Gridware Logo

Aussie Businesses Still Overconfident With Their Cyber Defences

By Ahmed Khanji Updated 13 November 2025 2 min read

in 𝕏
Aussie Businesses Still Overconfident With Their Cyber Defences

Despite rising ransomware attacks

CrowdStrike’s 2025 State of Ransomware Survey shows that many Australian businesses overestimate how ready they are for a ransomware attack. Confidence is high, but recovery times don’t match.

The study surveyed more than a thousand security leaders across several countries, including 100 from Australia and New Zealand.

Half of them said their organisation was very prepared for ransomware but only 9% managed to restore operations within a day.

Plans that never get tested

Most organisations have response plans and backup systems, but few test them in real conditions. CrowdStrike found that more than three quarters of respondents are finding it harder to keep pace with faster AI attacks.

Attackers now use AI to write convincing messages, translate them for different regions and scan networks automatically.

What used to take hours now happens in minutes. Response plans that stay static can’t keep up with that pace.

Recovery that doesn’t meet expectations

Australia and New Zealand had some of the slowest recovery rates in the survey. 86% of respondents expected to recover within a day. Fewer than 1 in 10 did. In the UK, more than a third reached that goal.

This gap comes from how leaders and security teams see readiness. Executives tend to think the organisation is covered, while technical teams can see what’s still missing. When that difference isn’t addressed, the same weaknesses stay open.

Paying doesn’t guarantee recovery

Many victims still pay attackers hoping to speed up recovery. CrowdStrike found that 83% of paying organisations were targeted again and 93% said their data was taken anyway. Almost 4 in 10 couldn’t restore everything from backups.

Ransomware operations now move quickly and repeat where they succeed. Attackers look for businesses that seem organised but haven’t tested their recovery process end to end. Even a short disruption can be enough to force payment.

Readiness needs proof

Real readiness can be measured. It’s the time it takes to detect, isolate and restore systems when pressure hits. That measure says more about capability than any report or checklist.

Teams that rehearse live incidents recover faster. Teams that haven’t tested their plan often discover too late what’s missing.

With the holiday season approaching, every gap matters more. Short staffing and heavier online traffic make this the hardest time of year to respond.

Ahmed Khanji

Ahmed Khanji

CEO, Gridware

Ahmed Khanji is the CEO of Gridware, a leading cybersecurity consultancy based in Sydney, Australia. He is recognised for his insights into offensive security and emerging technologies such as blockchain, and often contributes to broader cybersecurity conversations across the country. With an extensive background as a security advisor to major Australian enterprises, Ahmed helps organisations navigate the evolving threat landscape with clarity and confidence.