Key Takeaways
- IBM estimates the average ransomware or extortion incident costs $5.08 million, while Sophos puts mean recovery spending excluding ransom at $1.53 million.
- Faster recovery is becoming more common, but it depends on tested backups, established response procedures, and access to specialist support.
- Business leaders should treat ransomware readiness as an operational resilience issue, not simply a security technology purchase.
Ransomware’s financial damage does not stop when an attacker receives payment or when encrypted systems come back online. Forensic investigations, malware removal, data restoration, legal advice, regulatory work, customer communications, and lost operating time can all add to the final bill.
That wider cost is substantial. IBM’s 2025 Cost of a Data Breach report estimates that the average ransomware or extortion incident costs $5.08 million. Sophos’s 2025 survey, covering 3,400 organizations across 17 countries, calculates mean recovery costs excluding ransom at $1.53 million.
Those figures measure different parts of the problem, so they should not be treated as conflicting benchmarks. IBM’s estimate captures the broader incident impact. Sophos focuses on remediation expenses outside the ransom payment itself. Together, they show why evaluating ransomware exposure solely through the size of a demand can leave executives with an incomplete view.
Recovery is partly a technology exercise, but it is also a business coordination test. Security teams may need to isolate infected endpoints while infrastructure specialists rebuild identity services, application owners validate data, lawyers assess disclosure duties, and communications teams manage questions from customers and employees. A delay in any one area can hold up the rest.
There are signs that preparedness is improving. Sophos found that 53% of affected organizations fully recovered within one week in 2025, compared with 35% in 2024. Tested restoration procedures, incident-response planning, and specialist assistance can help explain that shift. Having backup copies is useful. Knowing which systems to restore first, who has the authority to approve the process, and whether those copies are clean is what turns backup capacity into practical resilience.
Larger businesses still face difficult payment decisions. Sophos reported in 2026 that 48% of enterprises with 1,000 or more employees paid a ransom in 2025 (source). Median demands fell to $1.2 million and median payments to $1 million, while mean remediation costs excluding ransom reached $1.84 million.
Paying does not erase the recovery workload. Systems still need to be examined and rebuilt, stolen credentials rotated, persistence mechanisms removed, and affected data assessed. Nor does a payment establish that a decryptor will work quickly or that copied information will be deleted. So what should boards measure? Recovery time, restoration success, operational dependencies, and the financial effect of downtime often reveal more than a simple backup-completion percentage.
Sector conditions matter too. Kiteworks’ review of Sophos manufacturing data cites an average recovery cost excluding ransom of $1.3 million and an average ransom payment of $1 million. It also reports that 58% of affected manufacturers recovered within a week. Production environments can complicate containment because shutting down connected operational systems may carry safety, quality, and revenue consequences.
A practical program can follow the Govern, Identify, Protect, Detect, Respond, and Recover functions in NIST Cybersecurity Framework 2.0. NIST SP 800-61 Rev. 3, published in 2025, provides further direction for integrating incident response into broader risk management. A CNI Solutions incident-response planning guide also outlines the value of defined roles, escalation paths, evidence handling, and post-incident review.
Technology choices remain part of the equation. Cohesity and Rubrik provide resilient backup and recovery capabilities, while CrowdStrike supports endpoint detection and response. Yet product deployment alone is not a recovery strategy. Immutable or isolated backups should be validated through regular restoration exercises, preferably under realistic time constraints.
Cloud synchronization deserves particular scrutiny. Synchronizing corrupted or encrypted files can reproduce damage across connected environments, whereas a recoverable backup preserves independent restore points. The distinction sounds basic, but it can become painfully clear during an incident.
For business leaders, the useful question is not whether ransomware can be eliminated. It is whether the business can contain an intrusion, make informed decisions, restore priority services, and account for the full economic impact. Regular exercises can expose gaps before attackers do, and that preparation may be the difference between a controlled disruption and weeks of expensive uncertainty.
⬇️