One-Third ANZ Firms Pay Ransom, Data Often Lost

Commvault

New Commvault research finds many organisations are still making short term ransomware decisions instead of building long term cyber resilience.

Commvault (NASDAQ: CVLT), a leader in unified resilience at enterprise scale, has released new research revealing that organisations across Australia and New Zealand continue to pay ransomware demands despite no guarantee of recovering their data or restoring business operations.

According to Commvault's State of Data Resilience ANZ 2026 report, 34% of organisations that experienced a ransomware attack paid the ransom demand. Yet paying proved to be a high-risk strategy. Of those organisations that paid, more than one third (36%) said payment failed because attackers either did not restore access to their data or returned with further ransom demands.

The findings underscore a growing disconnect between security investments and recovery readiness. Among organisations that experienced ransomware attacks, confidence in the integrity and completeness of backups was a key factor in the decision to pay a ransom. This suggests that many organisations still do not have sufficient confidence in their ability to recover independently of attackers.

"Too many organisations are still treating ransomware as a decision they'll make on the day. By the time you're deciding whether to pay, you've already lost control of the situation. True resilience comes from building robust recovery capabilities and regularly testing them well before an attack occurs, not during one," commented Martin Creighan, Vice President, Asia Pacific at Commvault.

The research also found that organisations are better at defining critical business functions than identifying the technology needed to support them. While 61% of ANZ organisations have defined the minimum business functions required to continue operating during a cyber crisis, only 43% have done the same for their technology environments. Organisations that define both are significantly more likely to maintain operations and recover faster following a cyberattack.

As organisations adopt AI, data estates continue to expand and technology environments become increasingly complex. Identifying the systems, applications and data that matter most is becoming critical to reducing recovery uncertainty and maintaining business continuity.

According to Gareth Russell, Field CTO, Security, Asia Pacific at Commvault, organisations need to stop making recovery decisions during a crisis and start building resilience before one occurs.

"The conversation needs to shift from 'How do we recover everything?' to 'What must we recover first?' Organisations that define their Minimum Viable Company before an attack know exactly which people, applications, systems and data keep the business operating, and they've already proven they can recover them. That's how you reduce downtime, remove uncertainty and avoid treating ransomware payments as a recovery strategy."

About research methodology

TRA (now part of Omdia) conducted an independent quantitative market survey of 411 organisations with respondents from CIO/ CISO, IT leader, IT decision maker and direct reports.

Supporting Graphics

Graphic 1

Unsupported image type.

Graphic 2

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).