In the space of three weeks this September, ransomware groups have posted extortion claims against a South Australian farm machinery supplier, a hardware conglomerate, and a commercial kitchen manufacturer in New South Wales. None of them are large enough to have made national news under normal circumstances. All of them are exactly the size and profile of a typical Perth SMB. If your business doesn't already have a written incident response plan, that's the actual takeaway: decide now, while nothing is on fire, who you call first and what happens in the first hour — because new Australian research shows most businesses haven't.
Three claims in three weeks
Ransomware groups increasingly run their own "leak sites" — pages on the dark web where they name victims and threaten to publish stolen data unless a ransom is paid. Three recent postings show how far down the size scale this now reaches:
- 4 September — the newly emerged Storm group listed a South Australian farm machinery supplier, publishing sample documents as proof and threatening a full data release.
- 15 September — the group calling itself The Gentlemen claimed an attack on an Australian hardware conglomerate, posting an extortion notice threatening to leak sensitive data.
- 16 September — the Kairos group named a commercial kitchen manufacturer in New South Wales on its leak site.
None of these three claims had been publicly confirmed by the businesses involved, regulators, or mainstream media as this article was written. That unconfirmed status is worth sitting with for a moment, because it's not actually the reassurance it sounds like.
Why "unconfirmed" doesn't mean "not real"
A leak-site posting is itself the attack's second stage. The group has already been inside the network, already exfiltrated whatever it wanted, and is now using public pressure — customers, suppliers and staff seeing the company's name on a leak site — to push toward payment. Whether the business confirms it publicly changes nothing about what already happened; it only changes how the story is managed from here. For a small business without a plan, that management happens in a panic, in public, in real time.
This is also precisely why "we're too small to be a target" keeps being wrong. None of the three businesses above are household names. A farm machinery dealer and a commercial kitchen manufacturer are ordinary trading businesses, not the kind of high-profile target that makes headlines — which is exactly the profile modern ransomware crews go after, because smaller businesses are less likely to have tested backups, a written response plan, or 24/7 monitoring.
The research backs it up
New research commissioned by Optus and conducted by Ipsos in 2026 surveyed Australian sole traders and small businesses and found:
- Only 40% of small businesses prioritise cybersecurity.
- 35% have already experienced a cyberattack.
- 60% have no cyber response plan at all.
Put those together and the picture is stark: more than a third of small businesses have already been hit, but nearly two-thirds still haven't decided in advance what they'll do if it happens again — or happens to them for the first time.
What an incident response plan actually contains
A response plan doesn't need to be a fifty-page document. For a business our size, it needs to answer a short list of questions clearly enough that any staff member can act on it under pressure:
Who gets called first
Your IT provider, your cyber insurer (if you have a policy), and your lawyer's contact details, written down somewhere that doesn't depend on the compromised network to access.
What NOT to do
Don't unplug, reformat, or "just delete the weird file" before anyone qualified has looked at it. Isolating a machine from the network is usually right; wiping it destroys the evidence needed to understand how the attacker got in and whether they're still inside anywhere else.
Whether your backups actually work
A backup that's never been test-restored is a hope, not a plan. If a server dies or gets encrypted, the business needs to know — in advance, not on the day — how long a restore actually takes and how much data would be lost.
Who decides on paying a ransom
This should never be improvised by whoever happens to answer the phone at 2am. Decide the process — legal advice, insurer involvement, law enforcement notification — before there's a countdown timer on screen.
How you'll talk to staff and customers
A short, pre-agreed line for "what do we tell people" removes one more decision from an already overloaded moment, and stops mixed messages going out while the situation is still being assessed.
We've written before about what we actually do in the first hour of a ransomware incident — that post covers the response itself. This one is about the part that happens before any of that: deciding the plan while you have the luxury of time to think clearly.
Perth businesses aren't exempt
Ransomware crews don't check postcodes. The businesses named on leak sites this month were spread across South Australia and New South Wales, but there's nothing about a farm machinery supplier or a kitchen manufacturer that makes them more attractive targets than a Perth accounting firm, trades business, or medical practice. The profile that matters to an attacker is opportunity, not location: outdated software, no multi-factor authentication, and no tested backup.
Getting started
If your business has been meaning to formalise an incident response plan but hasn't got around to it, this is as good a prompt as any. We can help assess where the gaps are — from backup and disaster recovery through to broader IT security — and put a written plan in place before it's needed rather than while it's being tested for real. Computer Mechanics has supported Perth businesses since 1997; see why local businesses choose us to work through cybersecurity planning properly.



