A Third Hit, Yet Almost Everyone Feels Safe

RSM Australia's 2026 Cyber Security Report has surfaced a gap between perception and reality that should concern anyone whose personal data sits inside a medium or large organisation. The report, based on a survey of 155 medium-to-large Australian organisations, found that roughly a third experienced a ransomware attack or extortion attempt over the past year. Despite that, 97% of respondents still believe their organisation's data is adequately protected.

That disconnect matters beyond the boardroom. When a ransomware attack succeeds, it is rarely just the company's own files that are locked or stolen. Customer records, employee data, health information and financial details often ride along, and the confidence gap RSM has identified suggests many organisations are not treating that risk with the urgency the numbers demand.

Why the 'Big End of Town' Is Falling Behind

One of the more counterintuitive findings buried in RSM's data is that larger organisations are lagging behind their mid-sized counterparts when it comes to cyber security readiness. Conventional wisdom holds that bigger companies have bigger budgets, dedicated security teams and more mature governance. According to this report, that assumption doesn't always hold up in practice.

This pattern isn't unique to Australia. Larger, more complex organisations often carry legacy systems, sprawling vendor relationships and layers of bureaucracy that slow down security decisions, even when resources are available. The IBM Italy subsidiary breach linked to Chinese cyber operations is a reminder that scale and reputation don't automatically translate into resilience. Large organisations managing critical infrastructure can still be exposed through subsidiaries, contractors or overlooked systems, exactly the kind of complexity that smaller, more nimble organisations tend to avoid simply because they have fewer moving parts to secure.

The Privacy Cost of Ransomware Isn't Just the Ransom

It's easy to think of ransomware purely as a business continuity problem: files get encrypted, operations stall, a ransom demand arrives. But modern ransomware campaigns increasingly pair encryption with data theft, meaning attackers steal sensitive information before locking systems, then threaten to publish or sell it regardless of whether a ransom is paid.

That double-extortion model is precisely why the privacy implications of RSM's findings deserve more attention than they typically get. Every organisation that stores customer names, addresses, payment details or health records is effectively holding privacy risk on behalf of the people it serves. When ransomware operators pursue payment, they are increasingly monetising the personal data of employees, customers and patients, not just corporate secrets. Healthcare and medical device companies illustrate this well. Incidents like the iRhythm June 2024 data breach affecting cardiac patients and the related iRhythm breach involving third-party cloud applications show how attacks on a single organisation can expose deeply sensitive personal health information, sometimes through vendors and cloud services the affected individuals never even knew were involved.

The human toll of ransomware extends further still. Behind every high-profile extortion case are negotiators, investigators and sometimes criminal prosecutions, as seen in the case of a Florida ransomware negotiator convicted in a US extortion case. These cases underline that ransomware isn't an abstract technical threat. It's an organised criminal enterprise with real financial and legal consequences on both sides of the transaction.

What This Means For You

If you're an employee, customer or patient of a medium-to-large Australian organisation, this report is a useful prompt to recalibrate your expectations. A one-in-three chance of ransomware impact within the surveyed group is a meaningful figure, and the 97% confidence rate suggests many organisations may not be communicating breach risks clearly, or may not fully grasp their own exposure.

For individuals, the practical response isn't panic, it's preparation. Assume that any organisation holding your data could eventually be targeted, and adjust your habits accordingly: use unique passwords for sensitive accounts, enable multi-factor authentication wherever it's offered, and pay attention to breach notifications rather than dismissing them as routine noise.

For organisations, RSM's findings are a clear signal that self-assessed confidence is a poor substitute for tested resilience. Regular penetration testing, incident response drills and honest board-level reporting on cyber risk matter far more than internal perception surveys.

Key Takeaways

  • RSM Australia's 2026 Cyber Security Report found roughly one in three of 155 surveyed medium-to-large organisations experienced a ransomware attack or extortion attempt in the past year.
  • Despite that exposure, 97% of respondents still believe their data is adequately protected, a gap that suggests widespread overconfidence.
  • Larger organisations appear to be falling behind mid-sized ones in cyber readiness, challenging assumptions that bigger budgets guarantee better security.
  • Ransomware increasingly involves data theft alongside encryption, meaning personal and health information is frequently at risk even when a ransom isn't paid.
  • Individuals should treat breach notifications seriously and strengthen personal account security regardless of how confident an organisation claims to be about its defences.

Ransomware in Australia isn't a fringe risk confined to a handful of unlucky companies. It's a statistically common event for medium-to-large organisations, and the confidence gap RSM has documented is arguably as newsworthy as the attacks themselves. Staying informed about how these incidents unfold, and how organisations respond to them, remains one of the simplest ways to protect your own data in the meantime.