Ransomware Protection for NZ Businesses

Ransomware protection combines the measures that reduce the chance of an attack, limit how far it spreads, and help the business recover. It covers secure access, patching, endpoint protection, protected backups and a response people know how to follow. Recovery also has to deal with compromised accounts and with any information stolen during the attack. New Zealand’s National Cyber Security Centre treats prevention and recovery as one discipline, because attackers who reach administrator credentials often go after the backups before encrypting anything.

The scenario below is a composite and the numbers in it are illustrative.

A thirty person engineering firm paid nothing and lost eleven days anyway. The encryption ran on a Friday night, the backup server was reached first, and the only copy that survived was a drive somebody had unplugged in March and forgotten about. Eleven days was how long it took to rebuild forty workstations from that drive and re-enter three weeks of job sheets from paper.

It is one way an incident can unfold rather than the usual one, and it is the kind of shape ransomware protection has to be built against.

The ransom demand was never the expensive part. The controls that were supposed to stop it had been bought and installed, and the one thing that saved the business was an accident.

Work out your own figures from two questions: how long could you keep invoicing without your systems, and who in the building could prove a backup restores.

Neither needs a consultant. Both are answerable in an afternoon. Few owners have put them to anyone, and the answers are usually worse than expected.

What follows are five assumptions that cost New Zealand businesses money, and what ransomware protection has to cover once you stop making them.

Do Small Businesses Get Hit by Ransomware?

Yes, and being small is no protection. A firm of thirty people runs the same Microsoft 365, the same remote access and the same unpatched line-of-business server as a firm of three hundred, with nobody whose actual job is watching any of it. Ransomware protection at that size has to work without a security team, which changes which controls are worth having.

The NCSC responded to 1,129 incident reports between April and June 2026, of which 92 were triaged for specialist technical support because of their potential national significance. Those are all reported cyber incidents rather than ransomware alone, and they are not a count of attacks on New Zealand small businesses. They also cover only what somebody chose to report, so read them as a measure of reported activity rather than of the odds against your own firm. Size your ransomware protection on your own exposure instead.

Read the public loss figures carefully before you use them to size your own risk. Reported losses are dominated by individuals, so a headline dollar total says almost nothing useful about what an attack would cost your firm.

Your own number is worth working out, carefully. Start with the contribution you would lose rather than headline revenue, and separate revenue that is delayed from revenue that never arrives, because adding full revenue loss and idle payroll together counts the same money twice. Then add the costs you cannot avoid while you are down, the extra ones the incident creates, the recovery work itself, and the point at which cash actually moves. Write your assumptions next to the figure, because that is what makes it arguable rather than decorative, and what tells you how much ransomware protection is worth buying.

Attackers do not choose targets by revenue. They scan for the exposed service and the reused password. Exposed services and reused passwords attract opportunistic attacks. Beyond that, target value, sector, the access an attacker already holds and what they are trying to achieve all vary.

The economics run against you in the response as well. A large organisation has somebody on call overnight and a documented process for isolating a network, while a thirty person firm has a duty manager and a phone number for the IT provider. That gap is what ransomware protection has to close, and it closes with process more than spend. Knowing who makes the call to pull the internet connection is worth more at two in the morning than any product on the market. That decision costs nothing to make in advance and cannot be made well under pressure.

No sector is exempt. Ransomware reaches engineering firms, medical practices, freight operators and accountants, because a common way in is a service exposed to the internet and that has little to do with the work you do. The foundations of ransomware protection are therefore much the same job in a workshop as in a clinic, even where the systems and the obligations differ.

What Protects a Business From Ransomware?

Ransomware protection is easier to hold in your head as five work areas than as a ranked list of products. Each one contains several controls, and which of them matter most depends on your actual exposure and where the gaps are, not on a fixed order. Completeness across the five is what reduces risk in ransomware protection, and nothing here guarantees an outcome.

Work area What it should cover
Reduce entry points Review services exposed to the internet, strengthen sign-in, patch vulnerabilities, filter email, and support safe staff behaviour.
Limit spread and damage Least privilege, separate administration, network segmentation, endpoint protection and controlled application execution.
Detect and respond Relevant logs and alerts, someone to investigate them, clear authority to act, and agreed coverage outside business hours.
Preserve recovery Protected backup copies, backup administration held separately, usable recovery points and restore testing.
Prepare the business Recovery priorities, response contacts, an alternative way to communicate, and who owns the notification decisions.

Reducing entry points is where ransomware protection does most of its work, because it stops an attack before there is anything to recover from. Multi-factor authentication has to cover the VPN and the remote desktop as well as email, and the exceptions matter as much as the coverage, because most tenancies carry a handful of accounts excluded from the policy for a reason that made sense two years ago. Those are the accounts an attacker will find. Alongside it sit the services nobody meant to leave exposed, email filtering, and staff who know what to do with a message that looks wrong.

Patching follows the exposure rather than the calendar. Internet-facing systems are exploited within days of a vulnerability being published and sometimes within hours, so those and anything under active exploitation come first, with emergency patching or a temporary mitigation where no fix is available yet. Internal systems still need a schedule, and it should be set by risk rather than left to a standing monthly allowance.

Limiting spread decides how much of the business an intruder reaches. Day-to-day work should not be done from an account that can reach the backup server, administration belongs apart from ordinary use, and the network should not let one compromised machine talk to everything else. Endpoint protection and controlled application execution sit in the same work area. The same reasoning runs through the eight attack types.

Detection is the work area businesses skip, and it is the one that shortens an incident. An alert on a failed backup, a new administrator account or an out-of-hours login gives somebody the chance to act while an attacker is still moving. Send those alerts to a person rather than a shared mailbox, because an alert nobody owns is the same as no alert, and agree who holds the authority to respond outside business hours before you need them.

Preserving recovery and preparing the business are the two work areas where ransomware protection is judged, because between them they decide what the worst day looks like. Protected copies, backup administration held apart from everyday accounts, recovery points you can actually use and a restore that has been tested belong in the first. Recovery priorities, response contacts, a way to communicate when the usual systems are unavailable and a clear view of who has to be notified belong in the second.

A firm with sound access control and a protected copy has better ransomware protection than one running a large security product with neither, and that is an argument for covering the work areas rather than for following a particular order. What the work costs depends on the systems in scope, what the business already licenses and how much human response is included, so treat the setup, the ongoing ransomware protection and the incident recovery scope as three separate questions.

Do Backups Protect You From Ransomware?

Only the ones an attacker cannot reach. Modern ransomware protection assumes the backup is a target, because the NCSC’s ransomware lifecycle puts destroying backups in the same phase as encrypting the data.

Ransomware protection diagram showing three connected backups reached by an attacker and one offline copy untouched

By that point an attacker may hold administrative credentials and have found the backup server, though not every attack gets that far or follows the same sequence. Where they do, the copies those accounts can reach are at risk, and they are often destroyed before the encryption starts so that recovery is not an option you still hold when the demand arrives. Being reachable on the network is not the same as being deletable, which is why ransomware protection treats permissions as seriously as connectivity.

Protect the recovery copies from everyday accounts and systems. Offline means disconnected, such as a drive unplugged between runs or tape in a cabinet. Immutable means protected against change or deletion for a defined period, and an immutable copy can still be online. The NCSC calls offline or disconnected copies critical to recovery. In ransomware protection terms, check who holds privileged access to the copies, what retention is set, and which keys and services you would need in order to restore.

Credentials matter as much as the media. Where the backup system signs in with the same administrator account used to run the network, one stolen password reaches the servers and the copies together. That is the single most common way a business discovers it has no recovery.

Immutable storage is widely available, though product support, configuration and retention all affect what it protects and what it costs. The copy can be written and read but not altered or deleted for a set period. Read the mode you are actually buying as part of your ransomware protection, because some implementations allow a privileged override and others do not, and that difference is the whole point of the control.

Cloud sync is not a backup for this purpose. A folder replicating to OneDrive or Dropbox is one copy in two places, so encryption on the laptop reaches the cloud copy within seconds. Versioning helps and it is not the same as a copy the attacker cannot touch.

Test the restore before you need it, because an untested backup is unproven recovery rather than recovery you can count on. NCSC guidance gives examples ranging from restoring a single file through to a full restoration, so agree a schedule that suits the systems you run and how fast they change. Test the right thing as well: restoring a document proves nothing about whether the job management system comes back, and a ransomware incident takes both.

How the copies are structured is a subject of its own, and our guide to a data backup strategy covers the model, the recovery numbers and the test schedule. Ransomware protection asks only one thing of it: could a compromised account delete this.

Should You Ever Pay a Ransomware Ransom?

The New Zealand Government strongly discourages it. Its guidance on cyber ransom payments asks victims to report every incident to the relevant agencies whether or not a ransom is paid.

The practical case against paying is simpler than the ethical one. A decryption key is not a restore, and firms that pay still spend weeks rebuilding, because the key unlocks files and does nothing about the compromised accounts, the persistence the attacker left behind or the machines that have to be rebuilt anyway.

Then a second demand follows. Data is copied out before anything is encrypted, so the first payment buys decryption and the second buys a promise not to publish. That promise comes from somebody who has already extorted you once.

Payment also has to come from somewhere, in cryptocurrency and at speed, and the practical questions around that reach your bank, your board and your insurer inside the first day. It does nothing for the obligations that follow either, because those apply from the moment personal information left the building.

There is no guarantee attached to any of it. The Government’s advice states plainly that payment does not guarantee you will get your data back, and warns that a payment to a group operating from a sanctioned state may breach the Russia Sanctions Act 2022 or the United Nations Act 1946. The people making the promise are running a business model, not a support desk.

Decide the position before an incident, not during one. A business that has already agreed it will not pay spends the first day restoring instead of arguing. Write the decision down and tell the people who would be in the room, because ransomware protection includes the position on payment, and that decision otherwise gets made badly, late, by whoever is most frightened.

Does Antivirus Stop Ransomware?

Not on its own, and it is not where an attack starts. Ransomware arrives through a stolen password on a remote access service or an unpatched internet-facing system, and neither of those is a file for antivirus to inspect.

The NCSC’s critical controls for ransomware are multi-factor authentication, security updates on internet-facing systems within 48 hours, application allowlisting, least privilege, network segmentation, backups, and logging and alerting on every pathway. Of endpoint tooling it says only that some products have had success in stopping the encryption process, and that this is not guaranteed. Ransomware protection that starts at the endpoint has skipped the places an attack is actually stopped.

Email is still the other common way in, and the controls that work there stop a credential being usable. Scanning attachments is the smaller half of the problem. Our post on email security covers that side.

Detection tools do their work once an attacker is already inside. They notice the credential dumping and the lateral movement in the days before encryption, and that window is where a ransomware attack can still be stopped.

Ransomware protection is layered because each layer fails differently, which is defence in depth applied to one attack type. Expecting a single product to replace the layers is the most common gap in small business ransomware protection.

Application allowlisting is the control small businesses are almost never offered, and it belongs in any serious ransomware protection plan. It stops software the business did not approve from running at all, which defeats most of the tooling an attacker deploys after getting in. It takes setup work, which is why it rarely gets proposed.

Ask your provider which of these ransomware protection controls is switched on, and get the answer in writing. A list of what is enabled, on which systems, is the document an insurer will ask for and the one most firms cannot produce. Review it whenever anything changes, because a new remote access tool or a server nobody decommissioned puts a fresh door in the wall, and ransomware finds those faster than the paperwork does.

How Long Does Ransomware Recovery Take?

Days to weeks for a business of thirty people with working backups, and longer without. The encryption itself is over in hours. The rebuild runs into the second week. Preventing that second week is the whole point of ransomware protection.

Ransomware recovery timeline showing hours of encryption against days of containment, rebuild and restore

The stages shown are illustrative rather than a schedule, because the sequence depends on which systems are affected. The order of the work is what makes it slow. You cannot restore into a network the attacker still has access to, so the compromised accounts are closed and the entry point is found before anything comes back, and skipping that step restores the problem along with the data.

Then the machines are rebuilt from scratch, because nobody can certify a cleaned machine afterwards. Forty workstations at an hour each is a week of somebody’s time before a single file is restored.

Insurance and legal notification run alongside all of it, and both want evidence you cannot produce while your systems are down. Keep contact details and the response plan on paper, because the copy on the file server will be encrypted with everything else.

Staff cannot work while any of this happens, and that bill is larger than the technical one. Thirty people unable to invoice for a week is the number to put in front of anyone who thinks ransomware protection is expensive.

Partial recovery is the outcome nobody plans for. Firms get the file server back quickly and then wait days for the line-of-business system, so decide now which systems have to come back first and in what order. The first hours decide most of the timeline, and that ground is covered in detail by our incident response plan.

Is a Ransomware Attack a Privacy Breach?

A ransomware incident can be a privacy breach if personal information is accessed, altered, destroyed or made unavailable, and the Privacy Commissioner gives information encrypted by ransomware as an example. You do not need proof that data was copied out before you assess the breach and the harm it could cause, and that assessment is part of ransomware protection rather than separate from it.

If the breach has caused, or is likely to cause, serious harm, notifying the Privacy Commissioner and the affected people as soon as practicable is a legal obligation under the Privacy Act 2020, subject to the exceptions the Act allows.

The Office of the Privacy Commissioner expects agencies to notify within 72 hours of becoming aware that a breach is notifiable, even while the investigation is still open. That figure is a guide rather than a statutory deadline, and it is not permission to wait either. Seventy-two hours is still short when the systems holding the evidence are encrypted, and the businesses that manage it are the ones who already knew what personal information they held and where it lived.

Affected people have to be told as well, and that conversation goes better coming from you than from a listing on a leak site.

Check contractual and sector duties separately, because their triggers and timing depend on the agreement and the law that applies. Client agreements in professional services and health sometimes set a shorter notification window than the Act does, so read what you have already promised before you need to act on it. Knowing those deadlines before an incident makes them urgent is part of ransomware protection.

Start the list now, while nothing is on fire: customer records, staff files, payroll, the job system and the mailboxes, with a note of what personal information each one holds. This is the part of ransomware protection that has nothing to do with technology, and it is knowing what you hold so that you can say what was taken.

Could You Run the Business Without Your Systems Tomorrow?

Most firms have never asked, and the answer is what ransomware protection is really buying. Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand.

Our cyber security team can review access security, endpoint protection, backup resilience and response arrangements across the systems in scope, then agree with you which improvements to prioritise. Putting a restore test on a schedule somebody signs is usually one of them.

Most of what we find is unremarkable. Multi-factor authentication switched on for email and not for the VPN, or a backup nobody has ever restored from. What each one takes to put right depends on the system it sits on, which is part of what the review establishes.

We would rather do that work on an ordinary Tuesday than meet you on the worst day of your year.

Frequently Asked Questions

What is ransomware protection?

Ransomware protection combines the measures that reduce the chance of an attack, limit how far it spreads, and help the business recover. It covers secure access, patching, endpoint protection, protected backups and a response people know how to follow. Treating prevention and recovery as one job is what separates it from buying a security product.

Can ransomware encrypt backups?

Yes, and backups are often targeted deliberately. Where an attacker gains administrative credentials, copies those accounts can reach are at risk and are frequently destroyed before the encryption starts. A disconnected or properly configured immutable copy is the one most likely to survive, so ransomware protection treats the backup as a target from the outset.

Should a business pay a ransom?

The New Zealand Government strongly discourages paying cyber ransoms. Payment does not guarantee recovery, the removal of attacker access or the protection of stolen information, and it may breach sanctions. A decryption key is not a restore either, so firms that pay still have machines to rebuild and compromised accounts to close, and further extortion is possible. Report the incident to Police and the NCSC, and if payment is being considered, get independent legal and professional advice and follow your own decision process.

Is Microsoft Defender enough to stop ransomware?

Endpoint protection can act before encryption, and it is not a ransomware protection strategy on its own. Be specific about which product and configuration you mean, because Defender Antivirus with behaviour monitoring is a different proposition from Defender for Business or Defender for Endpoint. Whichever you run, it does nothing about a stolen password used on remote access or an unpatched server facing the internet, so combine it with secure access, patching, protected backups and a response plan.

How does ransomware get into a business?

Phishing, password guessing, an exploited public-facing system, or malware delivered by email. Valid credentials used on remote access without a second factor are a common route, and exposed services attract opportunistic attacks, though the mix varies with the target and what the attacker is after. Attackers often move through the network before anything is encrypted. Ransomware protection is mostly about closing those doors and noticing the movement behind them.

What is immutable backup?

Immutable backup is storage that can be written and read but not changed or deleted for a set retention period. It is a practical answer to attackers deleting backups, but read the mode you are buying: some implementations allow a privileged override and others do not, and product support, configuration and retention all affect the ransomware protection you actually get and what it costs.

Do small businesses need ransomware protection?

Yes, and arguably more than a large one does. The software estate is often much the same and the supervision is not. Exposed services attract opportunistic attacks regardless of revenue, so a thirty person firm with an unprotected remote desktop is worth an attacker looking at, and ransomware protection has to work without a security team behind it.

Do you have to report a ransomware attack?

Reporting to the NCSC and to Police is recommended in every case, and that is separate from your legal duties. Where personal information has been accessed, altered, destroyed or made unavailable and serious harm has been caused or is likely, notifying the Privacy Commissioner is a legal obligation under the Privacy Act 2020, not a courtesy, and the affected people have to be told as well.

What is the first thing to do in a ransomware attack?

Stop using the affected devices, isolate them from the network where you can do that safely, and contact your incident response lead or IT provider immediately from a device you trust. Do not reconnect backups and do not start wiping systems. Follow the containment steps in your response plan, including whether a machine needs to be shut down to stop damage that is still happening. Memory can hold evidence worth preserving, so where shutting down is not needed to stop the spread, isolating the device is usually the better first move. The plan that tells you which applies is part of ransomware protection.

Does cyber insurance cover ransomware?

Cover depends on the policy, its exclusions and limits, and the circumstances of the incident. Read the conditions now, including which controls the insurer assumes you hold, and check the notification and consent requirements with your insurer or broker before you act, because approved response providers and recoverable expenses are often specified. Do not assume that one missing control decides a claim on its own. Insurers do ask what ransomware protection you hold, so keep the evidence current.

What does ransomware protection cost a small business?

It depends on what is being covered rather than on headcount. The drivers are the systems in scope, how exposed they are, the data volume and retention, the recovery the business needs, and how many hours of human response you are buying. Some of ransomware protection is configuration inside software you already licence. Other parts carry licensing, monitoring or support costs, and a managed response service is not usually included in an existing licence. Separate the setup, the ongoing protection and the incident recovery scope when you compare quotes.

Does Exodesk provide ransomware protection in New Zealand?

Yes. Exodesk has operated since 1989, with offices in Christchurch and Dunedin serving businesses across New Zealand. A review covers multi-factor coverage, patching, backup resilience and logging, and we agree with you which improvements to prioritise.

NEXT STEP

Not sure where your ransomware protection has gaps?

Talk to Exodesk about access security, endpoint protection, backup resilience and response arrangements. We can review the systems in scope and agree which improvements to prioritise.

Or read more about our managed IT services.

Start typing and press Enter to search

Data backup strategy banner showing three drives with one standing apart and unpluggedOutsourcing cybersecurity banner showing tasks moving between two buildings with one staying behind Call Us Now