Ransomware has not gone away, it has grown up. The attacks hitting Australian businesses in 2026 look quite different from a few years ago, and some of the old advice no longer holds. Here is what has changed, and the good news: the defences that actually stop it are well understood and within reach of any business.
What’s changed
It is not just about locking your files anymore
The old model was simple: criminals encrypted your data and demanded a ransom for the key. The counter was equally simple, a good backup, and you could restore and ignore them.
Attackers adapted. Now they steal your data first, then encrypt it, and threaten to publish it if you do not pay. This is called double extortion, and it changes everything: a backup no longer saves you from the threat of your clients’ information being leaked. Prevention matters more than ever, because you cannot restore your way out of a data breach.
Ransomware is a business now
Criminal groups sell “ransomware as a service”, ready-made attack kits that let less-skilled criminals run professional-grade attacks for a cut of the profit. That has widened the pool of attackers and the number of targets. Small and medium businesses are firmly on the menu, precisely because they are seen as less defended than big enterprises.
The attacks are faster and smarter
AI has made the phishing emails that start most attacks far more convincing, with fewer of the spelling mistakes and clumsy wording that used to give them away. And once inside, attackers move faster than they used to, sometimes going from a single clicked link to encrypting a whole network in hours. There is less time to notice and react.
They come for your backups
Attackers know backups are your safety net, so a modern attack often hunts for and deletes or encrypts your backups first. A backup that is connected to your network and reachable with the same admin login is not the insurance you think it is.
What still stops it
Here is the reassuring part. Despite all of the above, the overwhelming majority of ransomware attacks still rely on the same handful of openings, and closing them stops most attacks before they start. There is no silver bullet, but there is a proven stack.
- Align to the Essential Eight. The Essential Eight is the set of mitigation strategies the Australian Signals Directorate recommends, and it was practically designed against this threat: patching, application control, restricting admin rights and more. Reaching the first maturity level closes the doors attackers use most.
- Backups that attackers cannot reach. Keep at least one backup copy that is offline or immutable, meaning it cannot be changed or deleted even by someone with your admin password. Then test that you can actually restore from it. This is what turns a ransomware hit into a bad day rather than a closed business.
- Stop the intrusion, not just the login. Multi-factor authentication is still essential, but on its own it is no longer enough, because attackers now phish live sign-in sessions. Pair it with conditional access that only lets your managed, compliant devices reach company data, so a stolen password on an unknown laptop gets nowhere. Most of this is already sitting in a Microsoft 365 Business Premium licence, waiting to be switched on.
- Remove standing admin rights. Most ransomware needs admin access to spread. If day-to-day accounts do not have it, and admin access is granted only when needed, you take away the attacker’s favourite tool.
- 24/7 detection and response. Modern security software watches for the behaviour of an attack in progress and can isolate an affected machine automatically, at 2am on a Sunday, before it spreads. Attacks no longer keep business hours, so your defence cannot either.
- Train your team. Since most attacks still start with a person clicking something, regular, plain-English security awareness training remains one of the highest-value things you can do.
- Have a plan before you need one. Knowing who to call and what to do, and having practised it, is the difference between a contained incident and a chaotic one.
This layered approach is the heart of the IT security work we do, and it lines up with the phishing defences in our guide to building a human firewall.
The bottom line
Ransomware in 2026 steals before it encrypts, moves faster, and hunts your backups, so “just keep a backup” is no longer a strategy on its own. But the way in has barely changed. Align to the Essential Eight, keep backups attackers cannot touch, switch on the security you already own, remove standing admin rights, and watch your systems around the clock, and you have closed the doors the criminals rely on.
If you would like an honest read on how exposed your business is, and what to fix first, our Brisbane team is happy to take a look. See our IT security services or get in touch for a quick chat.
Adam leads the Itopia team in Brisbane, helping professional-services firms get secure, productive and confident with their technology, in plain English.

