TelcoNews Australia - Telecommunications news for ICT decision-makers
Australia
Many ANZ ransomware victims still pay, study finds

Many ANZ ransomware victims still pay, study finds

Wed, 12th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Commvault has published research showing that 34% of organisations in Australia and New Zealand that suffered a ransomware attack paid the ransom. The findings suggest organisations still rely on payment despite uncertain recovery outcomes.

The survey found payment often did not resolve the problem. Among organisations that paid, 36% said it failed because attackers either did not restore access to data or later demanded more money.

The research was based on a quantitative survey of 411 organisations in Australia and New Zealand. Respondents included Chief Information Officers, Chief Information Security Officers, IT leaders, IT decision-makers and their direct reports. It examined how organisations in the region prepare for cyber incidents and respond when ransomware disrupts operations.

The results suggest recovery concerns remain a major factor in ransom decisions. Among organisations that experienced ransomware attacks, confidence in the integrity and completeness of backups was an important influence on whether they chose to pay.

This points to a gap between spending on security tools and confidence in recovery processes. It also suggests some organisations still doubt their ability to restore systems and data without relying on attackers.

Recovery gap

The study also found a divide between business continuity planning and technology planning. While 61% of organisations said they had defined the minimum business functions needed to keep operating during a cyber crisis, only 43% had defined the technology environments required to support those functions.

Organisations that had mapped both business priorities and supporting technology were more likely to maintain operations and recover more quickly after a cyberattack, the report found. The findings come as companies manage larger volumes of data and more complex technology estates, including systems linked to artificial intelligence projects.

Martin Creighan, Vice President, Asia Pacific, Commvault, said many businesses still approach ransomware as an immediate crisis decision rather than a preparedness issue.

"Too many organisations are still treating ransomware as a decision they'll make on the day. By the time you're deciding whether to pay, you've already lost control of the situation. True resilience comes from building robust recovery capabilities and regularly testing them well before an attack occurs, not during one," Creighan said.

The report argues that planning should focus not only on restoring systems, but also on identifying which parts of the business must come back first. That approach helps limit downtime and reduce uncertainty during an attack.

Priority systems

Gareth Russell, Field CTO, Security, Asia Pacific, Commvault, said organisations should set recovery priorities before an incident. He pointed to the need to identify the people, applications, systems and data essential to keeping the business running.

"The conversation needs to shift from 'How do we recover everything?' to 'What must we recover first?' Organisations that define their Minimum Viable Company before an attack know exactly which people, applications, systems and data keep the business operating, and they've already proven they can recover them. That's how you reduce downtime, remove uncertainty and avoid treating ransomware payments as a recovery strategy," Russell said.

The data adds to evidence that ransomware is not only a security problem but also an operational one, with decisions shaped by how quickly organisations believe they can restore services. In this survey, the fact that more than one in three paying victims still did not achieve a clean recovery highlights the limits of treating ransom payments as a path back to normal operations.