As cyber threats continue to evolve, understanding the landscape of ransomware attacks becomes crucial for organizations aiming to bolster their defenses against these disruptive incursions. In 2024, Sophos Ltd. undertook a comprehensive survey involving 5,000 IT and cybersecurity leaders across 14 countries, focusing on the experiences of 855 professionals from mid-sized organizations in the United States. This survey sheds light on the shifting dynamics of ransomware threats and their implications for U. S. organizations.
For current context, Verizon's 2025 Data Breach Investigations Report found ransomware present in 44% of all breaches, up from 32% the year before, and in 88% of breaches at small and mid-sized businesses. IBM's 2025 Cost of a Data Breach Report put the global average breach cost at $4.44 million, with the U.S. average at a record $10.22 million.
Key Findings from the Latest Survey
Decrease in Ransomware Incidence
The survey reveals a notable decrease in the incidence of ransomware attacks in the U. S., with 58% of organizations reporting attacks, down from 68% in 2023. This aligns with the global trend, where 59% of organizations experienced ransomware attacks in the last year.
Impact and Attack Vectors
On average, 44% of an organization's computers were affected during these attacks, slightly lower than the global average of 49%. The primary vectors for these attacks were compromised credentials, accounting for 33% of incidents, followed closely by exploited vulnerabilities at 32%.
Data Encryption and Theft
A significant 58% of the attacks led to data encryption, below the global average of 70%. Moreover, in instances where data was encrypted, 39% also involved data theft, indicating a higher risk compared to the global average of 32%.
Backup Compromise and Recovery
An alarming 94% of attacks targeted organizational backups, with 66% of these attempts being successful. Notably, 95% of U. S. organizations managed to recover their data, although this is slightly lower than the global recovery rate.
Ransom Demands and Payments
The financial implications of these attacks are stark. The average initial ransom demand stood at $5.2 million, with the median at $3 million. Eventually, U. S. organizations paid, on average, 81% of the demanded ransom. This percentage is notably lower than the global average, where 94% of the initial demand was paid.
Recovery Costs and Durations
Excluding ransom payments, the average cost of recovery from a ransomware attack was $2.91 million. Recovery times have also increased, with only 36% of organizations fully recovering within a week, a decrease from 45% in the previous year.
Law Enforcement Engagement
A positive note is that 98% of ransomware victims reported the attack to law enforcement, with a majority finding the engagement process straightforward and helpful.
Recommendations for Organizations
Given the evolving nature of ransomware attacks, organizations are urged to enhance their cyber resilience through:
- Prevention: Ensuring robust access controls and minimizing vulnerabilities to prevent unauthorized access.
- Protection: Implementing strong foundational security measures, especially at endpoints, to thwart ransomware attempts.
- Detection and Response: Quickly detecting and neutralizing threats within the network to prevent data compromise and backup encryption.
- Planning and Preparation: Developing and rehearsing an effective incident response plan to ensure a swift and coordinated response to cyber incidents.
Conclusion
The most recent State of Ransomware survey highlights both challenges and successes in the fight against ransomware in the U. S. While the incidence of attacks has decreased, the sophistication and impact of successful attacks have grown. It is imperative for organizations to stay ahead of these threats through continuous improvement of their cybersecurity postures, leveraging both technological solutions and strategic planning to safeguard their assets and maintain resilience against evolving cyber threats.