Human Error & Ransomware Risks for Australian Businesses

Show Links

In this episode of Don’t Be A Sitting Duck, host Leigh Kefford dives into the evolving cyber-threat landscape in Australia. We look at how human error is emerging as a bigger driver of data breaches even as total breach numbers drop, and why ransomware continues to pose a critical risk to business continuity. Each story includes what happened, why it matters and practical actions you can take.

Stories Covered

  • Fewer data breaches in Australia, but human error now a bigger threat — Rising share of staff mistakes despite a drop in total reported breaches.
  • Ransomware realities: What you need to know — Ongoing rise in ransomware and its business impact, and what businesses must focus on to defend themselves.

Together these stories point to a clear message for business leaders: technology alone isn’t enough. The human element — culture, process, training — and the readiness for a crisis matter just as much. Listen, reflect and get your plan in place.

Key Takeaways

  • Human error now accounts for around 37 % of reported breaches in Australia.
  • Malicious attacks (including ransomware/phishing) remain the primary cause of breaches.
  • Ransomware is not just a data loss event — it’s a business continuity and reputational risk.
  • Practical defence involves training, segmentation, MFA/backups, vendor oversight and incident readiness.
  • Book an assessment, test your recovery, and assume the unexpected.

Sources & Further Reading

What To Do Next

  • Book your free Empower Systems Assessmentnationalpc.com.au/empower

  • Listen to my audiobook: Sitting Duck – The Phone Call You Don’t Want to Receive → Available now on Spotify and leading audiobook platforms

  • Subscribe to the Don’t Be A Sitting Duck Podcast for daily insights

Episode Transcript

I’m seeing two major stories we’ll cover: one around how human error is surging in data breaches in Australia, and the other focused on the persistent threat of ransomware and what businesses need to know. And yes—there are clear, practical actions today’s business leaders should be taking. Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford—let’s dive in.

In the first half of 2025, Office of the Australian Information Commissioner (OAIC) reported 532 notifiable data breaches in Australia, down about 10 % from the previous six-month period.

However, breaches caused by human error rose significantly — from 29 % up to 37 % of all incidents.

While malicious attacks still account for the majority of breaches (59 % of incidents) in Australia.

What stands out is the rise in breach notifications tied to staff mistakes or mis-handling of data. For example, the OAIC called out a case where a government agency’s outsourced software developer ran an unauthorised script, exposing private documents publicly and in search engines.

This matters because many organisations assume that once the technology “looks secure” they’re fine — but the human factor remains a weak link. Outsourced vendors, scripts, configuration errors, staff errors: these are the risks that often bypass the firewall and endpoint protections. It also means the board and executive leadership need to shift their mindset: • It’s not just “how many hackers are out there” but “how many mistakes are we enabling internally”. • It also means breach readiness isn’t optional — you need to assume human error will happen and have a plan.

Take Action
Here are actionable steps businesses should take:

Conduct a supplier / outsourcing risk review: ensure every third-party or developer you engage has their scripts, access and configuration under control. Ask: “What happens if they make a human error — can we detect and contain it?”

Boost staff awareness and training, but go beyond generic training: Include real-world scenarios of mis-configuration, unauthorised scripts, human mistakes — and test them via simulations or role-play.

Implement segmentation and least-privilege access: internal systems and data should only be accessible to those who absolutely need it; if a script runs in the wrong place, the blast radius is limited.

Review your breach response plan: if human error causes an exposure, you still have to act fast — including notification, containment, forensic review. Make sure your plan is tested and ready.

While the above article doesn’t focus on a single ransomware event, the broader ransomware threat remains very real in Australia and globally. The OAIC report flagged that malicious or criminal attacks (including ransomware and phishing) continue to dominate breach causes.

Additional industry commentary makes clear that ransomware remains one of the highest-impact cyber threats, and its tactics are still evolving.

Ransomware attacks typically begin with phishing, credential theft, exploitation of remote access vulnerabilities, or supply-chain issues.

Once the attacker gains a foothold, they may encrypt data, exfiltrate data, threaten publication, or disrupt services. Because business operations increasingly depend on digital systems, the impact is not just the ransom payment — it’s downtime, reputational damage, regulatory exposure and erosion of trust. As one piece puts it, “[ransomware] tactics will continue to morph… the best defence is to be prepared, not just for an attack but also for the after-effects.”

For Australian businesses — the sectors most affected by breach notifications (health, finance, government) — are also among those with high sensitivity to disruption. The presence of ransomware in the threat mix just underscores the urgency: you’re not just protecting data, you’re protecting business continuity.

Take Action
Here are steps businesses should adopt to defend against ransomware:

Backups and recovery strategy: Ensure you have regular, tested backups that are air-gapped or immutable, and a plan for rapid recovery. Don’t just back up — test the restore.

Multi-factor authentication (MFA) plus strong credential hygiene: Protect remote access, VPNs, and administrative accounts. Credential theft remains one of the leading causes of breaches.

Patch management and vulnerability hygiene: Keep OS, software, plugins, remote access services up to date. Attackers exploit unpatched systems.

Incident simulation / tabletop exercises: Run a ransomware simulation so your leadership team knows what to do if encrypted or exfiltrated. Do you have contact lists, legal counsel, communication plan, forensic specialist?

Segmentation + privilege control: Limit the attacker’s ability to spread laterally. Even if they get in, they shouldn’t be able to encrypt your entire estate or critical systems.

That’s a wrap for today’s episode! Want more cybersecurity insights? Head over to sittingduck.com.au for show notes, resources, and the latest updates. Thinking about your business security? Here’s what to do next: Book your free Empower Systems Assessment to uncover vulnerabilities and learn how to strengthen your defences. Listen to my audiobook, Sitting Duck – The Phone Call You Don’t Want to Receive—a real-world look at Business Email Compromise. Available now on Spotify and leading audiobook platforms.

Until next time—stay safe, stay informed, and don’t be a sitting duck!

This podcast was produced by National PC, delivering expert cyber security services in Townsville and Cairns through our Empower Managed IT solutions—secure, reliable, and built for North Queensland businesses.