Key Takeaways
- The research found that 34% of ANZ ransomware victims paid, but 36% of those payers still faced failed recovery or additional demands.
- While 61% of surveyed organisations had defined critical business functions, a smaller segment mapped the minimum technology environment needed to sustain them.
- Tested backups and recovery priorities can reduce pressure to negotiate with attackers during an incident.
Commvault has found that paying ransomware attackers remains a common, and frequently ineffective, response among organisations in Australia and New Zealand.
The State of Data Resilience ANZ 2026 report found that 70% of ANZ organisations reported a ransomware demand, and 34% of those victims paid. Among those that paid, 36% said the transaction failed to resolve the incident because attackers did not restore access to data or subsequently demanded more money.
That is an uncomfortable outcome for business leaders who may view payment as the quickest route back to normal operations. A ransom payment is not a conventional commercial transaction. There is no enforceable service agreement, no dependable remediation process, and little recourse if the attacker changes the terms.
The wider survey findings show how often that calculation arises. Overall, 70% of ANZ organisations reported receiving a ransomware demand, with 20% of the overall sample stating they paid (source). The percentages use different denominators: the 34% payment rate applies specifically to the organisations that suffered a confirmed attack.
Policies do not eliminate the pressure, either. Although 54% of surveyed organisations had a no-payment policy, 15% of those organisations still paid when attacked. The gap between written policy and incident response illustrates what happens when prolonged downtime, customer disruption, and uncertainty collide.
A no-payment position is easier to maintain when recovery has already been demonstrated. If executives cannot establish whether backups are complete, clean, and available, payment can begin to look like an operational shortcut, even with no reliable evidence that it will work.
Commvault's vice president for Asia Pacific stated that organisations should make their preparations before an incident rather than treating payment as a decision for the day of an attack. The vice president argued that resilience comes from building robust recovery capabilities and regularly testing them in advance.
The study identified a related planning gap. While 61% of ANZ organisations had defined the minimum business functions required during a cyber crisis, a smaller segment of respondents had defined the minimum technology environment supporting those functions. Knowing that payroll, order processing, or customer communications are critical is one step. Mapping those activities to specific identities, applications, infrastructure, data sets, and dependencies is another.
What happens if the authentication service needed to reach a restored application is still unavailable? Authentication failures during restoration represent a specific operational risk that can halt the entire recovery process.
The company's field CTO for security in Asia Pacific described the required operating baseline as the "Minimum Viable Company." Rather than attempting to restore every system simultaneously, organisations can identify the people, applications, systems, and data that keep essential operations running, then test whether those components can be recovered in the required sequence.
That approach is consistent with the recovery and governance principles in the NIST Cybersecurity Framework. It also complements the risk management and business continuity controls associated with ISO/IEC 27001. For practical backup planning, the Australian Cyber Security Centre advises organisations to maintain backups and test restoration processes.
Testing matters because a successful backup job does not necessarily mean a successful business recovery. Organisations may need to validate data integrity, isolate recovery environments, secure privileged access, and establish realistic recovery times. They also need to account for dependencies spread across cloud services, on-premises infrastructure, and software-as-a-service applications.
AI adoption adds another wrinkle. As data estates expand and applications draw on more interconnected services, identifying authoritative data and recovery priorities can become harder. More data does not automatically mean more resilience.
TRA, now part of Omdia, conducted the quantitative survey on behalf of the company across a broad sample of ANZ organisations. Respondents included CIOs, CISOs, IT leaders, and other technology decision-makers.
The findings leave ANZ executives with a fairly direct question: if attackers encrypted critical systems tomorrow, could the organisation restore its most important operations without trusting the attacker? For many businesses, the answer will depend less on the backup policy document and more on the results of the latest full recovery exercise.
โฌ๏ธ