Ransomware remains one of the most devastating threats facing small and medium businesses in Australia. An attack can encrypt every file in your organisation within minutes, bring operations to a complete halt, and leave you facing an extortion demand with no guarantee that paying will restore your data. The average cost of a ransomware incident for an Australian SMB — including downtime, recovery costs, and reputational damage — runs to hundreds of thousands of dollars.
The good news is that protecting your business from ransomware is achievable with a combination of technical controls and staff awareness. Here’s what actually works.
How Ransomware Gets In
Understanding the entry points helps you focus your defences. The vast majority of ransomware attacks enter through one of three pathways:
- Phishing emails — staff click a malicious link or open an infected attachment, which downloads and executes the ransomware payload. This accounts for roughly 40% of Australian ransomware incidents.
- Compromised credentials — attackers use stolen passwords (often obtained from previous data breaches or phishing) to log into remote access tools like Remote Desktop Protocol (RDP) or VPNs, then manually deploy ransomware.
- Unpatched vulnerabilities — attackers exploit known vulnerabilities in software or hardware that hasn’t been updated. Many major ransomware campaigns have exploited vulnerabilities that had patches available for months before the attack.
The Controls That Actually Stop Ransomware
- Multi-factor authentication everywhere — MFA on email, remote access, and critical business applications stops credential-based attacks cold. Even if an attacker has your password, they can’t log in without the second factor.
- Endpoint Detection and Response (EDR) — next-generation security software that detects ransomware behaviour (rapid file encryption) and kills the process before it can spread. Traditional antivirus is not sufficient.
- Email filtering with malicious link and attachment blocking — enterprise-grade email security significantly reduces the volume of phishing emails that reach your staff’s inboxes.
- Regular patching — keeping all software, operating systems, and firmware updated removes the vulnerabilities that many ransomware groups exploit.
- Restricted administrative privileges — ransomware running under a standard user account can cause significantly less damage than ransomware running with administrative rights. Staff should not have local admin unless they genuinely need it.
- Offline or immutable backups — ransomware specifically targets backup systems to maximise leverage. Backups must be stored separately from the main environment — ideally with immutable retention that prevents them from being encrypted or deleted.
- Staff phishing simulation training — regular training and simulated phishing campaigns keep staff alert and improve their ability to recognise attacks before clicking.
What to Do If You’re Attacked
If you suspect a ransomware attack: immediately isolate affected systems from the network by disconnecting ethernet cables and disabling Wi-Fi; call your IT provider; do not pay the ransom without professional advice (payment does not guarantee recovery and may attract further attacks); and be aware of your Notifiable Data Breaches obligations if personal data may have been accessed.
Kinsoft provides ransomware protection and incident response services for Sydney businesses. Contact us to review your current protection posture.