Ransom paid, data still lost – and brokers are asking the wrong question

The real risk sits in a gap that most renewal conversations never reach

Ransom paid, data still lost – and brokers are asking the wrong question

Cyber

By Roxanne Libatique

More than one in three organisations across Australia and New Zealand that paid a ransomware demand still failed to recover their data. That is not a cybersecurity statistic. It is a claims outcome – and it points to a question most brokers are not yet asking at renewal. Data protection company Commvault published its State of Data Resilience ANZ 2026 report on August 12, 2026, showing that 34% of organisations in Australia and New Zealand that experienced a ransomware attack paid the ransom. Of those that paid, 36% reported the payment failed – because attackers either withheld access to data or returned with further demands, according to Security Brief New Zealand. The survey drew on responses from 411 organisations, including chief information officers, chief information security officers, IT leaders, IT decision-makers, and their direct reports.

The report also provides a New Zealand-specific figure: 63% of New Zealand organisations have defined the minimum business functions needed to keep operating during a cyber crisis – slightly more than the 60% recorded in Australia – yet fewer than half across both markets had mapped the technology environments required to support those functions, according to iTWire’s reporting on the study. The average recovery time to a minimal operational level remains 28 days, down from 42 days in 2023, but still well in excess of the one-day restoration that more than 80% of executives across both countries say they expect.

The gap underwriters are not closing

The Commvault research found that confidence in the integrity and completeness of backups was an important factor in organisations’ decisions about whether to pay a ransom. The findings suggest that uncertainty over whether systems and data could be restored without attackers’ assistance can influence ransomware response decisions. Arctic Wolf’s 2025 Cyber Insurance Outlook, based on responses from more than 400 cyber insurance brokers and carrier professionals worldwide, found that organisations in Australia and New Zealand must meet a minimum of six security controls to qualify for cyber insurance coverage. The report identified data backups among the security controls considered in cyber insurance underwriting.

The problem, as the Commvault failure rate illustrates, is that confirming a backup exists and confirming it will work under incident conditions are different questions. Geordie Stewart, chief information security officer at NSP, made the distinction precisely when presenting to the Insurance Brokers Association of New Zealand (IBANZ) in 2026: “Having a control isn’t the same as having an effective control. That’s the most common reason cyber claims fail.”

Stewart’s observation, drawn from working with New Zealand organisations through cyber incidents and insurance assessments, applies directly to backups. Ransomware operators routinely target and corrupt backup systems before deploying encryption. An immutable backup – one that cannot be altered or deleted even by an administrator – is what insurers now require, not simply a backup. A system that has never been restored under realistic conditions offers an untested assumption, not a demonstrated recovery capability.

Where the cost accumulates

Adelphi Insurance Brokers’ 2026 New Zealand cyber market review found that ransomware claims in New Zealand declined slightly in frequency in 2025 but increased in severity and cost, with business interruption costs – including lost income during an outage and additional expenses to keep operations running and restore normal activities – the primary driver of claim costs. Globally, CRC Group data found that business interruption claims are on average more than 650% more costly than claims without interruption losses, with ransomware behind approximately 81% of them. The 28-day average recovery window in the Commvault data gives those figures local context. If an insured organisation has not identified which systems must come back online first, the business interruption clock runs longer, the claim cost compounds, and the ransom payment – even where it fails – sits on top.

Martin Creighan, vice president, Asia-Pacific at Commvault, said the pattern reflects a preparedness gap rather than a crisis management failure. “Too many organisations are still treating ransomware as a decision they’ll make on the day. By the time you’re deciding whether to pay, you’ve already lost control of the situation. True resilience comes from building robust recovery capabilities and regularly testing them well before an attack occurs, not during one,” Creighan said, as reported by Security Brief New Zealand.

Gareth Russell, field CTO, security, Asia-Pacific at Commvault, said organisations need to shift how they frame recovery planning. “The conversation needs to shift from ‘How do we recover everything?’ to ‘What must we recover first?’ Organisations that define their Minimum Viable Company before an attack know exactly which people, applications, systems, and data keep the business operating, and they’ve already proven they can recover them. That’s how you reduce downtime, remove uncertainty, and avoid treating ransomware payments as a recovery strategy,” Russell said.

Paying does not discharge legal obligations

A ransom payment does not remove an organisation’s privacy breach notification obligations. Under New Zealand’s Privacy Act 2020, organisations must notify the Office of the Privacy Commissioner (OPC) as soon as practicable after becoming aware of a notifiable privacy breach and must also notify affected individuals unless an exception applies. The OPC’s expectation is that organisations notify it within 72 hours of becoming aware that a breach is notifiable. The OPC’S 2025 Annual Report recorded 1,093 privacy breach notifications during the year, a 27% increase on the previous year.

On ransom payments, Cabinet has agreed that government agencies will not pay cyber ransoms – a policy formalised in April 2023 – and the Department of the Prime Minister and Cabinet (DPMC) strongly discourages private sector payment, noting that paying a ransom may breach the Russia Sanctions Act 2022 or the United Nations Act 1946, with criminal penalties of up to seven years imprisonment and fines of up to $1 million for organisations. The government’s Cyber Security Strategy 2026-2030, released by the DPMC in February 2026, estimated cybercrime costs New Zealanders more than $1.6 billion annually.

The National Cyber Security Centre (NCSC) recorded $26.9 million in direct financial losses from cyber incidents across New Zealand in the 2024/25 financial year, according to the NCSC’s Cyber Threat Report 2025. The NCSC's Cyber Security Insights report for Q1 2026 recorded $5.6 million in direct financial losses across 1,164 incidents in a single quarter, a 76% increase on the $3.2 million recorded in Q4 2025.

The renewal conversation this data demands

The combined picture – failed ransom payments, 28-day recovery windows, rising business interruption severity, and tightening underwriting criteria – has a practical implication for every broker working with cyber-insured clients in New Zealand. The question at renewal is not whether a client has backups. It is whether those backups are immutable, whether they have been restored under realistic conditions within the past 12 months, and whether the client has documented which systems and functions must come back online first. Those answers determine how long a business interruption claim runs, whether a ransom payment becomes a claims conversation rather than a recovery tool, and whether the extortion sub-limit in a client’s policy reflects their actual exposure – or an assumption that has never been tested.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!