Wednesday, July 22, 2026

New Cybereason ransomware study reveals true cost to business

Cybereason, the leader in future-ready attack protection, today released research findings from a global ransomware study of nearly 1,300 security professionals that reveals more than half of organisations have been the victim of a ransomware attack. In the UK specifically, 305 companies were contacted and 84% of businesses that chose to pay a ransom demand suffered a second ransomware attack, often at the hands of the same threat actor group (53%).

The research also divulged that of the organisations in the UK who opted to pay a ransom demand to regain access to their encrypted systems, 43% reported that some or all of the data was corrupted during the recovery process. These findings underscore why it does not pay to pay ransomware attackers, and that organisations should focus on early detection and prevention strategies to end ransomware attacks at the earliest stages before critical systems and data are put in jeopardy.

Key findings (UK-specific) in the research include:

  • Loss of business: 47 percent of organisations reported significant loss of business following a ransomware attack. Of these individuals, 61% admitted to losing revenue.
  • Ransom demands increasing: 51percent of businesses that paid a ransom demand shelled out between £250,000 – £1 million, while 4 percent paid ransoms exceeding £1 million.
  • Brand and reputation damage: 63percent of organisations who admitted to losing business indicated that their brand and reputation were damaged as a result of a successful attack
  • C-Level talent loss: 45 percent of organisations who admitted to losing business reported losing C-Level talent as a direct result of ransomware attacks
  • Employee layoffs: 31 percent of those who admitted to losing business reported being forced to layoff employees due to financial pressures following a ransomware attack
  • Business closures: A startling 34 percent of organisations who admitted to losing business reported that a ransomware attack forced the business to close down operations entirely

Other key findings included in the full report reveal the extent to which losses to the business may be covered by cyber insurance, how prepared organisations are to address ransomware threats to the business with regard to adequate security policies and staffing, and more granular information on the impact of ransomware attacks by region, company size and industry vertical. In addition, the report provides actionable data on the types of security solutions organisations had in place prior to an attack, as well as which solutions were most often implemented by organisations after they experienced a ransomware attack.

“Ransomware attacks are a major concern for organisations across the globe, often causing massive business disruptions including the loss of income and valuable human resources as a direct result. In the case of the recent Colonial Pipeline ransomware attack, disruptions were felt up and down the East Coast of the United States and negatively impacted other businesses who are dependent on Colonial’s operations,” said Chief Executive Officer and Co-founder of Cybereason, Lior Div.

“Paying a ransom demand does not guarantee a successful recovery, does not prevent the attackers from hitting the victim organisation again, and in the end only exacerbates the problem by encouraging more attacks. Getting in front of the threat by adopting a prevention-first strategy for early detection will allow organisations to stop disruptive ransomware before they can hurt the business.”

Survey methodology

The research was conducted by Censuswide in April of 2021 on behalf of Cybereason. 1,263 cybersecurity professionals took part in the survey—with participants from the United States, United Kingdom, Spain, Germany, France, United Arab Emirates, and Singapore. Major industry verticals covered in the research include the Technology, Manufacturing, Financial Services, Retail, Healthcare, Automotive, Legal and Government sectors. 

Further information

www.cybereason.com

Latest

AI is not the disruption. Your operating model is

The five per cent of organisations capturing value from...

AI is not one technology – and leaders should stop treating it that way

To prepare effectively for the future, Mehdi Paryavi argues...

Why the best sustainability investments don’t depend on customers caring

Consumer belief is the riskiest asset on the balance...

Progress on environment stalls as pressure to deliver immediate returns mounts

New research reveals how a growing focus on short-term...

Subscribe To Our Content

Don't miss

AI is not the disruption. Your operating model is

The five per cent of organisations capturing value from...

AI is not one technology – and leaders should stop treating it that way

To prepare effectively for the future, Mehdi Paryavi argues...

Why the best sustainability investments don’t depend on customers caring

Consumer belief is the riskiest asset on the balance...

Progress on environment stalls as pressure to deliver immediate returns mounts

New research reveals how a growing focus on short-term...

Why promising social ventures fail – and the solution emerging to prevent this

Misunderstandings between investors and founders are damaging social innovation,...

AI is not the disruption. Your operating model is

The five per cent of organisations capturing value from AI are not deploying tools faster – they are redesigning how work gets done, says...

AI is not one technology – and leaders should stop treating it that way

To prepare effectively for the future, Mehdi Paryavi argues that businesses should stop viewing AI as a single phenomenon and start focusing on agentic...

Why the best sustainability investments don’t depend on customers caring

Consumer belief is the riskiest asset on the balance sheet, argue Goutam Challagalla and Frédéric Dalsace. The real question is whether customers would buy...

LEAVE A REPLY

Please enter your comment!
Please enter your name here