HomeBlog › Cybersecurity

Ransomware Protection Perth — What Small Businesses Actually Need

19 June 2026·5 min min read· Cybersecurity

Picture this: it's Monday morning. You're a bookkeeper in Subiaco, or maybe you run a plumbing business out of Joondalup. You open your laptop, go to pull up last week's invoices, and instead you get a black screen with white text telling you every file on the machine has been encrypted. There's a Bitcoin address. There's a countdown timer. And there, in the corner of your eye, you can see the backup drive you plugged in on Friday — also encrypted.

That's not a hypothetical. It's a pattern the ACSC reports regularly, and Perth businesses are not exempt from it.

This post covers what ransomware protection for Perth businesses actually looks like in practice — not in theory, not in a vendor pitch deck, but as a working set of layers you can implement before the ransom note appears.

What Ransomware Actually Does (and Why Paying Doesn't Help)

Ransomware is malware that encrypts your files and holds them hostage. The attacker demands payment — usually cryptocurrency — in exchange for a decryption key. The whole thing can happen in under an hour once the malware executes.

Here's what most business owners don't know until it's too late:

Paying doesn't guarantee you get your files back. The ACSC explicitly advises against paying ransoms. There's no contract, no customer service, no refund policy. Some attackers take the money and disappear. Others provide a decryption key that only partially works. And a growing number use double extortion — they encrypt your files and exfiltrate them first, so even if you recover your data, they're threatening to publish it.

That second part matters for Australian businesses operating under the Privacy Act 1988. If ransomware actors exfiltrate data that includes personal information about your clients, you may have a notifiable data breach on your hands under the Notifiable Data Breaches (NDB) scheme — regardless of whether you pay the ransom.

Why Small Perth Businesses Are Targeted

There's a persistent myth that small businesses are too small to be worth attacking. The reality is the opposite.

Small businesses are targeted precisely because they're under-defended. A criminal operation doesn't want to spend six months probing the perimeter of a large enterprise with a dedicated security team. They want a business that's running unpatched software, has no endpoint protection beyond Windows Defender's default settings, and keeps its backup on the same server as its live data.

ACSC data consistently shows SMBs account for a significant share of ransomware incidents reported in Australia. Perth businesses face the same threat landscape as businesses anywhere else — and they often face it with less preparation.

The Four Layers That Stop Most Ransomware

You don't need a $50,000 security stack. You need four things done properly. Most Perth SMBs who've survived a ransomware attempt had at least three of these in place. Most who didn't survive had none.

Layer 1: Endpoint Protection That's Actually Configured

The default Windows Defender installation on most Windows PCs is better than nothing, but it's not the same as Microsoft Defender for Business. Defender for Business is a managed endpoint protection platform designed specifically for organisations with fewer than 300 users. It includes attack surface reduction rules, behavioural monitoring, and centralised management — things the consumer version doesn't have.

What this means practically: when ransomware starts encrypting files, Defender for Business can detect the behavioural pattern and stop execution before it gets to your critical data. Consumer antivirus products — even good ones — tend to rely more heavily on signature matching, which means newly deployed ransomware variants can get through.

If you're running PCs with the out-of-box Windows security settings and calling it "covered", that's a gap worth fixing.

Layer 2: Patch Everything, Consistently

The majority of ransomware attacks exploit known vulnerabilities — software weaknesses that already have a patch available. Attackers rely on the fact that most businesses apply patches slowly, inconsistently, or not at all.

Essential Eight Maturity Level 1 — the ACSC's baseline cybersecurity framework — requires patching applications and operating systems within one month of release for non-critical patches, and within 48 hours for critical ones. That's not an ambitious standard. It's a baseline.

The practical implementation for a small business looks like:

  • Automatic Windows Update configured and verified — not just turned on and forgotten
  • Microsoft 365 apps updating automatically
  • Third-party applications — browsers, PDF readers, accounting software — on a managed update schedule
  • Firmware updates for routers and network devices on the calendar

Your IT support company should be verifying this regularly, not just checking a box at setup and moving on.

Layer 3: Restrict Admin Rights

This one has an outsized return on investment relative to how easy it is to implement. Restricting admin rights means that standard users on your network can't install software, change system settings, or modify core files — which also means ransomware running under their user account can't do those things either.

Most ransomware needs elevated privileges to encrypt files across the entire system and spread laterally to other machines on the network. If it executes under a standard user account without admin rights, its blast radius shrinks dramatically. It might still encrypt files in that user's local folder, but it won't reach your shared drives, your server, or other workstations.

The argument against restricting admin rights is always "it's inconvenient". Yes, it is. It's considerably less inconvenient than rebuilding your entire file server from scratch.

Need a hand with this?

Perth IT Care can sort it out for you. No jargon, no runaround.

Get in touch