THREAT WATCH
Critical Progress LoadMaster: CVE-2026-8037 — Progress LoadMaster Command Injection Vulnerability Critical JetBrains TeamCity: CVE-2026-63077 — JetBrains TeamCity Deserialization of Untrusted Data Vulnerability Critical IBM Langflow: CVE-2026-9198 — IBM Langflow Code Injection Vulnerability High Apache Tomcat: CVE-2026-34486 — Apache Tomcat Missing Encryption of Sensitive Data Vulnerability High N-able N-central: CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability Actively Exploited N-able N-central: CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability Medium Cisco Secure Firewall Management Center (FMC): CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Medium Fortinet FortiOS: CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability Critical Progress LoadMaster: CVE-2026-8037 — Progress LoadMaster Command Injection Vulnerability Critical JetBrains TeamCity: CVE-2026-63077 — JetBrains TeamCity Deserialization of Untrusted Data Vulnerability Critical IBM Langflow: CVE-2026-9198 — IBM Langflow Code Injection Vulnerability High Apache Tomcat: CVE-2026-34486 — Apache Tomcat Missing Encryption of Sensitive Data Vulnerability High N-able N-central: CVE-2026-18556 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability Actively Exploited N-able N-central: CVE-2026-18577 — N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability Medium Cisco Secure Firewall Management Center (FMC): CVE-2026-20316 — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Medium Fortinet FortiOS: CVE-2025-68686 — Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

Ransomware: a business leader’s risk brief

Key takeaways
  • The ransom is the smaller number. Recovery now costs an average of US$1.7 million per incident before any ransom is counted, and that figure rose 11 percent in a year even as ransom demands fell.
  • The entry point has moved. For the first time in four years, exploited vulnerabilities are not the leading root cause. Email, phishing and stolen credentials are.
  • Multi-factor authentication was already switched on at 97 percent of victims whose attack started with stolen credentials. The damage happened in the coverage gaps.
  • Backups are working. Two-thirds of organisations with encrypted data restored it from backup, and the share of victims paying has fallen to an estimated all-time low.
  • Smaller organisations are carrying more of the loss, stopping attacks before encryption far less often than larger ones.
  • Four decisions here need a business leader, not an IT team. The rest is delivery.

Ransomware is now a business continuity problem that happens to arrive through a computer. That framing matters, because the decisions that determine how badly an incident hurts are mostly made months before it happens, and most of them are not technical. This brief covers what the current evidence says, what it costs, and the specific choices that need a leader’s signature rather than an engineer’s.

The ransom is not the bill

The most common planning error is treating the ransom demand as the size of the risk. It is not. In Sophos’s State of Ransomware 2026, a survey of 2,158 IT and security leaders across 17 countries whose organisations were hit in the previous year, the average cost of recovering from an incident was US$1,700,200 before any ransom was included. That is an 11 percent rise on the year before, and it rose even though the median ransom demand fell 65 percent over two years to US$698,000.

Bar comparison showing median ransom payment of US$769,000 against average recovery cost of US$1,700,200 excluding ransom, with statistics on backup recovery, payment rates and negotiated discounts
Recovery costs are rising while ransom demands fall. Figures from Sophos, State of Ransomware 2026.

Those recovery costs are the things a board already understands: lost production, idle staff, overtime, forensic investigation, legal advice, customer notification, and the slow work of rebuilding systems that have to be assumed compromised. The ransom, if it is paid at all, is a line item inside a much larger disruption. The practical consequence is that spending which shortens downtime is usually worth more than spending which reduces the chance of an incident by a few percent.

The wider market data points the same way. Blockchain analysis firm Chainalysis reported in its 2026 Crypto Crime Report that total on-chain ransomware payments fell about 8 percent to roughly US$820 million in 2025, even as publicly claimed attacks rose 50 percent, with the share of victims paying reaching an estimated all-time low of 28 percent. Attackers are running more operations for less money. That is genuine progress, and it is the direct result of organisations getting better at recovering without paying.

Where attacks actually start now

The second planning error is defending against last year’s entry point. The Sophos data records a significant shift: exploited vulnerabilities lost the top root-cause position they had held for three years, falling 14 percentage points to 18 percent of incidents. Malicious email at 26 percent and phishing at 24 percent together account for half of all cases, with compromised credentials third at 23 percent.

Bar chart of ransomware root causes showing malicious email at 26 percent, phishing at 24 percent, compromised credentials at 23 percent, exploited vulnerabilities at 18 percent and brute force at 6 percent, with identity-based attacks accounting for 79 percent overall
Email, phishing and credential theft now account for the majority of incidents. Figures from Sophos, State of Ransomware 2026.

Read those top three together and they are largely one problem wearing three labels. Sophos reports that 79 percent of ransomware attacks began with an identity-based approach: someone’s login was used, whether it was phished, bought, or stolen by malware. The company’s separate analysis of real incidents its own responders handled found identity-related causes in 67 percent of 661 cases.

This has a direct budget implication. If half your incidents arrive by email and four in five involve someone’s identity, then patching cadence alone will not close the gap, however well it is run. Email filtering, domain authentication and identity controls belong in the same conversation, at the same level of seriousness.

The multi-factor authentication trap

Here is the finding most likely to change a leader’s mind. Among victims whose attack started with compromised credentials, 97 percent already had multi-factor authentication enabled in some form at the time of the attack. Having MFA was not the differentiator. Where it was switched on was.

Sophos found the gaps in predictable places: staff-facing cloud applications were covered, while VPNs, firewall administration consoles and older internal applications frequently were not. Attackers do not attack the door with the lock on it. If your organisation has “rolled out MFA”, the useful question is not whether it is deployed but which systems were left out of the rollout and why. Our guide to what a board should approve on MFA covers the specific coverage questions worth asking.

Note

Where attacks began, according to victims: exposed applications and systems 38 percent, user devices 30 percent, firewalls 21 percent, VPNs 8 percent, and connected devices 3 percent. Firewall-origin incidents carried heavier demands, with 59 percent asking for US$1 million or more against a 48 percent baseline. Perimeter equipment is not neutral infrastructure; it is a high-value target with privileged reach.

Size is now a risk factor

The gap between large and small organisations is widening on the measure that matters most, which is stopping an attack before data is encrypted or stolen. Sophos found that only 34 percent of organisations with 100 to 250 employees managed this, against 46 percent of organisations with 3,001 to 5,000 employees.

That difference is not about tooling budgets alone. It is largely about whether someone is watching outside working hours and can act within minutes. Attackers have not overlooked this. Chainalysis noted a structural shift toward higher volumes of smaller victims, alongside a fragmenting market of as many as 85 active extortion groups, with median payment sizes rising sharply even as the total pool of payments shrank. Fewer headline intrusions, more mid-market disruption.

Decide the payment question before you need to

Paying is a business decision with legal, insurance and reputational dimensions, and it should never be made for the first time at two in the morning during an outage. Some evidence worth having in advance: 48 percent of organisations with encrypted data paid, 66 percent recovered from backups, and 51 percent of those who paid negotiated below the original demand.

Two things complicate the decision. First, paying buys a decryption key, not a clean recovery. Systems still have to be rebuilt and verified, which is why recovery costs stay high either way. Second, most modern extortion involves stolen data as well as encryption, so functioning backups solve the outage but not the disclosure. Chainalysis observed groups responding to falling payment rates by becoming more aggressive in negotiation, including contacting employees and customers directly, and by analysing stolen data to make more specific threats.

Before you assume payment is available

Sanctions regimes in several jurisdictions restrict payments to certain groups, and your obligations depend on where you operate and where your data subjects are. Establish with your legal advisers, in advance and in writing, who is authorised to approve a payment, what your regulator’s notification clock is, and what your cyber insurance policy actually requires you to do first. Discovering any of this during an incident costs time you will not have.

What only a leader can decide

Most ransomware guidance is written for the people who implement it. These four items cannot be delegated, because each one is a resourcing or authority decision.

What downtime you can absorb. Someone has to state how long the organisation can operate without each critical system, and what it costs per day when it cannot. Without that number, no one can size a recovery capability or justify its cost. This single figure drives almost every other decision on this page.

Who can act, at 3am, without asking. Containment often means disconnecting systems and disrupting the business, and staff will hesitate to do that without cover. Name the person, write down their authority, and say explicitly that a defensible decision made quickly will be supported afterwards.

Whether recovery has ever actually been tested. Backups existing is not the same as backups restoring. The question to ask is not “do we have backups” but “when did we last restore a critical system from backup, how long did it take, and who watched”. If nobody can answer, that is the finding.

Who you call, agreed before you need them. Incident response, legal counsel and your insurer all need to be reachable within the hour. Retainers and contact routes are cheap to arrange in advance and slow to arrange during an outage.

What to do now
  1. Ask for a list of every system where multi-factor authentication is not enforced, with a reason and a date for each. Pay particular attention to VPNs, firewall and other administrative consoles, and legacy applications.
  2. Set a maximum tolerable downtime figure for your three most critical systems, and have it written down and agreed.
  3. Commission a restore test of one critical system from backup, and ask for the elapsed time rather than a pass or fail.
  4. Confirm that at least one backup copy is offline or otherwise beyond the reach of an administrator account.
  5. Name the person authorised to disconnect systems during an incident, and confirm in writing that they have that authority.
  6. Agree your position on ransom payment with legal counsel now, and record who approves it.
  7. Check what your cyber insurance requires of you in the first 24 hours, before you need to comply with it.
  8. Run one tabletop exercise involving the executive team, not just IT. The value is in discovering which decisions are unclear.

The honest summary

The direction of travel is genuinely positive. Payment rates are at or near record lows, backup recovery is at near-record highs, ransom demands have fallen substantially, and organisations that do pay are negotiating better. None of that happened by accident; it is the accumulated result of unglamorous preparation across thousands of organisations.

What has not improved is the cost of being unprepared. Recovery bills are rising, encryption succeeds more often than it did last year, and smaller organisations are absorbing a disproportionate share of the damage. The organisations that come through an incident well are not the ones that bought the most; they are the ones that had already decided who does what, and had checked that their recovery works. Those decisions are available to any organisation, at any budget, and they are available today.

Last verified: 7 August 2026. Survey findings describe the organisations sampled rather than the whole economy, and the Sophos data covers organisations that were hit by ransomware in the preceding 12 months.

Leave a Reply

Your email address will not be published. Required fields are marked *