Sophos

96 stats7 reports

All Statistics

Just 31% of MSPs can fully automate reports at speed.

AutomationReportingManaged ServicesMSPs

81% of MSPs say they would save more than 30% of their team's time by using a single, unified platform to handle customer security posture, compliance management, and reporting activities.

Operational EfficiencyManaged ServicesMSPs

MSPs expect an average time saving of 53% from using a single, unified platform for customer security posture, compliance management, and reporting.

Operational EfficiencyManaged ServicesMSPs

56% of ransomware attacks succeed in encrypting data, up from 50% the previous year.

EncryptionRansomware

97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.

Multi-Factor AuthenticationIdentity

51% of organizations that pay the ransom negotiate a lower amount than the initial demand.

RansomwareNegotiation

67% of ransomware victims confirmed their ransomware incident stemmed from an identity attack.

RansomwareIdentity Compromise

Mean recovery cost for identity-related incidents reached $1.64 million, with a median of $750,000, and 73% of affected organizations facing costs of $250,000 or more.

Cost of BreachFinancial ImpactIdentity-Related Breach

Human error (employees tricked into providing credentials) was cited in nearly 43% of identity incidents.

Human ErrorSocial EngineeringIdentity Attack

62% of retailers who experienced attacks restored their data using backups in 2025, the lowest rate in four years

RansomwareEncrypted dataBackupData restorationRetail

The median ransom demand for retail ransomware attacks doubled to $2 million in 2025 compared to 2024

RansomwareRansom Retail

47% of retail IT/cybersecurity teams reported increased pressure after experiencing data encryption in 2025

RansomwareData encryptionRetail

In 71% of cases where companies paid a smaller ransom than the initial demand, negotiation played a role, either directly or with third-party assistance.

RansomwareRansom

Organisations with $250 million revenue or less saw median ransom demands of less than $350,000.

RansomwareRansom

Healthcare reported the lowest median ransom payment at $150,000.

RansomwareRansomHealthcare

The Veeam vulnerability (CVE-2024-40711) and similar documented vulnerabilities played a role in nearly 15 percent of the cases Sophos MDR tracked involving malicious intrusions in 2024.

VulnerabilitiesMalicious intrusion

Over a third of all incidents involving intrusion into smaller organisations have systems on the network edge as the initial point of compromise.

Malicious intrusionSmall businessNetwork edge devices

Compromised network edge devices account for a quarter of the initial compromises of businesses in cases that could be confirmed from telemetry.

Network edge devicesSecurity incident

Ransomware cases accounted for 70 percent of Sophos Incident Response cases for small business customers in 2024.

RansomwareSmall business

55% of MSPs still require some manual effort to consolidate activities.

Operational EfficiencyManual ProcessesManaged ServicesMSPs

Compliance influences 50% of customer MSP purchasing decisions.

CompliancePurchasing DecisionsCustomer BehaviorMSPs

46% of customers look to their MSP to act as CISO.

Managed ServicesMSPsLeadership

84% of MSPs expect demand for CISO services to increase over the next 12 months.

Managed ServicesMSPs

53% of MSPs use multiple tools or platforms to centrally manage cybersecurity compliance or CISO-type activities.

ToolingManaged ServicesComplianceMSPs

99% of MSPs provide some level of compliance service.

ComplianceManaged ServicesMSPs

Compromised credentials accounted for 23% of ransomware incidents.

IdentityRansomwareCompromised Credentials

Brute-force attacks accounted for 6% of ransomware incidents.

Brute ForceRansomware

Across ransomware attacks that begin with exploited vulnerabilities, compromised credentials, or brute force, 38% of initial compromises occur in exposed applications and systems.

ApplicationsRansomware

Across those attacks, 21% of initial compromises occur in firewalls.

FirewallsNetwork Security

79% of ransomware attacks start with an identity-based approach.

IdentityRansomware

Median ransom demand is $698,000, down 65% over two years.

Ransom DemandsEconomics

Malicious email (26%) and phishing (24%) together account for 50% of ransomware incidents.

Email SecurityPhishingRansomware

Across those attacks, 3% of initial compromises occur in IoT devices.

IoTRansomware

48% of victims whose data was encrypted pay the ransom, roughly in line with a four-year average of about 50%.

Ransom PaymentsRansomware

Exploited vulnerabilities accounted for 18% of ransomware incidents, down 14 percentage points year-over-year.

VulnerabilitiesRansomwareExploited Vulnerabilities

67% of ransomware victims confirmed their ransomware incident was the same event as their most significant identity attack.

IdentityRansomware

Across all ransomware attacks, 48% of ransom demands are for $1 million or more.

Ransom DemandsEconomics

Median ransom payment is $769,000, down from $1,000,000 the previous year.

Ransom PaymentsEconomics

32% of retail organizations paid the ransom, the lowest payment rate of any sector.

RetailRansomware

Backup-based recovery accounts for 66% of encrypted-data cases, up 12 percentage points from 2025.

BackupRecovery

Average recovery cost is $1.7 million per incident, up 11% year-over-year.

Recovery CostsEconomics

72% of local and state government organizations paid the ransom, the highest payment rate among sectors.

GovernmentRansomware

Across those attacks, 8% of initial compromises occur in VPNs.

VPNNetwork Security

Only 34% of small organizations (100–250 employees) stop attacks before encryption or extortion, compared with 46% of organizations with 3,001–5,000 employees.

Small BusinessEnterprise SecurityRansomware

67% of root causes across 661 incident response and managed detection and response (MDR) cases are identity-related.

IdentityIncident Response

When ransomware attacks start with exploitation of a vulnerability in the firewall, 59% of those ransom demands are for $1 million or more.

Ransom DemandsFirewalls

The UK records the highest median ransom demand for any country at $2.5 million.

United KingdomRansom Demands

Multi-factor authentication (MFA) is missing where it matters in 59% of IR and MDR cases.

Multi-Factor AuthenticationIdentity

Across those attacks, 30% of initial compromises occur on user devices.

Endpoint SecurityRansomware

Organizations with weak NHI management pay approximately $150,000 more to recover from incidents than average.

Cost of BreachNon-Human Identities