Research published by Commvault reveals that 34% of organizations in Australia and New Zealand that experienced a ransomware attack opted to pay the ransom. This reliance on payment persists despite the uncertain outcomes associated with such decisions. The findings indicate a troubling trend where organizations continue to depend on ransom payments, often without achieving the desired recovery.
Ransomware Recovery Challenges and Concerns
The survey highlighted that paying the ransom frequently does not resolve the underlying issues. Among those organizations that chose to pay, 36% reported that the payment failed to restore access to their data, or attackers subsequently demanded additional funds. This raises significant concerns about the effectiveness of ransom payments as a recovery strategy.
Survey Scope and Methodology
The research was conducted through a quantitative survey involving 411 organizations across Australia and New Zealand. Respondents included Chief Information Officers, Chief Information Security Officers, IT leaders, and decision-makers. The study aimed to assess how these organizations prepare for cyber incidents and respond to ransomware disruptions.
Recovery Concerns and Planning Gaps
One of the key findings suggests that recovery concerns heavily influence ransom payment decisions. Confidence in the integrity and completeness of backups emerged as a critical factor for organizations when deciding whether to pay. This points to a significant gap between investments in security tools and the confidence in recovery processes, indicating that many organizations still harbor doubts about their ability to restore systems and data independently.
The study also identified a disconnect between business continuity planning and technology planning. While 61% of organizations defined the minimum business functions necessary to operate during a cyber crisis, only 43% had established the technology environments required to support those functions. Organizations that effectively mapped their business priorities alongside supporting technology were more likely to maintain operations and recover swiftly after a cyberattack.
Shifting the Recovery Conversation
Martin Creighan, Vice President, Asia Pacific at Commvault, emphasized that many businesses still treat ransomware as an immediate crisis rather than a preparedness issue. He stated, “Too many organisations are still treating ransomware as a decision they’ll make on the day. By the time you’re deciding whether to pay, you’ve already lost control of the situation.” This perspective underscores the importance of building robust recovery capabilities and regularly testing them before an attack occurs.
Establishing Recovery Priorities
Gareth Russell, Field CTO, Security, Asia Pacific at Commvault, advocated for organizations to set recovery priorities prior to an incident. He noted the necessity of identifying essential personnel, applications, systems, and data crucial for business continuity. Russell remarked, “The conversation needs to shift from ‘How do we recover everything?’ to ‘What must we recover first?'” Organizations that define their Minimum Viable Company before an attack are better positioned to reduce downtime and uncertainty, avoiding the reliance on ransom payments as a recovery strategy.
The data reinforces the notion that ransomware is not merely a security issue but also an operational challenge. The fact that over one in three paying victims did not achieve a clean recovery highlights the limitations of viewing ransom payments as a reliable path back to normal operations.
Follow Cyber Warriors Middle East for further cybersecurity features, research and analysis.


