Across Australia, cyber incidents continue to test the resilience of critical infrastructure and public services. While government agencies have strengthened their perimeter defences, the nature of risk has changed. Today, the question is not if an attack will happen – it’s how fast you can recover when it does.
For NSW Government leaders, this challenge is front and centre. As the State continues to digitise citizen services and modernise systems, the pressure to meet new mandatory resilience standards has intensified. True readiness now depends not only on technology, but on the speed and clarity of executive-level decision-making when systems go down, data is encrypted, and public confidence is at stake.
At Digital NSW 2025 showcase, Canary IT and Commvault co-hosted “Inside a Ransomware Crisis” – an executive simulation which was held over two exclusive sessions. Limited to a select number of executive attendees from various NSW Agencies and Departments, attendees were immersed in an interactive experience which recreated the critical hours of a ransomware attack. Facilitated by Commvault’s Security Field CTO for APAC, participants navigated real-world decision paths – from initial detection and containment to communication strategies and the ultimate ethical and financial dilemma: to pay or not to pay the ransom.
What makes this experience unique is its real-world applicability underpinned by collaboration with confidentiality. Conducted strictly under Chatham House Rules, the format ensures complete candour among peers, enabling genuine discussion about vulnerabilities, accountability, and policy coordination. Leaders can explore their response strategies in a safe environment, uncovering gaps that often only become visible under the pressure of a real event.
This focus on realism mirrors the insights from the latest Commvault State of Data Readiness Report. The findings paint a stark picture of the gap between expectation and operational reality:
80% of business leaders expect full recovery within five days, yet the average recovery time is four weeks.
70% have already faced a ransom demand, but only 32% managed to recover all their data.
54% admit they lack full visibility into the relationships, metadata, and configurations needed to restore operations after a breach.
These statistics underscore that resilience is not just about technology; it’s about governance, collaboration, and culture. The ability to operate effectively during a cybersecurity incident depends on how well leadership teams can align business expectations with IT reality, and how quickly they can act when minutes matter.
Canary IT showcased how we help public sector organisations build this alignment through the Resilience Ring – a holistic framework covering protection, response, recovery, and continuity. Together with Commvault, we demonstrated how a continuous improve cycle of controls for automation, immutability, and rapid cloud recovery can transform how agencies safeguard critical services and data sovereignty.
We invite you to connect with Canary IT and Commvault to see how proactive resilience can protect what matters most: continuity of service, public trust, and data integrity.



