Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

Teal shield with tick and network nodes on dark navy background with the label Cyber Strategy

Ransomware Crews Have Started Reading Your Org Chart

New research from Zscaler's ThreatLabz, reported by The Register, tracked 351 victims across 334 organisations in a single month-long ransomware campaign, and the crews weren't chasing the CEO. Nearly two-thirds of the people they went after held manager-level titles or above, the average target was 46, and three-quarters worked in accounting, finance, sales, operations, HR or marketing.

In one month-long campaign: 351 victims, 334 organisations. Two-thirds were manager-level or above. Three-quarters worked in finance, accounting, sales, operations, HR or marketing.

The reframe is worth sitting with. Security teams have spent years locking down technical privilege: the admin accounts that hold the keys to the servers. Attackers have quietly moved to what Zscaler calls business privilege: the person who approves invoices, signs supplier contracts, sees the payroll file, or can push a payment through before anyone asks a second question. In a typical Australian small business that person isn't in IT at all. They're the office manager at a Northern Beaches venue, the finance officer at a Central West not-for-profit, or the practice manager at a wealth firm.

Here's the pattern we see in client environments: it's almost always the busy, trusted, long-tenured staffer who gets picked, not the newest hire, because they can make things happen quietly. Attackers map exactly who that is from LinkedIn and a compromised mailbox well before the ransom note ever lands.

What to Actually Do About It

  • Work out who holds "business privilege" in your organisation: who can move money or change bank details, and make sure a second person signs off on every request.
  • Give those roles your strongest protection: phishing-resistant MFA and tighter mailbox rules, not just the IT admins.
  • Verify any unusual payment or contract request out-of-band, by phone, on a number you already have stored, not one supplied in the email itself.
  • Run the "what if this account was taken over" drill, not just the "what if we get encrypted" scenario.

Encryption is the part victims notice. The quiet reconnaissance beforehand is the part that decides how bad it gets. We help Australian businesses put the right controls around the people who actually carry the risk, not just the server room. If you're not sure who your business-privilege users are, our cybersecurity team can map it with you.

Related guide: Cybersecurity for Sydney SMBs: our complete guide to protecting your business from cyber threats.

Sources

Written by Dan Briggs, Head of Relationships, All IT Services. All IT is a Sydney-based managed IT provider supporting businesses across financial services, hospitality, and not-for-profit sectors from its Brookvale base.


Frequently Asked Questions: Ransomware and Business Privilege

"Business privilege" refers to the access and authority that allows someone to move money, approve payments, change supplier bank details, access payroll, or authorise contracts, without needing IT-level system access. Ransomware crews now target these individuals specifically because compromising one business-privilege account can yield a fraudulent payment or data theft faster and more reliably than exploiting a technical vulnerability.
According to Zscaler's ThreatLabz research, the most targeted individuals are managers aged around 46, working in accounting, finance, sales, operations, HR or marketing. They tend to be long-tenured, trusted staff who can approve payments or take action without significant oversight. In Australian SMBs this is often an office manager, finance officer, practice manager, or department head.
CEOs are increasingly well-protected and scrutinised. Middle managers hold significant business authority but typically receive less security training and fewer protections. Attackers also find that managers are more likely to act quickly on a request from a perceived superior without asking questions, and their accounts receive less monitoring than C-suite accounts.
Start by identifying who holds business privilege in your organisation: anyone who can approve payments, change bank details, or authorise contracts. Apply phishing-resistant MFA to those accounts, implement two-person sign-off for financial requests, require out-of-band verification (a phone call to a known number) for any unusual payment or supplier change, and run tabletop exercises based on account-takeover scenarios rather than just ransomware encryption events.

Not Sure Who Your Business-Privilege Users Are?

Our cybersecurity team can map the accounts that carry real financial risk in your business and help you put the right protections in place.


Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →