Ransom paid, data still lost – and brokers are asking the wrong question
Three questions every NZ cyber renewal is missing
Ransom paid, data still lost – and brokers are asking the wrong question
CYBER
By Roxanne Libatique
13 Aug 2026

More than one in three organisations across Australia and New Zealand that paid a ransomware demand still failed to recover their data. That is not a cybersecurity statistic. It is a claims outcome - and it points to a question most brokers are not yet asking at renewal.

Commvault published its State of Data Resilience ANZ 2026 report on August 12, drawing on responses from 411 organisations including chief information officers, chief information security officers, IT leaders, and IT decision-makers. It found that 34% of organisations in Australia and New Zealand that experienced a ransomware attack paid the ransom. Of those that paid, 36% reported the payment failed - because attackers either withheld access to data or returned with further demands, according to Security Brief New Zealand's reporting on the study.

The report also provides a New Zealand-specific figure: 63% of New Zealand organisations have defined the minimum business functions needed to keep operating during a cyber crisis - slightly more than the 60% recorded in Australia - yet fewer than half across both markets had mapped the technology environments required to support those functions. The average recovery time to a minimal operational level remains 28 days, down from 42 days in 2023, but still well in excess of the one-day restoration that more than 80% of executives across both countries say they expect.

The gap underwriters are not closing

The Commvault research found that confidence in the integrity and completeness of backups was a significant factor in whether organisations paid a ransom at all. The findings suggest that uncertainty over whether systems and data could be restored without attackers' assistance directly influences ransomware response decisions.

Arctic Wolf's 2025 Cyber Insurance Outlook - based on responses from more than 400 cyber insurance brokers and carrier professionals worldwide - found that organisations must meet a minimum of six security controls to qualify for cyber insurance coverage, with data backups among the controls considered in underwriting assessments. That is a global benchmark, not an ANZ-specific requirement, but it reflects the direction in which underwriting standards are moving across markets including New Zealand.

The problem, as the Commvault failure rate illustrates, is that confirming a backup exists and confirming it will work under incident conditions are different questions. Geordie Stewart, chief information security officer at NSP, made the distinction precisely when presenting to the Insurance Brokers Association of New Zealand (IBANZ) in 2026: "Having a control isn't the same as having an effective control. That's the most common reason cyber claims fail."

Stewart's observation applies directly to backups. Ransomware operators routinely target and corrupt backup systems before deploying encryption. An immutable backup - one that cannot be altered or deleted even by an administrator - is what insurers now require, not simply a backup. A system that has never been restored under realistic conditions offers an untested assumption, not a demonstrated recovery capability.

Where the cost accumulates

Adelphi Insurance Brokers' 2026 New Zealand cyber market review found that ransomware claims in New Zealand declined slightly in frequency in 2025 but increased in severity and cost, with business interruption costs the primary driver. Globally, CRC Group data found that business interruption claims are on average more than 650% more costly than claims without interruption losses, with ransomware behind approximately 81% of them. The 28-day average recovery window in the Commvault data gives those figures local context. If an insured organisation has not identified which systems must come back online first, the business interruption clock runs longer, the claim cost compounds, and the ransom payment - even where it fails - sits on top.

Martin Creighan, vice president, Asia-Pacific at Commvault, said the pattern reflects a preparedness gap rather than a crisis management failure. "Too many organisations are still treating ransomware as a decision they'll make on the day. By the time you're deciding whether to pay, you've already lost control of the situation. True resilience comes from building robust recovery capabilities and regularly testing them well before an attack occurs, not during one," Creighan said.

Gareth Russell, field CTO, security, Asia-Pacific at Commvault, said organisations need to shift how they frame recovery planning. "The conversation needs to shift from 'How do we recover everything?' to 'What must we recover first?' Organisations that define their Minimum Viable Company before an attack know exactly which people, applications, systems, and data keep the business operating, and they've already proven they can recover them. That's how you reduce downtime, remove uncertainty, and avoid treating ransomware payments as a recovery strategy," Russell said.

Paying does not discharge legal obligations

A ransom payment does not remove an organisation's privacy breach notification obligations. Under New Zealand's Privacy Act 2020, organisations must notify the Office of the Privacy Commissioner (OPC) as soon as practicable after becoming aware of a notifiable privacy breach, and must also notify affected individuals unless an exception applies. The OPC's guidance sets 72 hours as the expected notification window - a guide rather than a statutory deadline, but one the Commissioner has made clear it treats as the standard for prompt notification.

The OPC's 2025 Annual Report recorded 1,093 privacy breach notifications during the year, a 27% increase on the previous year. Rising volumes suggest the OPC is tracking compliance more actively, which raises the stakes for any organisation that pays a ransom, fails to recover data, and then delays notification on the assumption the payment resolved the situation.

On ransom payments themselves, Cabinet has formalised a policy that government agencies will not pay cyber ransoms - confirmed in April 2023 - and the Department of the Prime Minister and Cabinet strongly discourages private sector payment. A ransom payment may breach the Russia Sanctions Act 2022 or the United Nations Act 1946, with criminal penalties of up to seven years imprisonment and fines of up to $1 million for organisations. The government's Cyber Security Strategy 2026-2030, released in February 2026, estimated cybercrime costs New Zealanders more than $1.6 billion annually.

The National Cyber Security Centre recorded $26.9 million in direct financial losses from cyber incidents across New Zealand in the 2024/25 financial year. Its Cyber Security Insights report for Q1 2026 recorded $5.6 million in direct financial losses across 1,164 incidents in a single quarter - a 76% increase on the $3.2 million recorded in Q4 2025.

Three questions for every cyber renewal

The combined picture - failed ransom payments, 28-day recovery windows, rising business interruption severity, and tightening underwriting criteria - has a practical implication for every broker working with cyber-insured clients in New Zealand. The question at renewal is not whether a client has backups. It is whether those backups are immutable, whether they have been restored under realistic conditions within the past 12 months, and whether the client has documented which systems and functions must come back online first. Those answers determine how long a business interruption claim runs, whether a ransom payment becomes a claims conversation rather than a recovery tool, and whether the extortion sub-limit in a client's policy reflects actual exposure - or an assumption that has never been tested.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB NZ.