Security

Paying Less, Losing More: Ransomware Recovery Costs Are Rising as Ransom Demands Collapse

Sophos surveyed 2,158 IT and security leaders across 17 countries and found median ransom demands down 65% over two years while average recovery costs reached $1.7 million. The money moved from the extortionist to the clean-up operation.

August 14, 2026 · Security
A monitor on an office desk displaying security and analytics dashboards in a dimly lit room

Key Takeaways

  • Sophos's seventh annual ransomware survey, covering 2,158 IT and cybersecurity leaders in 17 countries, found that 79% of attacks now begin with a compromised identity rather than with malware.
  • Average recovery cost reached $1.7 million per incident, and the share of attacks in which adversaries successfully encrypted data rose to 56% from 50% a year earlier.
  • Median ransom demands have fallen 65% over two years, and only 48% of organisations whose data was encrypted paid a ransom.
  • Verizon's 2026 Data Breach Investigations Report found ransomware present in 48% of breaches, up from 44%, with 69% of victims refusing to pay.

There is a reading of the 2026 ransomware data that sounds like victory. Median ransom demands have fallen 65% over two years according to Sophos's seventh annual State of Ransomware survey, which polled 2,158 IT and cybersecurity leaders across 17 countries. Fewer than half of the organisations that had data encrypted, 48%, paid anything at all. Verizon's 2026 Data Breach Investigations Report puts the refusal rate higher still, at 69%. On the single metric the industry has spent a decade trying to move, organisations are winning: they are paying criminals less often.

Then there is the other number. Average recovery cost reached $1.7 million per incident. Successful encryption climbed to 56% of attacks from 50% the year before. So adversaries are getting into more environments and locking more data, while extracting less cash for it, and the total bill is going up rather than down. The money did not leave the ransomware economy. It moved from the extortion payment to the recovery operation.

The Ransom Was Never the Expensive Part

Recovery cost is the line item that survives a decision not to pay, and it is remarkably insensitive to how well the negotiation goes. Rebuilding identity infrastructure, restoring from backups of uncertain vintage, running forensics to a standard that satisfies a regulator, and staffing an incident bridge for weeks all cost the same whether the ransom was $700,000 or nothing. Sophos found that 55% of organisations recovered within a week and 16% inside a day, which is a genuine improvement in resilience, but a one-week outage across a mid-sized enterprise is not a cheap week.

This reframes what a ransomware programme is actually buying. Refusing to pay is now the majority behaviour, not the brave exception, which means the marginal security investment is no longer about avoiding a payment decision. It is about compressing the recovery. The organisations with the best economics are not the ones with the strongest negotiating posture, they are the ones whose restore path is tested, whose identity blast radius is small, and whose forensic logging survives the encryption.

“Organizations have strengthened their ransomware resilience in the past year.”

Ross McKerchar, Chief Information Security Officer, Sophos

Identity Is the Perimeter That Actually Failed

The most consequential figure in the Sophos data is not financial. It is that 79% of ransomware attacks now start with a compromised identity. Malicious email accounts for 26% of root causes and phishing for a further 24%, which together make credential capture the origin of half of all incidents. The malware, when it eventually runs, is the last act rather than the first.

Verizon's report complicates this in a way worth sitting with. For the first time in the DBIR's 19-year history, credential theft was knocked off the top spot for initial access: exploited vulnerabilities took it, at 31% of breaches, up from 18% in the previous edition. Credential abuse fell to 13% as an initial vector, down from 22%. But look across the whole breach rather than just the front door and credential abuse reappears in 39% of cases. Attackers are increasingly getting in through an unpatched system and then immediately reaching for credentials to go anywhere useful. Verizon also found organisations fully remediating CISA's known exploited vulnerabilities dropped to 26% from 38%, with median patch time stretching to 43 days from 32.

Two details in the data resist the resilience narrative. Sophos recorded the UK median ransom demand at $2.5 million, the highest it has measured, which says the collapse in demands is an average concealing wide variance by geography rather than a uniform retreat. And Verizon, drawing on some 13,000 polled organisations, found only 23% had fully remediated third-party multi-factor authentication issues. The identity weakness that begins 79% of these attacks is frequently not in the enterprise at all, but in a supplier whose access nobody re-examined after the contract was signed.

What This Changes in a Budget Conversation

A security programme built on the premise that the goal is to avoid paying a ransom is now solving a problem most organisations have already solved. The harder and more expensive problem is the $1.7 million that arrives regardless. That argues for shifting spend toward the two capabilities that shorten recovery rather than prevent the decision: identity containment, so a single compromised account does not become a full-environment event, and restore validation, so the backups turn out to work under pressure.

The ransomware story has quietly stopped being about the ransom. Criminals are asking for less because fewer people pay, and the organisations that stopped paying discovered what security teams have said for years: the invoice does not go away, it just arrives from your own recovery vendors instead.

Share

More in Security

All Resources →