RANSOMWARE · 13 MIN

Ransomware Readiness and Response in Australia: A CISO and Board Playbook

Australian organisations now face ransomware as a continuous operating risk, not a tail event. This is the prevention stack, 72-hour response sequence and ransom-decision framework CISOs and CIOs use to keep the board, ASD, APRA and OAIC aligned under pressure.

Run your first mission free

Why ransomware is now a board-level risk in Australia

The Australian Signals Directorate's most recent Annual Cyber Threat Report identifies ransomware and data-extortion as the most disruptive cybercrime category affecting Australian entities. Optus, Medibank, Latitude, HWL Ebsworth and MediSecure have collectively reshaped director expectations: ransomware exposure is treated as a continuous-disclosure, regulatory and reputational risk — not just an IT incident.

The prevention stack that actually moves the dial

Defence-in-depth is the language. The Essential Eight is the floor. The controls below are the ones that, when present and rehearsed, materially change the outcome when an intrusion happens.

Six controls that change the outcome

  • Immutable, isolated backups. Air-gapped or object-lock backups with tested restore. The Maersk lesson: if your backup admin account is in the same AD forest as production, you do not have backups.
  • Application control + patching. ACSC Essential Eight ML2 minimum. Internet-facing systems patched within 48 hours of vendor advisory. Most Australian ransomware intrusions in 2024–2026 began with an unpatched edge device.
  • Phishing-resistant MFA. FIDO2 or platform authenticators on all admin, VPN, M365 and remote access. SMS and push-only MFA are now considered residual risk by ASD.
  • Network segmentation. Crown-jewel systems isolated from corporate AD. Identity tiering (Tier 0/1/2). Lateral movement is what turns an intrusion into a crisis.
  • EDR with 24/7 response. Detection alone is insufficient. Median dwell time on Australian ransomware cases is now under 24 hours — response must be continuous.
  • Rehearsed incident response. Quarterly tabletop, annual full-stack exercise with backup restoration. The plan you have not rehearsed is the plan that will fail.

The first 72 hours of a ransomware incident

The first three days set the trajectory for the next three months. The sequence below is the one CISOs use to keep technical response, regulator obligations and board communications running in parallel rather than in conflict.

72-hour ransomware response sequence

  • 0–1 hour. Declare an incident. Isolate affected segments at the network layer (not just hosts). Preserve volatile evidence. Engage legal counsel for privilege. Brief the CEO.
  • 1–4 hours. Stand up the Cyber Incident Response Team (CIRT). Confirm scope of encryption. Validate that backup tiers are intact and isolated. Notify cyber insurer to unlock panel responders.
  • 4–24 hours. ReportCyber lodgement. SOCI 12-hour critical notification if applicable. Forensic imaging. Begin parallel restoration planning from clean backups. Hold initial board update.
  • 24–72 hours. OAIC eligible-breach assessment in flight if personal information involved. APRA CPS 234 notification within 72 hours. SOCI 72-hour follow-up. Draft external comms and customer notifications. Begin ransom decision framework — never in isolation.
  • Day 3 onwards. Staged restoration with integrity verification. Threat-hunt for persistence before reconnecting. Post-incident review and defensible decision record for OAIC, APRA, ASD and the board.

Should we pay the ransom?

The ASD recommends against paying in almost all cases. Payment funds the criminal ecosystem, does not guarantee data return, and roughly one in three paying victims is extorted again within twelve months. That said, the decision is rarely binary. The defensible decision record covers:

  • Sanctions screening — confirmed counterparty is not on the Consolidated List or linked to a sanctioned regime. A payment to a sanctioned actor is a serious criminal offence.
  • Recovery viability — credible restore path from intact backups within tolerable time, or not.
  • Data exposure — extortion-only cases where personal information is already exfiltrated change the calculus; payment rarely prevents publication.
  • Reporting obligation — under the Cyber Security Act 2024, in-scope entities must report ransomware payments to ASD within 72 hours.
  • Insurance position — confirm cover, panel response and any payment pre-conditions.
  • Board authority — payment is a board-level decision, documented with options, evidence and rationale.

Parallel regulator obligations

  • ASD / ReportCyber — voluntary technical notification (strongly recommended); mandatory ransomware payment report within 72 hours for in-scope entities under the Cyber Security Act 2024.
  • SOCI Act — 12 hours for critical impact, 72 hours otherwise, for responsible entities.
  • OAIC (NDB scheme) — eligible-breach assessment within 30 days; notify as soon as practicable once eligibility is established.
  • APRA CPS 234 — material information security incidents within 72 hours.
  • ASIC — continuous-disclosure assessment for listed entities.

Treat these as parallel clocks running from different start points. A single ransomware event commonly triggers four to five notifications, each with its own statement, its own evidence threshold and its own reputational consequence.

FOR INCIDENT LEADERS

Generate a Ransomware Crisis Response Plan in minutes.

FORTE/CYBERx produces a one-page executive runbook — first-60-minute actions, RACI, ransom-decision frame, regulator notification drafts and board comms — anchored to ASD guidance, NDB, CPS 234 and SOCI obligations.

Start a free mission

The board questions that matter

  • How long would it take us to restore critical services from clean backups, today?
  • Are our backup admin credentials isolated from the production identity plane?
  • Who has the authority to authorise a ransom payment, and what is the documented frame?
  • When did we last rehearse a full ransomware tabletop, including legal, comms and the board?
  • Which regulators are notified, on what clocks, and who owns each notification?

The defensible decision record

Every material ransomware decision — isolate or wait, pay or refuse, notify now or after assessment — should be captured with context, the options considered, the evidence relied on, legal advice, the decision and the rationale. This record is the single most useful artefact in any subsequent OAIC, APRA or shareholder action.

FAQ

Is it illegal to pay a ransom in Australia?

Paying a ransom is not, in itself, illegal in Australia today. However, the Cyber Security Act 2024 introduced a mandatory ransomware payment reporting obligation for many entities, and payments to sanctioned individuals or entities under the Autonomous Sanctions regime remain a serious criminal offence. Boards should treat any payment as a regulated decision, not a procurement one.

Who must I notify when ransomware hits?

In parallel: the Australian Signals Directorate (ASD) via ReportCyber and, for SOCI responsible entities, mandatory incident reports within 12 or 72 hours; the OAIC under the NDB scheme where personal information is involved; APRA within 72 hours for regulated entities under CPS 234; ASIC where continuous-disclosure obligations are triggered; and your cyber insurer per policy terms.

How long should ransomware recovery take?

Recovery time depends on backup architecture, segmentation and rehearsal. Mature Australian organisations restore critical services within 3–7 days; those without immutable, isolated backups commonly take 3–6 weeks. The single biggest determinant of recovery speed is whether the backup tier itself was compromised before encryption.

What does the ACSC recommend?

The Australian Signals Directorate (ACSC) recommends against paying ransoms in almost all cases, prioritises the Essential Eight (especially patching, application control, MFA and daily backups), and asks affected entities to report via ReportCyber so it can share intelligence and offer technical assistance.

Related

Be ready for the ransomware event you have not yet had.

Two free missions. No credit card. Built for Australian technology and security leaders.