The Data Protection Review
// Section
Ransomware-Resiliences
// Published
August 5, 2026
// Read time
8 min
// Share
LinkedIn
Ransomware-Resiliences

Sophos State of Ransomware 2026: Backup-Based Recovery Overtakes Ransom Payment for the First Time

Sophos's seventh ransomware survey puts backup-based recovery at 66% of encrypted-data cases against 48% paying. What the numbers do and don't prove.

The editors of The Data Protection Review
Editorial Staff
Server racks in a data centre with restore progress indicators, representing recovery from backup
Server racks in a data centre with restore progress indicators, representing recovery from backup

Sophos published the seventh edition of its State of Ransomware survey with a headline number that backup teams have been waiting a decade to see: of organizations whose data was encrypted, 66% restored from backups — up 12 percentage points year over year — while 48% paid a ransom. For the first time in the survey’s history, restoring from your own copies is not merely competitive with paying an extortionist. It is the majority path.

The survey covers 2,158 IT and cybersecurity leaders across 17 countries, with responses gathered between January and March 2026 describing the previous twelve months. That is a large, vendor-agnostic sample, and the trend it describes is real. But the same dataset contains three findings that complicate the victory lap, and they matter more to anyone actually designing a recovery capability than the headline does.

The payment economics have inverted, not collapsed

The median ransom demand fell to $698,000, down from $1.32 million in 2025 and $2 million in 2024 — roughly a 65% decline over two years. The obvious reading is that attackers have lost pricing power because victims can now recover without them. That reading is probably partly correct, and 51% of organizations that did pay negotiated the figure down from the initial demand.

What undercuts a purely triumphant interpretation is the median payment: $769,000, which is higher than the median demand. These two medians are computed over different populations — every victim who received a demand versus the subset who chose to pay — so the comparison is not a contradiction. But it points at something useful. The organizations still paying in 2026 are disproportionately the ones facing large demands, which is consistent with attackers shifting from volume extortion toward victims whose recovery position is genuinely weak. Cheap demands go to targets who will just restore and ignore you. Expensive demands go to targets who cannot.

Meanwhile the cost that actually lands on the balance sheet went the wrong way. Average recovery cost per incident rose 11% year over year to $1.7 million — and that figure excludes ransom payments. Recovering from backup is winning on frequency while getting more expensive per event. The operational work of a full restore, the downtime, the forensic and remediation labour, and the rebuild of compromised identity infrastructure are the real bill, and they do not shrink because you declined to pay.

Attackers are getting better at the encryption step

The second complication: 56% of attacks succeeded in encrypting data, up from 50% the previous year. Prevention is losing ground at the same time recovery is gaining it. Those two trends together describe a discipline that is absorbing more hits and surviving more of them — which is a legitimate improvement in resilience, but it is not the same thing as a reduced threat.

The size gradient here is stark and directly relevant to smaller IT shops and the MSPs serving them. Only 34% of organizations with 100–250 employees stopped an attack before encryption, against 46% at firms with 3,001–5,000 employees. Smaller organizations are not facing a gentler class of attacker; they are facing the same operators with less detection coverage and thinner staffing on the response side. For that cohort, recoverability is not a fallback layer behind prevention. It is the primary control, because prevention is failing two times in three.

The root causes moved to identity

The third finding reframes what a backup architecture has to defend against. Sophos attributes 79% of attacks to an identity-based initial approach. Breaking out the specific root causes: malicious email at 26%, phishing at 24%, compromised credentials at 23%, and exploited vulnerabilities down 14 percentage points to 18%. Patch velocity, long the default answer to “how did they get in,” has dropped to fourth place. Credentials are the front door.

That has a concrete architectural consequence, and it is the part of this report worth acting on. If the overwhelming majority of intrusions begin with valid credentials, then any backup repository reachable with credentials is inside the blast radius by definition. A domain-joined backup server, an SMB share holding recovery points, a cloud bucket with standing write and delete permissions cached on production hosts — each of these is protected by exactly the control that 79% of attacks defeat first.

Notably, 97% of respondents had some form of MFA enabled, and attacks still succeeded at these rates. “Some form of MFA” is doing a lot of work in that sentence. Push-notification MFA on a backup console, with fatigue-prone approval flows and no phishing resistance, is not equivalent to hardware-backed authentication on a separately-governed identity plane.

What the 66% actually justifies

The useful conclusion is narrower than the headline. Backup-based recovery is now the dominant recovery method, and the organizations achieving it are demonstrably better off than those negotiating. That vindicates a decade of investment in immutability, retention locks, and isolated copies.

It does not show that backup investment is finished. Read alongside the encryption rate climbing to 56% and identity-based entry at 79%, the report describes an environment where you should expect to be encrypted and expect the attacker to arrive holding legitimate credentials. Three things follow:

  • Assume the credential is compromised, not just the endpoint. The recovery copy that survives is the one no production credential can delete — object lock with a governance mode that the backup service account itself cannot override, or media with no standing network path at all. Immutability configured through the same console an attacker can log into is a speed bump, not a control.
  • Budget for the restore, not the ransom. The $1.7 million average recovery cost is the number that will actually hit you, and it is rising. Restore throughput, staffing for a parallel rebuild, and tested runbooks are what compress it.
  • Test at the scale you would actually need. A 66% success rate across a survey population says nothing about whether your restore completes inside your RTO. Verified recovery of a representative workload, on a schedule, is the only evidence that transfers.

The survey is a genuine milestone for the data-protection discipline. It is also a description of attackers who encrypt more often, enter through identity, and reserve their expensive demands for the organizations whose backups will not hold. Which of those two stories applies to a given environment is decided long before the ransom note arrives — by whether the recovery copy is reachable by a stolen credential, and by whether anyone has proved a full restore lately.

Source: Sophos, The State of Ransomware 2026 (seventh edition; 2,158 respondents across 17 countries, surveyed January–March 2026).