Ransomware continues to challenge organizations despite significant investments in cybersecurity defenses.
According to reporting from Infosecurity Magazine, research from SpyCloud found that 90% of surveyed organizations had experienced ransomware attacks, with three-quarters of those organizations hit more than once over a 12-month period. The research also found that ransomware impacted 75% of organizations during the year studied, up from 61% the previous.
One of the more concerning findings is how attackers are gaining access. Phishing and social engineering remained the most common initial entry point, while third-party access, stolen cookies, session hijacking, and infostealer malware also contributed to successful attacks. In fact, more than half of devices infected with infostealer malware were running antivirus or endpoint detection and response tools.
These findings reinforce an important reality: cyber security tools alone cannot eliminate ransomware risk. Organizations need to prepare for what happens when preventative controls fail.
The financial consequences also remain significant. The research found that 44% of businesses faced more than $1 million in costs following a ransomware attack, while nearly two-thirds of ransomware demands reached $1 million or more. Among organizations that paid a ransom, only one-third fully recovered their data.
Ransomware preparedness is no longer just about preventing an attack. It is about building the operational, technical, and compliance infrastructure necessary to respond quickly and effectively when an incident occurs.