One in three ANZ organisations still pay ransomware demands, Commvault research says

0

Commvault has released research suggesting organisations across Australia and New Zealand continue to pay ransomware demands despite uncertainty over whether data will be returned or business operations restored.

The company’s State of Data Resilience ANZ 2026 report found 34% of organisations that experienced a ransomware attack paid the ransom demand. Of those that paid, 36% reported the payment did not resolve the incident because attackers did not restore access to data or returned with further ransom demands, according to the research.

The research points to backup confidence as a factor influencing whether organisations decide to pay. Commvault said respondents’ confidence in the integrity and completeness of backups affected decision-making, suggesting some organisations lack confidence in their ability to recover without engaging with attackers.

Commvault Vice President, Asia Pacific Martin Creighan said organisations should avoid making ransomware payment decisions during an incident and instead focus on building and testing recovery capabilities in advance. “Too many organisations are still treating ransomware as a decision they’ll make on the day. By the time you’re deciding whether to pay, you’ve already lost control of the situation. True resilience comes from building robust recovery capabilities and regularly testing them well before an attack occurs, not during one,” Creighan said.

The report also found a gap between business continuity planning and technology mapping. It said 61% of ANZ organisations had defined the minimum business functions required to continue operating during a cyber crisis, while 43% had defined the minimum technology environment required to support those functions. Commvault said organisations that define both are more likely to maintain operations and recover faster following a cyberattack.

Commvault Field CTO, Security, Asia Pacific Gareth Russell said organisations should prioritise identifying what must be recovered first. “The conversation needs to shift from ‘How do we recover everything?’ to ‘What must we recover first?’ Organisations that define their Minimum Viable Company before an attack know exactly which people, applications, systems and data keep the business operating, and they’ve already proven they can recover them. That’s how you reduce downtime, remove uncertainty and avoid treating ransomware payments as a recovery strategy,” Russell said.

Commvault linked the issue to growing technology complexity, citing expanding data environments and AI adoption as factors increasing the importance of identifying critical systems, applications and data for business continuity.

The report’s methodology states TRA (now part of Omdia) conducted a quantitative survey of 411 organisations, with respondents including CIOs, CISOs, IT leaders and IT decision-makers.

You can read the full report here.

Share.