Sophos
Reports
All Statistics
Just 31% of MSPs can fully automate reports at speed.
81% of MSPs say they would save more than 30% of their team's time by using a single, unified platform to handle customer security posture, compliance management, and reporting activities.
MSPs expect an average time saving of 53% from using a single, unified platform for customer security posture, compliance management, and reporting.
56% of ransomware attacks succeed in encrypting data, up from 50% the previous year.
97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.
51% of organizations that pay the ransom negotiate a lower amount than the initial demand.
67% of ransomware victims confirmed their ransomware incident stemmed from an identity attack.
Mean recovery cost for identity-related incidents reached $1.64 million, with a median of $750,000, and 73% of affected organizations facing costs of $250,000 or more.
Human error (employees tricked into providing credentials) was cited in nearly 43% of identity incidents.
62% of retailers who experienced attacks restored their data using backups in 2025, the lowest rate in four years
The median ransom demand for retail ransomware attacks doubled to $2 million in 2025 compared to 2024
47% of retail IT/cybersecurity teams reported increased pressure after experiencing data encryption in 2025
In 71% of cases where companies paid a smaller ransom than the initial demand, negotiation played a role, either directly or with third-party assistance.
Organisations with $250 million revenue or less saw median ransom demands of less than $350,000.
Healthcare reported the lowest median ransom payment at $150,000.
The Veeam vulnerability (CVE-2024-40711) and similar documented vulnerabilities played a role in nearly 15 percent of the cases Sophos MDR tracked involving malicious intrusions in 2024.
Over a third of all incidents involving intrusion into smaller organisations have systems on the network edge as the initial point of compromise.
Compromised network edge devices account for a quarter of the initial compromises of businesses in cases that could be confirmed from telemetry.
Ransomware cases accounted for 70 percent of Sophos Incident Response cases for small business customers in 2024.
55% of MSPs still require some manual effort to consolidate activities.
Compliance influences 50% of customer MSP purchasing decisions.
46% of customers look to their MSP to act as CISO.
84% of MSPs expect demand for CISO services to increase over the next 12 months.
53% of MSPs use multiple tools or platforms to centrally manage cybersecurity compliance or CISO-type activities.
99% of MSPs provide some level of compliance service.
Compromised credentials accounted for 23% of ransomware incidents.
Brute-force attacks accounted for 6% of ransomware incidents.
Across ransomware attacks that begin with exploited vulnerabilities, compromised credentials, or brute force, 38% of initial compromises occur in exposed applications and systems.
Across those attacks, 21% of initial compromises occur in firewalls.
79% of ransomware attacks start with an identity-based approach.
Median ransom demand is $698,000, down 65% over two years.
Malicious email (26%) and phishing (24%) together account for 50% of ransomware incidents.
Across those attacks, 3% of initial compromises occur in IoT devices.
48% of victims whose data was encrypted pay the ransom, roughly in line with a four-year average of about 50%.
Exploited vulnerabilities accounted for 18% of ransomware incidents, down 14 percentage points year-over-year.
67% of ransomware victims confirmed their ransomware incident was the same event as their most significant identity attack.
Across all ransomware attacks, 48% of ransom demands are for $1 million or more.
Median ransom payment is $769,000, down from $1,000,000 the previous year.
32% of retail organizations paid the ransom, the lowest payment rate of any sector.
Backup-based recovery accounts for 66% of encrypted-data cases, up 12 percentage points from 2025.
Average recovery cost is $1.7 million per incident, up 11% year-over-year.
72% of local and state government organizations paid the ransom, the highest payment rate among sectors.
Across those attacks, 8% of initial compromises occur in VPNs.
Only 34% of small organizations (100–250 employees) stop attacks before encryption or extortion, compared with 46% of organizations with 3,001–5,000 employees.
67% of root causes across 661 incident response and managed detection and response (MDR) cases are identity-related.
When ransomware attacks start with exploitation of a vulnerability in the firewall, 59% of those ransom demands are for $1 million or more.
The UK records the highest median ransom demand for any country at $2.5 million.
Multi-factor authentication (MFA) is missing where it matters in 59% of IR and MDR cases.
Across those attacks, 30% of initial compromises occur on user devices.
Organizations with weak NHI management pay approximately $150,000 more to recover from incidents than average.