According to a report published by Coveware, the average total losses resulting from a ransomware attack currently amount to $84,116. This is more than double the previous value of $41,198. This amount refers not only to the ransom paid but also includes equipment replacement and repair costs, lost revenue, and in some cases, loss of company reputation.
The report also shows that a new risk associated with ransomware attacks has emerged, which can make data recovery even more expensive. Cybercriminals are not only encrypting their victims’ data to later demand payment for decryption. Currently, there is a visible trend where criminals download copies of these files and threaten to make them public if the ransom is not paid.
But why do ransomware victims still pay the ransom? Because it is a reliable way to recover critical data.
Coveware states in its report that 98% of companies that paid the ransom actually received a decryption tool. This results in approximately 97% of files being successfully decrypted, with only 3% being lost.
The hours that decide the size of the loss
The scale of a ransomware loss is usually decided not at the moment of encryption but in the first hours after it is noticed. In that window somebody has to contain the spread, preserve evidence, establish whether data left the network and start the notification clock — and each of those actions makes the others harder if nobody has agreed the order and the roles in advance.
Having that plan rehearsed, and a number to call for a team that already knows it, is the point of incident response.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Backup — Backup, also known as a backup copy or safety copy, is the process of creating…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
Learn More
Explore related articles in our knowledge base:
- Cyber Trends: Ransomware
- Data Leaks and Ransomware Attacks Are the Biggest Threats to Organizations
- New trends in ransomware attacks in 2025: how to defend a company against the evolving threat?
- Ransomware in industry: Why do factories pay ransom and how to build an effective defense plan?
- Personal board liability for cybersecurity under NIS2
Explore Our Services
📚 Read the complete guide: Ransomware: Ransomware - czym jest, jak się chronić, co robić po ataku
Need cybersecurity support? Check out:
- Incident Response - rapid response to security incidents
- SOC as a Service - 24/7 security monitoring
- Backup & Disaster Recovery - data protection and business continuity
Why this matters for organizations
Learn what ransomware is and how to protect your company from this type of cyber threat. Discover strategies, tools, and best practices that can help prevent and respond to ransomware attacks. In the context of growing cyber threats and tightening regulations (NIS2, DORA), organizations must proactively manage this security area. Failure to implement adequate safeguards can lead to data breaches, financial penalties, and reputational damage.
Best practices for implementation
Effective implementation requires several key steps:
- Risk assessment and inventory — identify assets, threats, and vulnerabilities specific to your organization.
- Policy development — document requirements, roles, and responsibilities.
- Technical controls — deploy tools and configurations proportionate to identified risks.
- Training and awareness — engage employees in protecting organizational security.
- Monitoring and continuous improvement — regularly verify effectiveness and adapt to the evolving threat landscape.
