If you run a business in Geelong, on the Bellarine, or down the Surf Coast, ransomware is the single cyber threat most likely to put you out of action. It is not the rare, dramatic event people imagine. The Australian Cyber Security Centre reports that ransomware remains one of the highest-impact threats to Australian small businesses, and the local firms we see hit are usually the ones who assumed they were too small to be a target.
This guide explains what ransomware is, how it actually gets into a business, what it costs when it lands, and the practical steps that keep your Geelong business recoverable. The good news is that the protections are well understood - backups, Microsoft 365 hardening, and the Essential Eight cover most of the risk. The bad news is that most local businesses have not finished any of them.
What is ransomware and how does it get in?
Ransomware is malicious software that encrypts your files - documents, databases, photos, accounting data - and then demands payment, usually in cryptocurrency, for the key to unlock them. Modern strains also steal a copy of your data first and threaten to release it publicly, which means paying does not necessarily make the problem go away.
GEO is a city of around 290,000 people on Wadawurrung Country in Victoria, Australia, about 75 kilometres south-west of Melbourne, sitting at the western end of Corio Bay and serving as the regional hub for the Bellarine Peninsula and the Surf Coast. Its mix of professional services, manufacturing, healthcare, construction and trades makes it a busy target zone for opportunistic attacks.
Ransomware rarely arrives through a Hollywood-style hack. It gets in through ordinary, everyday gaps:
- Phishing emails. A staff member clicks a link, enters their Microsoft 365 password into a fake login page, and attackers now have a working set of credentials. This is the number one entry point we see.
- Exposed remote desktop (RDP). A computer or server left facing the internet on port 3389 gets brute-forced overnight. If you can reach it from home, so can an attacker in another country.
- Unpatched software. Old versions of Windows, Office, VPNs, or firewall firmware with known security holes. Attackers scan for these constantly and automatically.
- Reused or stolen passwords. A password leaked from another site is tried against your email and admin accounts. Without multi-factor authentication, it often works.
- Compromised suppliers. An attacker gets in through a trusted vendor or contractor who has access to your network or Microsoft 365 tenant. You did nothing wrong and still got hit.
Once an attacker has a foothold, they typically move quietly for days or weeks, mapping your network, finding your backups, and stealing data before they trigger the encryption. That dwell time is why detection matters as much as prevention.
What a ransomware attack actually costs
The headline number is the ransom demand, but it is rarely the biggest cost. The real damage stacks up across several areas:
- Downtime. Most Geelong businesses we work with are effectively closed while systems are encrypted. Days of lost revenue, wages paid to staff who cannot work, and missed client deadlines.
- The ransom itself. Demands aimed at small businesses commonly sit in the tens of thousands of Australian dollars, and paying is no guarantee of recovery.
- Data loss. Files that were not backed up, or backups that were also encrypted, are gone for good. For some firms that is years of client records and accounting history.
- Reputational damage. Clients and partners find out their data was exposed. Trust takes a hit that lasts far longer than the technical recovery.
- Regulatory fallout. Under the Privacy Act and the Notifiable Data Breaches scheme, an attack involving personal data often has to be reported to the Office of the Australian Information Commissioner, and affected individuals notified.
Industry reporting consistently puts the average cost of a small-business ransomware incident in Australia well into five figures once downtime, recovery effort and lost work are counted, and the Australian Cyber Security Centre continues to flag ransomware as a leading cause of serious small-business disruption. For a 10-person Geelong firm, a single bad week can wipe out a quarter's profit.
The three layers of ransomware protection
Good ransomware defence is not one product. It is three layers working together:
- Prevent - stop the attack getting in. MFA, patched systems, anti-phishing controls, and least-privilege access.
- Detect - notice quickly when something is wrong. Logging, alerting, and someone actually watching them.
- Recover - get back to work without paying. Tested, offline backups and a rehearsed restore process.
Most local businesses we meet have a bit of prevention and almost nothing on detection or recovery. The problem is that prevention is never perfect, so the recover layer is the one that decides whether an attack is a bad day or a business-ending event.
Backups: your last line of defence
If you only do one thing from this guide, sort your backups. A clean, tested, offline backup is the difference between a ransomware hit being an annoying weekend and being a catastrophe. Attackers know this, which is why modern ransomware goes after backups first - deleting them, encrypting them, or corrupting them before triggering the main attack.
The classic rule still holds: the 3-2-1 rule. Three copies of your data, on two different media types, with one copy kept off-site and offline. For most Geelong small businesses that translates to:
- Your live Microsoft 365 and file data.
- An automated cloud backup of email, SharePoint, OneDrive and Teams.
- An immutable or offline copy that an attacker logged into your network cannot reach or delete.
Immutable backups - ones that cannot be altered or deleted within a set retention window - are the single biggest upgrade we make for local clients. They take ransom payments off the table because you can always restore.
And then test it. A backup you have never restored is a hope, not a plan. Run a test restore every quarter, time how long it takes, and confirm the restored data actually opens. If you want the deeper version of this conversation, our backup and ransomware protection service walks through it in detail, and our cloud vs local backup guide covers how the two approaches compare.
Hardening Microsoft 365 and identity
Most Geelong small businesses run on Microsoft 365, which means your identity is your perimeter. If someone logs into your tenant as a staff member or admin, the firewall in the office does not matter. Hardening Microsoft 365 is where prevention starts:
- Multi-factor authentication for everyone. Not just admins. Every account, including shared mailboxes and contractors. MFA blocks the overwhelming majority of credential-based attacks.
- Conditional access. Block logins from unexpected countries, require MFA on new devices, and stop legacy authentication protocols that bypass MFA entirely.
- Anti-phishing and anti-spam. Turn on the built-in Defender protections, tune the policies to your business, and quarantine suspicious mail before it reaches the inbox.
- Least privilege. Most staff do not need global admin. Reduce admin roles, use break-glass admin accounts, and review who has what access regularly.
Phishing is the front door for most ransomware, so getting email right is worth the effort. Our phishing emails in Microsoft 365 guide goes deeper on the practical settings, and if you want a hand configuring it properly, our Microsoft 365 services cover setup, hardening and ongoing management.
The Essential Eight: where to start
The Essential Eight is the Australian Cyber Security Centre's baseline set of mitigation strategies, and it maps almost perfectly onto ransomware prevention. You do not need to do all eight at once. The highest-impact starting points for a Geelong small business are:
- Application control and patching - close the obvious holes.
- MFA and least privilege - protect identity.
- Daily backups with tested restores - protect recovery.
- Restricting admin and Microsoft 365 privileges.
We use the Essential Eight as the framework for most client hardening work because it is practical, government-backed, and lines up with what insurers now expect. For the full picture, see our Essential Eight compliance service and our Essential Eight cyber security guide for the plain-English version.
What to do if you are hit
If ransomware lands, the first hour matters. The basics:
- Isolate. Disconnect affected machines from the network - pull the network cable, turn off Wi-Fi - but do not power them off unless advised, as that can destroy volatile evidence.
- Do not pay by default. The ACSC and the Australian Government advise against paying. Payment funds further crime and rarely guarantees recovery.
- Preserve evidence.Keep the affected systems as they are for investigation, and do not start deleting things to "clean up".
- Restore from backups. Only after you are sure the attacker is out and the entry point is closed - otherwise they encrypt you again.
- Report it. Lodge a report with ReportCyber at the ACSC. It is free, it is expected, and it may unlock help and intelligence.
If you are mid-incident and based in Geelong, the Bellarine or the Surf Coast, get in touch - incident response is part of what we do.
Getting help with ransomware protection in Geelong
Ransomware protection is not a one-off product you buy and forget. It is a set of controls - backups, identity, patching, monitoring - that need to stay in shape as your business changes. Most Geelong small businesses do not have the in-house time to keep on top of it, which is exactly where we come in.
Our cyber security services cover the full picture, from risk assessment to ongoing management. If backups are your gap, start with our backup and ransomware protection service - it is the single biggest risk-reducer for most local firms. And if you just want to talk it through, get in touch and we will tell you honestly where you stand.
