Eight capabilities that decide a ransomware outcome
Nothing here will stop you being attacked. What these eight decide is whether the attempt becomes an inconvenience, a fortnight of recovery, or a payment decision — and they are the eight to test a provider against.
Ransomware is not the most common thing that happens to Australian firms — email compromise is, by a wide margin. But it is the one with the potential to stop a practice entirely, and it is the reason most professional services firms start looking seriously at Australian managed IT services and cyber security in the first place.
ASD's Annual Cyber Threat Report for 2024–25 puts ransomware at around 11 per cent of reported cybercrime, which is steady year on year. The volume is not what changed. What changed is the obligation attached to it: since 30 May 2025 an organisation over the $3 million turnover threshold that makes an extortion payment must report it to ASD within 72 hours, and the Department of Home Affairs moved to active enforcement from 1 January 2026.
So the question is no longer only whether you can recover. It is whether you can recover without needing to make a decision that starts a statutory clock.
How to read this list
Each capability has three parts: what it does, what good looks like, and how you verify it rather than take it on trust. Use the verification column with your current provider. A firm that can produce eight artefacts is in reasonable shape; most produce four or five, and the missing ones are usually the same ones.
Several map onto the Essential Eight. ASD announced in June 2026 that the Essential Eight will be replaced by a broader set of guidance called the Essentials, with the controls largely carrying over — we covered what that means for work already in progress. Nothing below becomes less true under either framework.
Making entry harder
1. Identity that resists phishing, not just password guessing
What it does. Removes the most common initial access route. The majority of intrusions we see begin with a valid credential rather than an exploit.
What good looks like. Multi-factor on every account with no standing exemptions, conditional access that considers device and location, legacy authentication protocols disabled, and a method that survives an adversary-in-the-middle phishing kit. Push approvals and SMS codes no longer clear that bar on their own — see MFA is not the finish line.
Verify: a per-account MFA registration report, the list of exemptions with a reason against each, and confirmation that legacy authentication is blocked.
2. Detection and response on the endpoint, watched by a person
What it does. Catches the hours or days between initial access and encryption. That window is where an outcome is decided, and it is almost always outside business hours.
What good looks like. An EDR product is table stakes. The capability that matters is cyber security monitoring with a human who can act — isolate a host, disable an account — without waiting for permission. An alert that lands in a console nobody is watching at 3am is not a control.
Verify: the written standing authority to contain out of hours, plus three months of alert volumes showing what was actioned and how quickly.
3. Patching with a number attached
What it does. Closes the exploited-vulnerability route, which is the second common entry point after credentials — particularly on internet-facing appliances, VPN concentrators and file transfer products.
What good looks like. Separate, faster treatment for anything exposed to the internet. Third-party applications patched, not just Windows. And a measured compliance percentage rather than a described process.
Verify: patch compliance by month for the last six months, split between internet-facing and internal.
4. Email control, including the human step
What it does. Blocks the delivery route for most initial access, and — more importantly for a professional services firm — addresses the attack that is statistically far more likely to cost you money.
What good looks like. Enforcing DMARC, impersonation protection tuned to your partner and director names, attachment and link handling, and a payment verification procedure that does not rely on email. Roughly one in three cybercrime reports affecting Australian businesses starts with a mailbox; we set out the mechanics in the attack that actually empties the account.
Verify: your DMARC policy record — if the policy is set to “none”, it is reporting rather than enforcing — and the written payment verification procedure, with evidence it is followed.
Limiting the blast radius
5. Privileged access that does not travel
What it does. Determines whether one compromised workstation becomes one compromised workstation, or the whole environment. Ransomware operators are looking for administrative credentials from the moment they land.
What good looks like. No standing domain administrator rights. Separate administrative identities, time-bound elevation, local administrator passwords unique per machine, and your provider's own access held to the same standard — including named engineers rather than a shared account.
Verify: the current privileged account list, including the provider's, with the date of the last review and who signed it.
6. Segmentation and controlled remote access
What it does. Slows lateral movement and protects the systems that must survive — the practice management database, the document management system, the finance platform, and the backup infrastructure above all.
What good looks like. Backup systems on separate credentials and a separate network path. Remote access behind MFA with no exposed RDP. Server-to-server traffic restricted to what is needed. This is unglamorous work and it is what changes the size of the incident.
Verify: a current network diagram showing where the backup infrastructure sits, and an external port scan of your public addresses.
Recovering without paying
7. Immutable backups with a measured restore time
What it does. This is the capability that converts an extortion demand into a recovery timeline. Everything above reduces probability; this one changes the consequence.
What good looks like. Copies that cannot be altered or deleted within their retention period, held outside the production identity domain, covering Microsoft 365 as well as servers — Microsoft's shared responsibility model does not include backing up your tenant data for you. And restore testing on a schedule, producing a measured recovery time for named systems.
A backup success report is not a restore test. If the recovery time in your continuity plan is a target rather than a result, it has never been tested.
Verify: the most recent restore test report — date, system, elapsed time — and confirmation that immutability is enforced by the platform rather than by policy.
8. A rehearsed response plan that includes the legal clocks
What it does. Decides how the first six hours go, which in our experience determines most of what follows.
What good looks like. Named individuals with mobile numbers, printed. Insurer and legal counsel contacts in the same document. A pre-agreed position on who can authorise containment. And the notification obligations written into the plan itself: Notifiable Data Breaches assessment under the Privacy Act, client contractual notice periods, and the 72-hour ransomware payment report if you are over the threshold.
That last one catches more firms than expected — it is turnover, not headcount, and a payment made on your behalf by an insurer or an incident response firm still starts your clock. We have set out who it covers.
Verify: the plan, the date of the last tabletop exercise, and who was in the room. If the partners have never rehearsed it, you have a document.
Where firms usually fall down
Across assessments, the same three gaps recur regardless of size or sector.
The three we find most
- Backups run, restores have never been attempted end to end.
- Monitoring exists but nobody is authorised to act on it at 2am.
- Administrative rights are standing rather than elevated on request.
What that combination produces
- An intrusion that runs unattended over a long weekend.
- Encryption that reaches the backup infrastructure as well as production.
- A payment decision made under pressure, with a 72-hour clock nobody mentioned.
None of the eight is exotic and none of it is expensive relative to the exposure. What it requires is one party being accountable for all eight rather than four of them, which is the argument for buying managed IT and security from the same provider.
Questions
Does cyber insurance cover this instead?
Insurance covers financial consequence, not operational continuity, and increasingly it is conditional. Renewal questionnaires now ask directly about MFA coverage, privileged access, backup immutability and restore testing — four of the eight above — and answers given loosely at renewal become a problem at claim time.
Treat the questionnaire as a free audit. Where you cannot answer honestly, that is the work list.
Is paying ever the right call?
It is not illegal in Australia, and it is a decision for your board with legal counsel and your insurer involved — sanctions screening alone puts it outside the scope of an IT conversation. What we would say is that the decision is only ever forced by a gap in capability seven. Firms with tested immutable backups face a recovery timeline rather than a negotiation.
We are a 40-person firm. Is this proportionate?
Six of the eight are configuration and process rather than new products, and are well within reach at that size. Monitoring with human response and immutable backup are the two carrying real per-user cost, and they are also the two that most change the outcome.
If budget forces a sequence, do identity and tested backups first. They remove the most probability and the most consequence respectively.
Our IT provider says we are covered. How do we test that?
Ask for the eight artefacts listed above, in writing, with dates. A provider doing the work can produce most of them within a week and will be candid about the ones they cannot.
Pay attention to the difference between the question you asked and the question answered. A description of a process is not evidence that it ran.
General information about security practice and regulatory obligations, not legal advice. If you are managing an active extortion event, involve legal counsel and your insurer immediately.
All eight, under one agreement
Most firms hold four or five of these, spread across two or three vendors. We carry all eight and answer for the gaps — which is the whole argument for a single accountable partner.
- Identity and endpoint. Phishing-resistant MFA, conditional access, and detection and response watched by rostered Australian engineers.
- Immutable, tested backup. Restore testing on a schedule with a measured recovery time — the capability that removes the payment decision.
- Remediation included. A finding becomes work on a timeline, not a line item in next month’s report.
- Essential Eight to Essentials. Uplift sequenced to your budget, with evidence a board or an insurer will accept.
- One incident timeline. Detection through containment to root cause, produced by the party that saw all of it.
- The clocks in the plan. Notifiable Data Breaches and the 72-hour payment report written into the runbook, not a compliance register.
Find out which of the eight you have
An assessment produces the evidence, measured and dated, and tells you what it would cost to close the gaps — before an insurer or a client's risk team asks.