One in three ANZ organisations paid a ransomware demand last year. Most still lost their data. The reason most paid was not that attackers were too sophisticated. It was that they were not confident their backups would work.
That finding comes from Commvault's State of Data Resilience ANZ 2026 report, based on 411 organisations across Australia and New Zealand. The implications go well beyond ransomware.

The Numbers
34% of ANZ organisations that experienced a ransomware attack paid the ransom. Among those who paid, 36% said the payment failed anyway. Attackers either refused to restore data access or returned with another demand.
One in three organisations paid and still did not get their data back.
Separately, 54% of surveyed organisations had formal no-payment policies. Yet 15% of those same organisations still paid when an attack landed. Policy collapsed under pressure. This pattern is consistent with what recent cyber attacks affecting ANZ businesses in 2026 have shown across the region. This is not a data point about ransomware tactics. It is a data point about confidence. Organisations that pay are the ones who do not trust their own recovery infrastructure will hold.

Why Backup Confidence Fails
The Commvault report identifies backup confidence as the key factor shaping the ransom decision. Organisations uncertain about backup integrity were significantly more likely to engage with attackers instead of recovering independently.
The problem is not that backups do not exist. It is that backups have never been tested under realistic conditions.
2026 telemetry from Acronis found that 82% of active backup rules have automated testing set to never. For most organisations, no one is regularly verifying that recovery actually works. The same telemetry found 85% of recovery servers have RPO monitoring completely disabled. Backups can stop running silently. The first signal arrives during a failover, when the newest clean copy is days or weeks old.
A green dashboard does not mean recovery works. It means a job completed. Those are two different facts.
Ransomware operators know this. Backup repositories are targeted in 96% of attacks and successfully compromised 76% of the time. Eliminating the recovery option is what makes the ransom negotiable.

The Cost Gap
Organisations with compromised backups face median recovery costs near three million dollars. Organisations with intact, tested backups face costs closer to $375,000. That is an 8x difference driven entirely by backup readiness.
The Commvault report found that 61% of ANZ organisations have defined minimum business functions needed during a cyber crisis. Only 43% have done the same for the technology environments that support those functions. Organisations know what needs to keep running. Fewer have tested whether their technology actually can. That gap is where ransom payments come from.

Not Just About Encryption Anymore
Ransomware tactics in 2026 have shifted. Attackers increasingly bypass encryption entirely and go straight to data exfiltration, stealing data and threatening to publish it. Because attackers know most organisations now have backups, the leverage has moved from disruption to exposure.
A backup strategy does not protect against this version of the attack. If data is stolen before encryption triggers, restoring from backup does not undo the breach. This is part of why annual pentests fail to catch what matters.
The security conversation around ransomware now requires both recovery readiness and entry point elimination. Backup confidence addresses what happens after an attack. Penetration testing addresses whether the attack gets through in the first place. For deeper insight on this evolution of extortion models, you can read more about Ransomware 3.0.

Your Last Pentest Is Already Out of Date
Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.
What Closing the Gap Looks Like
True resilience comes from building and testing recovery capabilities well before an attack, not during one. By the time you are deciding whether to pay, you have already lost control.
Three things need to happen before an attack lands.
Recovery needs to be tested. Not a dashboard check. An actual restore exercise that proves the backup is clean, recent, and bootable. 37% of organisations fail to recover within required RTO because backups are untested, even when jobs show as successful.
Entry points need continuous validation. Ransomware relies on known vulnerability chains and exposed credentials for initial access. Building a continuous offensive security programme finds those paths before attackers do. 80% of organisations that paid were attacked again within twelve months, because paying does not close the door.
The technology environment needs to match the recovery plan. penetration testing for compliance requirements like SOC 2 and PCI DSS gives teams auditable, documented evidence that the environment is actually defensible, not just assumed to be. the true cost of waiting a full year between tests is exactly what shows up in ransom decision rooms across ANZ. To see this in action locally, you can read the ManageMyHealth breach details.
The Bottom Line
Paying a ransomware demand is not a security strategy. The data confirms it does not reliably return data, it invites repeat attacks, and it does nothing to close the vulnerabilities that allowed access in the first place.
Organisations that avoided paying had one thing in common. They trusted their recovery infrastructure because they had tested it. That confidence does not come from a backup product. It comes from regularly proving recovery works, and from knowing entry paths have been found and closed before a crisis forces the question.
If you want to know whether your current environment would leave you negotiating with attackers at 2am, the answer is not in your backup logs. It is in how recently you tested what happens when those logs are wrong.
Book a security consultation with Capture The Bug to find out where your pre-attack defences actually stand at our Request Demo page.
Plan Your Annual Pentesting Strategy the Right Way
Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.
FAQ
Why are ANZ companies still paying ransomware demands in 2026?
Backup confidence is the key driver, according to Commvault's State of Data Resilience ANZ 2026 report based on 411 organisations. Organisations uncertain whether their backups are intact and recoverable are more likely to engage with attackers rather than attempt independent recovery. When a live attack lands, untested recovery infrastructure becomes the deciding factor.
Does paying a ransom actually get your data back?
Rarely completely. Of ANZ organisations that paid, 36% reported the payment failed because attackers either withheld data access or returned with further demands. Globally, only 4% of organisations that paid recovered all of their data. 80% were attacked again within 12 months of paying.
What is the financial difference between tested and compromised backups?
Organisations with intact, validated backups face median ransomware recovery costs around $375,000. Organisations with compromised backups face costs near three million dollars. That is an 8x difference driven by whether backup infrastructure was functional and recoverable at the point of attack.
How does penetration testing reduce ransomware risk?
Ransomware attacks rely on entry points including unpatched vulnerabilities, exposed credentials, and misconfigurations. Continuous penetration testing finds and validates those paths before attackers use them. Backup repositories are targeted in 96% of ransomware attacks, so testing backup isolation is also a critical component of ransomware readiness.
What should ANZ organisations do now to reduce ransom risk?
Three things before an attack: regular restore testing under realistic conditions to confirm backups are clean and bootable, continuous security testing to close entry points before they are used, and mapping the technology environment to recovery plans so teams know exactly what to restore first. Decisions made during an attack are almost always worse than decisions made before one.





