Ransomware Realities: What Every Business Must Know
Show Links
Ransomware is more dangerous — and more accessible — than ever before. In this episode of Don’t Be A Sitting Duck, Leigh Kefford breaks down what’s really happening behind the scenes, how local businesses are being impacted, and the 5 non-negotiable actions your business must take to stay protected.
In This Episode:
- Why ransomware is exploding in 2025
- The biggest risks for regional businesses
- How phishing, patching, and backups can make or break your response
- What every business needs to qualify for cyber insurance
- The #1 tool to assess your risk — for free
Key Takeaways:
Most ransomware attacks are preventable with the right systems.
Employee awareness is as important as firewalls.
Recovery depends on preparation — not luck.
Episode Transcript
The numbers don’t lie — ransomware is still one of the most devastating threats facing Australian businesses today. From encrypted files and million-dollar ransoms to long-lasting downtime and regulatory penalties, the ripple effects are brutal.
In this episode, we’ll break down the real-world state of ransomware in 2025 — what’s changed, what’s stayed the same, and what your business needs to do to stay ahead. Plus, we’ll share the non-negotiable actions every business owner should take to avoid being the next headline.
Welcome to the Don’t Be A Sitting Duck Podcast, I’m Leigh Kefford — let’s dive in.
2024 saw a 68% rise in ransomware attacks globally — and 78% of those targeted small to medium businesses. The attackers aren’t just after large corporations anymore. Local businesses are squarely in the crosshairs, especially those who think, “It won’t happen to me.”
Even regional companies across North Queensland, including Townsville and Cairns, have reported incidents involving encrypted files, breached client data, and ransom demands exceeding $100,000.
How It Happened & Why It Matters
Here’s the uncomfortable truth: Most ransomware attacks begin with something preventable. A single phishing email. A missed patch. An unmonitored backup.
Ransomware-as-a-Service (RaaS) has exploded. That means threat actors don’t need elite skills to launch an attack — they can subscribe to toolkits that do it for them. It’s business, but it’s criminal. And it’s growing.
Why this matters: It’s not just about restoring your files — it’s the downtime, reputational damage, legal obligations, and the nightmare of explaining to clients that their data was compromised.
Take Action – How to Protect Your Business
Here’s what you must do now:
Backups: Offsite, encrypted, and tested weekly. If you haven’t tested your restore process in the last 30 days, that’s a red flag.
MFA Everywhere: Especially on email, remote desktop, and admin logins. It’s your cheapest, most effective wall.
Patch Everything: Don’t let an old version of software be your undoing.
Employee Training: Your people are the front line. Phishing simulation and awareness training is a non-negotiable.
Cyber Insurance Readiness: Insurers are asking for proof of controls.
Bonus tip: If you’re not sure where your weaknesses are, book a free Empower Systems Assessment — we’ll audit your environment and give you a practical roadmap.



