Key Findings
- 52% of ransomware incidents in Australia and New Zealand occur during weekends or public holidays
- 85% of organisations with in-house SOCs reduce staffing by at least half during those periods
- 81% of attacks happen after a major corporate event such as a merger or restructure
- 92% involve compromised credentials as the initial access point
Source: 2025 Holiday Ransomware Risk Report
Australia and New Zealand are seeing the same pattern again this season.
More than half of ransomware incidents in Australia and New Zealand occur during weekends or public holidays. The latest Holiday Ransomware Risk Report shows this trend is not slowing down at all for 2025.
This report found that 85% of organisations with in-house security operations cut their staffing by at least half on weekends and holidays. Another 7% have no SOC presence at all during those periods.
When visibility drops, threat actors can stay inside system for longer. Attackers exploit that gap, knowing many alerts raised over a weekend will not be seen until Monday. For environments that rely on manual containment or single-person escalation, that delay is enough to turn a small exploit into full ransomware deployment.
Corporate events and timing risks
Toward the end of the year, organisations tend to adjust structure and staffing. The report found that ransomware activity increased during those changes.
81% of incidents in the AUS and NZ occurred after a major corporate event such as a merger, acquisition or round of layoffs. More than half of cyber incidents were recorded after redundancies.
These findings align with what many cyber experts are seeing locally. We’re finding that technical environments are rarely breached because of missing tools. They’re breached because staffing or focus is temporarily out of balance.
Credential misuse is still the first point of access
What I see in practice matches the report. Most ransomware still begins with a single compromised account. 92% of the surveyed organisations already have some form of identity threat detection. But fewer than half include clear remediation procedures and only 62% have automated recovery.
Australian businesses have really mature monitoring tools but usually have underdeveloped recovery pathways. This means that when an identity compromise occurs outside business hours, response usually depends on availability rather than process.
What matters for resilience in Australia and New Zealand
Ransomware actors know the general working rhythm and they plan accordingly.
For local teams, the challenge is not really visibility but continuity.
Resilience is measured in consistency. It depends on response processes that function at half capacity and on recovery systems that don’t rely on one person being available.
Australia’s defenders already have the technical maturity to close these gaps. The adjustment now is focused on planning and timing, preparing for the periods when attention is at its lowest and risk is at its highest.



