The Backup You Have Not Tested Is a Ransom You Have Already Agreed to Pay

Not applicable. Cyber News cycle continuation; no numbered Part sequence to link to or from.


Thirty-four percent of ANZ organisations hit by ransomware in the past year paid the attacker. Of those that paid, thirty-six percent got nothing back: the criminal withheld the data anyway, or came back for more.[1] That is not a story about attacker sophistication. Commvault, whose State of Data Resilience ANZ 2026 report put those figures together from 411 chief information officers, chief information security officers and IT decision-makers across Australia and New Zealand, reads it the other way around: organisations pay because they do not trust their own backups to bring them back faster, or more completely, than the criminal is promising to.

That is a board question before it is a technical one. A restore nobody has rehearsed is a resilience claim an organisation has made to itself without ever finding out whether it is true, and the only way to test it for certain is the moment a ransom note makes the test necessary. New Zealand's National Cyber Security Centre has been saying as much, in writing, since 2021: testing a backup, in the agency's own words, is "an important way to have confidence" in an organisation's ability to recover.[2] That guidance is not new. What Commvault added this month is the first ANZ-wide price on what ignoring it actually costs, calculated at the worst possible moment: during the incident itself, not rehearsed in advance of one.

Commvault published its State of Data Resilience ANZ 2026 report on 12 August 2026, and the coverage that followed a week later framed it bluntly: Australian and New Zealand companies are paying ransoms because they do not believe in their own backups.[1] The finding that matters most sits underneath the headline payment figure. Gareth Russell, Commvault's Field Chief Technology Officer for Security in Asia Pacific, frames the fix as a concept the report calls the Minimum Viable Company: knowing, in advance, exactly which people, applications, systems and data actually keep an organisation operating, and having already proven those specific things can be recovered. The absence of that proof, not the presence of a smarter attacker, is what Commvault says drives a defender to the negotiating table.

The same report supplies the planning gap underneath the payment gap. Sixty-one percent of ANZ organisations have defined the minimum business functions they need to keep operating through a cyber crisis. Only forty-three percent have defined the minimum technology environment required to support those functions.[3] That eighteen-point gap is the distance between naming what matters to the business and knowing, specifically, what has to be restored, in what order, to actually deliver it. A board can approve a business continuity plan that reads well and still have no idea whether the technology underneath it will do what the plan assumes.

Set against the rest of the world, ANZ's numbers read as a regional lag rather than a universal problem. Sophos's State of Ransomware 2026 survey, drawn from 2,158 IT and security leaders across seventeen countries, found that backup-based recovery of encrypted data rose to sixty-six percent of cases in 2026, up from fifty-four percent the year before, even as the average cost of recovering from an incident climbed eleven percent to just under 1.7 million US dollars.[4] Two-thirds of the world's organisations that suffer a ransomware attack are now getting their data back from their own backups rather than the attacker's decryption key. Against that direction of travel, the finding that more than one in three ANZ organisations that paid a ransom this year still got nothing for it does not read as an isolated regional problem. It reads as ANZ trailing a shift that has already started everywhere else.

I have spent three books telling boards that resilience is a once-only argument: an organisation gets one real chance to prove it can recover, and by definition that chance only arrives once, at the moment the backup actually has to work. Everything else, every tabletop exercise, every policy document, every line item in an audit report, is rehearsal for a test the organisation has not yet sat. Commvault's numbers are what it costs when the real test arrives and the rehearsal never happened: more than a third of the people who reach for the chequebook get nothing for the money, because paying was never actually a recovery strategy. It was a substitute for one.

Put it inside the Fiduciary Risk Exposure formula I introduced early in this series: FRE equals the cost of remediation multiplied by the probability of breach, plus the potential loss. A board that has never tested its own restore cannot honestly complete either side of that equation. It does not know its real probability of a survivable breach, because survivable is precisely the word an untested restore leaves unproven. Every board packet that reports a comfortable recovery-time objective without a rehearsed restore behind it is reporting a number nobody has actually measured.

The Commvault numbers describe the decision from inside the organisation that gets breached. A second, related exposure sits one layer further out: the data an organisation loses is often not its own. In the same fortnight Commvault published its findings, three unrelated breaches supplied that vendor dimension from three different directions. Quest Apartment Hotels, part of the Ascott group and operator of more than 120 properties across Australia, disclosed on 19 August 2026 that unauthorised access to a database had exposed more than 1.5 million records: names, contact details and, in a smaller subset, dates of birth. Quest's own statement traced the cause to "a vulnerability through" a third-party service provider it declined to name.[5] The guests whose names appeared in that database never chose that provider. They chose a hotel.

Unlimited Technology Systems, a billing and revenue-cycle vendor supporting more than 4,500 oncology practices across the United States, disclosed on 6 August 2026 that a ransomware attack the previous October had compromised the data of just over 3.8 million patients, including Social Security numbers, health insurance details and diagnosis information.[6] The intrusion happened between 5 and 10 October 2025 and was discovered on 19 October 2025. Notification took roughly nine months. Every one of those 3.8 million people is a patient of a doctor, not a customer of Unlimited Technology Systems. Most of them will never have heard the company's name until this year.

And Lifeline Australia, the crisis support line, confirmed in mid-July that a threat actor operating under the alias "2019" had accessed staff and volunteer records and posted more than ten thousand of them to a dark web forum, some of them altered to include false information.[7] Lifeline was explicit that no help-seeker data was touched. Researchers tracking the same actor's wider activity report it reached something close to twenty-five Australian not-for-profit and mid-tier organisations over roughly five months, a sector picked for reasons that also predict who has never tested a restore: high staff turnover, thin technology budgets, and the assumption that a charity is not a target.[7]

Three jurisdictions, three sectors, one shape. In every case, the people whose data was lost had no relationship with, and no visibility into, the organisation that actually held it, and no way of knowing whether that organisation's backups had ever been tested until the breach forced the question into the open. A vendor's recoverability posture is exactly as invisible to the people it affects as its security posture, arguably more so, because a breach eventually gets disclosed under law. An untested backup regime usually does not surface until the day it fails.

None of this required a cleverer criminal. Every one of these organisations, Commvault's 411 respondents included, is working against the same economics: a functioning backup makes the ransom conversation short, and an unverified one makes it long, expensive and frequently pointless anyway. The finding that more than a third of ANZ organisations that paid still got nothing back is the sharpest version of that argument this series has been able to cite, because it removes the one assumption boards usually lean on when they defer a restore test: that paying is always at least a fallback. Commvault's data says it frequently is not even that.

New Zealand's own recovery-confidence baseline predates Commvault's ANZ-wide figures by five months, and the honest framing is to say so rather than present it as fresh. Kordia's "She Won't Be Right" report, published 30 March 2026, found that thirty percent of New Zealand businesses lack the confidence to recover from a major cyber attack, that a third of incidents took more than two months to resolve, and that sixty-one percent of businesses hit by an incident suffered serious operational disruption.[8] That is New Zealand's own version of the gap Commvault has now priced at the regional level. In March, three in ten New Zealand businesses told Kordia they did not trust their own ability to recover from a major attack. In August, an ANZ-wide survey put a number on what that lack of trust costs: better than one in three ransomware victims paid anyway, and more than a third of them got nothing for it.

NCSC's own position on this has not moved, because it has not needed to. The guidance quoted at the top of this article was first published in 2021 and last updated in April 2023.[2] It is not a response to Commvault's findings; it predates them by years. Its relevance here is what that predates. The standard Commvault's data says most ANZ boards are failing is not a standard New Zealand's own cyber agency has only just discovered. It has been stated, plainly, for five years. That makes this a narrower and more useful claim than "regulators recommend testing backups" would be on its own: the gap most boards are carrying is not a knowledge gap. It is an execution gap, sitting in plain sight of published guidance nobody has been required to act on.

There is a regulatory thread worth naming lightly rather than leaning on. New Zealand's Cyber Security Action Plan proposes a mandatory cyber risk management programme, aligned to a recognised framework, for operators across seven critical infrastructure sectors. Recoverability testing would sit comfortably inside a programme like that, though nothing published so far states it would be required specifically. The honest way to put it is that recoverability could plausibly become an auditable control, not just a recommended one, under the regime New Zealand is currently consulting on, not that it already has.

Sixty-one percent serious operational disruption is not an abstraction either. It is the gap between a board that assumed its incident response plan covered recovery, and a board that discovers, mid-incident, that the plan covered everything except the one step that determines how long the disruption actually lasts.

None of this requires a board to become technical to test it. It requires four questions, asked in the right order, of the right person.

First, ask when the last full restore was actually rehearsed, end to end, under the explicit assumption that the primary environment cannot be trusted. Not a file recovery test. Not a partial restore of a single system while the rest of the environment stays online. A full rehearsal, timed, under the same constraint an actual ransomware event imposes: assume everything connected to the compromised network is suspect until proven otherwise. If the honest answer is "we're not sure" or "it has been a while," the board already has its most useful data point of the year.

Second, ask for the organisation's own version of Commvault's Minimum Viable Company: the specific, named list of people, applications, systems and data that have to come back first for the business to keep functioning, and evidence that list has actually been tested, not just documented. Sixty-one percent of ANZ organisations can name their minimum business functions. Only forty-three percent can name the minimum technology environment underneath them. A board that cannot see both lists side by side is looking at half the picture.

Third, ask how far the organisation's recoverability obligations reach into its supply chain. Quest, Unlimited Technology Systems and Lifeline were all breached through, or as, a vendor relationship someone else depended on. A board's own restore test answers only its own exposure. It says nothing about whether the vendors holding its customers', patients' or members' data have ever tested theirs, and vendor assurance questionnaires rarely ask.

Fourth, set a cadence and put it in the minutes. A restore test performed once, two years ago, to satisfy an auditor, sits closer to no test at all than to a genuine resilience posture. The Once-Only Resilience Framework is not a warning that an organisation gets one chance at recovery in the abstract. It is a warning that the test itself needs to be repeated often enough that the one chance that actually matters, the real incident, is not the first time anyone has run it.

Commvault's own explanation for why more than a third of ANZ ransomware payments bought nothing is not a story about better criminals. It is a story about boards that have never watched their own recovery plan fail in a drill, where failing costs nothing but the afternoon, instead of failing during the incident, where it costs the ransom and the data both. Sophos's numbers say the rest of the world is already moving away from paying and toward trusting a tested backup instead, two-thirds of cases recovered that way in 2026 against just over half the year before. New Zealand's own Kordia baseline from March said thirty percent of businesses here already know they could not recover with confidence if it happened tomorrow. Neither of those facts is a prediction. Both describe exactly how much runway is left before the next incident turns an assumption into a fact.

The test itself is not expensive, and it is not technical in the way a board might assume. It is a rehearsal, timed, with the primary environment treated as untrustworthy, run against a named list of what the organisation actually needs back first. Every board that has run one already knows, in specific and falsifiable terms, what its own version of Commvault's thirty-six percent looks like. Every board that has not is currently finding out the same way Quest's guests, Unlimited Technology Systems' patients and Lifeline's staff and volunteers are finding out this year: after the fact, and on somebody else's schedule.

The recovery side of this problem has its own open-source tradition, one that gets less attention than the vulnerability side. Backup and restore tools such as Restic and BorgBackup publish their encryption, deduplication and restore logic as code anyone can read and test, independent of the vendor that wrote them, the same transparency principle behind the software bill of materials work this series covered last month. Separately, the No More Ransom initiative, a public-private partnership Europol and the Dutch police built with two commercial security vendors in 2016, has spent a decade proving that a decryption tool built once and shared widely can return a stolen key to more organisations than any single ransom payment recovers. A board that cannot explain how its own backup actually encrypts, deduplicates or restores its data is trusting a black box with the one test it only gets to sit for real, once.

The vendor-intermediary pattern in Quest, Unlimited Technology Systems and Lifeline is not new to critical infrastructure. It is the shape the Kaseya and MOVEit incidents put on allied governments' agendas in 2021 and 2023, when one shared platform's compromise became a recovery problem for thousands of downstream organisations that had never chosen that platform directly. Critical infrastructure operators, the sectors New Zealand's proposed regime and its allied equivalents both name, increasingly depend on the same small set of shared managed-service and backup platforms their smaller customers also use. A national cyber security agency can publish standing guidance on testing a restore, as NCSC NZ has since 2021, but it cannot test a private organisation's backup on its behalf. Recoverability, tested and evidenced rather than assumed, is the one control on this list that scales from a single board's fiduciary duty to a country's critical infrastructure posture without a single new law.

When did your board last watch its own restore fail in a drill, where the only cost was the afternoon, rather than during the real incident, where the cost was the ransom and the data both?

If your board wants an independent AI and cyber risk briefing, or a review of what your vendor's assurance actually verified, message me and I will send the scope and the fixed fee.


The views expressed in this article are entirely my own, informed by more than 30 years of professional experience in architecture, security, and technology leadership in New Zealand. I write as director of Te Pono Limited; the views are personal and do not represent the position of any client, any government agency, or the New Zealand government. My commentary on legislation and policy is analytical, drawing on publicly available sources and my professional expertise in architecture, security, and AI governance, and it is politically neutral.


Andreas Hamberger is a New Zealand leader in Architecture & Security and Associate Member of the Institute of Directors. The Hamberger Report: Cyber Guide for New Zealand Boards is the third book in The Hamberger Report series, providing board members and senior leaders with practical cyber resilience governance guidance. Through Te Pono he provides independent AI and cyber risk briefings and vendor assurance reviews to boards; contact andreas@thehambergerreport.com for the scope and fixed fee.


This article was produced with AI assistance under my direction. Research, drafting and images pass through a pipeline I built and govern: automated gates for source verification, forbidden language and political neutrality, and my own review before anything is published. The tools include Claude, Gemini and Openart. The frameworks, arguments and editorial judgements are mine and are the same discipline I apply to the AI systems I audit for clients. AI accelerated the work; the thinking, and the responsibility for it, are mine.


[1] Scoop. "ANZ Companies Paying Ransoms Because They Don't Believe in Their Backups." 18 August 2026. https://www.scoop.co.nz/stories/BU2608/S00168/anz-companies-paying-ransoms-because-they-dont-believe-in-their-backups.htm

[2] National Cyber Security Centre New Zealand. "Ransomware: Your Organisation Should Be Both Protected and Prepared." Originally published 31 May 2021, updated 28 April 2023. https://www.ncsc.govt.nz/news/ransomware-your-organisation-should-be-both-protected-and-prepared/

[3] Australian Cyber Security Magazine. "One in Three ANZ Organisations Still Pay Ransomware Demands, Commvault Research Says." August 2026. https://australiancybersecuritymagazine.com.au/one-in-three-anz-organisations-still-pay-ransomware-demands-commvault-research-says/

[4] Sophos. "Sophos State of Ransomware 2026." July 2026. https://www.sophos.com/en-us/blog/sophos-state-of-ransomware-2026

[5] Quest Apartment Hotels, via Newshub Medianet. "Statement from Quest Apartment Hotels." 19 August 2026. https://newshub.medianet.com.au/2026/08/statement-from-quest-apartment-hotels/167077/

[6] HIPAA Journal. "Patient Data Exposed, Ohio Revenue Cycle Management Company." August 2026. https://www.hipaajournal.com/patient-data-exposed-ohio-revenue-cycle-management-company/

[7] Cyber Daily. "Data Breach: Lifeline Australia Confirms Staff Data Compromised Following Hacking Claims." July 2026. https://www.cyberdaily.au/security/13894-data-breach-lifeline-australia-confirms-staff-data-compromised-following-hacking-claims

[8] Kordia. "She Won't Be Right: How Cyber Resilient Are New Zealand Businesses?" 30 March 2026. https://www.kordia.co.nz/news-and-views/she-wont-be-right-how-cyber-resilient-are-new-zealand-businesses

Next
Next

Cybersecurity Governance: New Zealand's Light-Touch Era Is Ending