Ransomware has a marketing problem: the word conjures hoodie-wearing hackers targeting banks, so most small business owners file it under "not my problem". The reality is the opposite. Small businesses are the preferred target precisely because they're less defended — same money, less resistance — and the Australian Cyber Security Centre's reporting puts small and medium businesses squarely among the most affected groups, with recovery costs that routinely reach tens of thousands of dollars.
You don't need an enterprise security budget to be a hard target. You need five habits, most of which cost close to nothing.
1. It arrives looking ordinary
Ransomware rarely kicks the door down. It walks in wearing a familiar face: an invoice PDF from a "supplier", a missed-delivery text, a login page that looks exactly like Microsoft 365, a "your password expires today" email. One click, one password typed into the wrong page, and the attacker has what they need.
The habit: slow down on anything that creates urgency around a link or an attachment. Check the actual sender address, not the display name. And when an email asks you to log in, don't click through — go to the site directly. Ten seconds of suspicion defeats the majority of attacks, and it's free.
2. A backup you haven't tested isn't a backup
Backups are the difference between "bad week" and "pay the ransom or close". Attackers know this, which is why modern ransomware hunts for backups first — encrypting the backup drive that's permanently plugged into the server, or the network share everyone can write to.
The habit: keep at least one backup copy offline or off-site (cloud backup with versioning counts), and actually restore a file from it on a schedule. Monthly is fine. Most backups fail silently; the ones that get tested don't. If nobody in your business has ever performed a test restore, assume the answer is no until proven otherwise.
3. MFA is the cheapest security you will ever buy
Multi-factor authentication — the code on your phone after your password — turns a stolen password from a catastrophe into a non-event. Attackers with your password but not your phone simply move on to an easier victim. It's built into Microsoft 365 and Google Workspace already; it just needs to be switched on.
The habit: MFA on everything that matters — email first (it's the master key to every password reset), then banking, accounting, and anything holding customer data. No shared logins: when everyone uses the same account, you can't tell who was compromised, and MFA stops working as designed.
4. Updates are boring until they aren't
Those update reminders you keep postponing are, more often than you'd think, patches for security holes that attackers are actively using. Running a years-old Windows version or an unpatched router means the door is open regardless of how careful your staff are — automated scanners find exposed, outdated systems without any human involvement.
The habit: turn on automatic updates for operating systems and browsers, and give anything that can't auto-update (point-of-sale systems, NAS boxes, routers) a monthly check. If some piece of legacy software chains you to an old, unsupported machine, isolate it from the rest of the network — don't let the weakest device sit beside the file server.
5. Have a plan for the bad day
The worst time to figure out your response is while your screens are showing a ransom note. A plan doesn't need to be a binder — one page answers almost everything: who do we call, what do we unplug, where are the backups, how do we operate for a few days without the system?
Two Australian specifics belong in that plan. First, report the incident to the ACSC via ReportCyber. Second, know your Privacy Act obligations: if personal information was accessed and serious harm is likely, the Notifiable Data Breaches scheme may require you to notify affected customers and the OAIC. Deciding how you'd assess that is much easier before the bad day than during it.
If it's already happened
Disconnect the affected machines from the network (pull the cable, kill the Wi-Fi), don't switch them off, don't negotiate alone, and get professional help fast — paying the ransom funds the next attack and, per ACSC guidance, frequently doesn't get the data back anyway. Recovery odds depend heavily on the first hours: our data recovery service exists for exactly this scenario, including rebuilding a backup regime so there's no second time.
And if reading this list produced more "no" answers than you're comfortable with, that's what Managed IT is for — backups, patching, monitoring and MFA rollout handled for a flat monthly fee, or start with a free IT health check and we'll tell you exactly where you stand.