TL;DR: The ASD ACSC’s 2024-2025 threat report shows ransomware remains Australia’s most disruptive cybercrime threat, critical infrastructure alerts rose 111% year on year, and healthcare/social assistance incidents succeeded in 95% of cases, according to Airlock Digital’s analysis. The operating lesson is that deny-by-default execution controls matter when attackers can blend into trusted software paths.
NHIMG editorial — based on content published by Airlock Digital: Cyber Threats on the Rise ASD ACSC Report showcases rise in ransomware, state sponsored threat actors and healthcare targeting
By the numbers:
- The ASD ACSC responded to 138 ransomware incidents in FY2024-25, and 39% were cases where the agency contacted the entity to warn of a possible cyber security incident.
- The ASD ACSC notified critical infrastructure entities of potential malicious cyber activity impacting their networks over 190 times in 2024-2025, up 111% from the previous year.
- Malicious actors were successful in 95% of healthcare and social assistance incidents the ASD ACSC responded to in 2024-2025.
Questions worth separating out
Q: How should security teams detect ransomware before encryption starts?
A: Security teams should watch for identity anomalies that precede encryption, such as unusual administrative logins, privilege changes, remote tool use, and access to directory or backup systems.
Q: Why do living off the land techniques make ransomware harder to contain?
A: They reuse built-in tools and legitimate admin utilities, which can make attacker activity look like normal operations.
Q: What breaks when application control exceptions are too broad?
A: Broad exceptions turn a prevention control into a partial filter.
Practitioner guidance
- Implement deny-by-default execution policies Start by restricting software execution to approved publishers, hashes, or application paths on the highest-risk systems, then expand coverage in phases to servers, laptops, and OT-adjacent endpoints.
- Audit living off the land exposure Identify which native tools, scripts, and admin utilities can be abused for execution, persistence, or lateral movement, then narrow who can invoke them and under what conditions.
- Tighten exception governance for critical services Review any application allowlist exceptions, temporary approvals, and operational overrides on healthcare, energy, and other essential service assets as time-bound risk decisions.
What's in the full article
Airlock Digital's full blog covers the operational detail this post intentionally leaves for the source:
- The report-specific breakdown of the ASD ACSC findings and how the vendor maps them to application control use cases.
- More detail on Deny by Default enforcement patterns and how they are applied across different endpoint populations.
- Implementation guidance for extending protection across IT and OT systems without weakening software trust governance.
- A fuller discussion of execution logging and how immutable records support investigations and compliance.
👉 Read Airlock Digital's analysis of ransomware, critical infrastructure, and healthcare targeting →
Ransomware, critical infrastructure, and healthcare: what teams need now?
Explore further
Execution control is becoming a resilience control, not just an endpoint hardening measure. Ransomware is no longer only about malicious files reaching a machine. When attackers can abuse legitimate software paths, the boundary between prevention and resilience collapses. Application allowlisting, signer governance, and exception discipline now sit in the same risk conversation as backup strategy and recovery testing. Practitioners should treat executable trust as a board-level resilience issue, not an endpoint niche.
A question worth separating out:
A: Yes. Critical services often include legacy systems, OT dependencies, and availability constraints that make blanket policy harder to apply. Teams should use tighter change governance, more granular allowlists, and clearer ownership for exceptions. The goal is to keep essential systems running without turning operational necessity into permanent software trust.
👉 Read our full editorial: Ransomware and healthcare targeting are rising across critical sectors