payday, but that’s not how the economics work anymore. Enterprise targets have security operations centres, incident response retainers, network segmentation and staff whose entire job is watching for exactly this kind of intrusion. Attacking one of the big four banks or a state government department is expensive, slow and likely to fail. Attacking a 30-person manufacturing business with a single overworked IT contractor is none of those things.
Small businesses in Australia typically have most or all of the following in place at once: one shared admin password reused across several systems, no multi-factor authentication on remote access tools, unpatched software because “we’ll get to it,” backups that either don’t exist or have never been tested, and no one whose job it is to notice a strange login at 2am. None of that makes an SME’s data less valuable. Customer records, payment details, employee information and supplier contracts are worth exactly as much to a criminal group whether they’re stolen from a multinational or a suburban trades business. The difference is how much resistance they meet on the way in, and for most small businesses right now, the answer is not much.
There’s also a volume play at work. Ransomware-as-a-service means the people actually deploying the malware often aren’t sophisticated hackers at all — they’re affiliates running off-the-shelf toolkits, and their business model depends on hitting a large number of soft targets rather than a small number of hard ones. A lot of that initial access still comes down to old-fashioned social engineering: a convincing phishing email, a fake invoice, or a phone call from someone impersonating IT support. We’ve written before about how these scam calls and impersonation tactics have evolved, and the same techniques that trick individuals into handing over a one-time code are being used against staff to get a foothold inside company networks.
The real cost, beyond the ransom figure
Every ransomware story eventually gets reduced to a single number — the ransom demand — but that figure is usually the smallest part of the actual damage. For an Australian small business, a serious ransomware incident typically involves several overlapping costs that stack up fast.
- Direct downtime: point-of-sale systems, booking platforms, invoicing and email can all be locked simultaneously, which for a lot of small operators means the business simply cannot trade for days at a time.
- Recovery costs: forensic investigation, specialist IT contractors, new hardware, and rebuilding systems from scratch when backups turn out to be incomplete or infected too.
- Regulatory exposure: if personal information was accessed, there may be notification obligations under Australian privacy law, and potential follow-up from regulators if the response is mishandled.
- Customer and supplier trust: clients who find out their data was exposed don’t always come back, and in tight-knit industries and regional communities, word travels fast.
- Insurance complications: cyber insurance can help, but many small business policies have conditions around MFA, patching and backup practices that, if not met, can reduce or void a payout right when it’s needed most.
Add it all up and it’s common for the total cost of an incident to run into six figures for a business with fewer than 20 staff, even when no ransom is ever paid. That’s before accounting for the weeks of lost momentum while the owner and staff are dealing with the fallout instead of running the business.
The first 24 hours: what to actually do
If you discover a ransomware attack in progress — files suddenly encrypted, a ransom note on screen, systems behaving strangely — the instinct is often panic, followed by either freezing or trying to fix everything at once. Neither helps. What matters in the first day is containment, evidence, and getting the right people involved in the right order.
- Isolate affected systems immediately. Disconnect infected machines from the network (unplug ethernet, disable Wi-Fi) rather than shutting them down completely, since a forensic investigator may need the machine’s memory state intact. The goal is to stop the ransomware spreading to other devices and shared drives, not to destroy evidence.
- Don’t rush to pay. Paying a ransom doesn’t guarantee you get a working decryption key, doesn’t guarantee the criminals haven’t kept a copy of your data anyway, and can mark you as a soft target for repeat attacks. Get advice from an incident response professional before making that call, not from the pressure of a countdown timer on a ransom note.
- Report the incident. This includes reporting to law enforcement and following the current guidance for Australian businesses on ransomware response and reporting channels, and, separately, notifying your cyber insurer straight away if you have a policy, since most require early notification as a condition of cover.
- Check your backups before you assume the worst. Confirm whether backups exist, how recent they are, and — critically — whether they were connected to the network at the time of the attack, since network-attached backups are often encrypted right along with everything else. An offline or immutable backup is what actually saves the day here.
- Assess what data was affected and notify customers where required. If personal information has been accessed or is likely to have been accessed, Australian businesses may have obligations under the Notifiable Data Breaches scheme to assess the breach and notify both affected individuals and the regulator within set timeframes. The Office of the Australian Information Commissioner’s guidance on notifiable data breaches sets out exactly when notification is required and how to run that assessment properly, and it’s worth reading before you decide notification isn’t necessary.
- Bring in specialist help early. A short engagement with an incident response firm in the first day is almost always cheaper than trying to muddle through recovery internally and getting it wrong, particularly around preserving evidence and confirming the attacker no longer has access before you reconnect systems.
One more thing worth saying plainly: don’t reconnect systems to declare victory the moment files are decrypted or restored. Attackers frequently retain a foothold through a secondary backdoor, and businesses that rush back online without a proper clean-up get hit again within weeks. Patience in those first 24 to 72 hours costs a lot less than a repeat incident a month later.
Prevention that actually works, versus security theatre
There’s no shortage of vendors happy to sell an Australian small business an expensive security package promising to make ransomware “impossible.” In practice, the handful of things that genuinely reduce risk are neither exotic nor especially costly, and most of them cost more in discipline than in dollars.
- Backups that are actually tested. Not just scheduled — tested. A backup nobody has tried restoring from is a hope, not a plan. At least one backup copy should be offline or immutable so it can’t be encrypted along with your live systems.
- Multi-factor authentication everywhere it’s offered, especially on email, remote access tools and any cloud admin accounts. A huge proportion of ransomware incidents start with a single compromised password, and MFA is still the single cheapest control that stops that from turning into a full breach.
- Patching on a schedule, not “when we get around to it.” Most ransomware doesn’t rely on brand-new zero-day exploits — it relies on known vulnerabilities that have had a patch available for months.
- Staff training that’s short, regular and specific, rather than an annual tick-box video nobody remembers. Teaching staff what a realistic phishing attempt actually looks like matters more than a thick policy document sitting in a shared drive nobody opens.
- Basic network segmentation so a single compromised laptop can’t reach every server and shared drive in the business.
Compare that list to what a lot of security theatre looks like: elaborate dashboards nobody monitors, compliance certificates that satisfy a checklist without changing daily behaviour, or premium hardware sitting unconfigured because no one had time to set it up properly. The Australian Government’s cyber security guidance for business.gov.au is a genuinely useful, no-cost starting point for working out which basics apply to your setup before spending on anything more elaborate, and it’s worth an hour of anyone’s time who’s putting a plan together for the first time. If you’re responsible for a website that handles customer orders, bookings or accounts, it’s also worth revisiting the fundamentals we set out in how to protect your website from data breaches, since a lot of the same weak points — outdated plugins, shared admin logins, no monitoring — apply just as much to ransomware as they do to a straightforward data breach.
None of this requires a six-figure security budget. It requires deciding that backups get tested quarterly, MFA gets switched on this week rather than next quarter, and patching becomes someone’s actual job rather than an occasional afterthought.
Final thoughts
Ransomware isn’t going away in 2026, and Australian small businesses aren’t going to stop being targets any time soon — the economics favour attackers going after the easiest wins, and too many SMEs are still the easiest wins available. The good news is that the gap between a business that gets hit and recovers in a few days and one that gets hit and nearly closes its doors usually comes down to preparation that isn’t expensive: tested offline backups, MFA switched on everywhere, patches applied on a schedule, and staff who know what a dodgy email looks like.
If it does happen to you, the steps that matter most in the first 24 hours are straightforward even under pressure: isolate before you panic, resist the urge to pay immediately, get the right specialists and authorities involved early, check what your backups actually give you to work with, and be honest with yourself about whether customer notification obligations apply. Businesses that follow that order tend to come out the other side bruised but intact. The ones that improvise usually don’t.




