If you only read headlines, ransomware looks like a problem in retreat. Sophos’ State of Ransomware 2026 report, built from 2,158 IT and security leaders across 17 countries, found the median ransom demand has fallen to $698,000, down 65% over two years. Median payments dropped too, from $1 million to $769,000. Total payments collected by attackers fell industry-wide in 2024, down from $1.25 billion the prior year to roughly $813 million.
Real progress. Also, for a small or mid-sized business, dangerously misleading. The retreat is happening at the top of the market. The pressure moved downhill, toward you.
The Numbers Behind the Good News
Ransom demands are shrinking, but the attacks themselves are landing more often. In that same Sophos report:
- 56% of attacks succeeded in encrypting data, up from 50% the year before
- The average recovery cost hit $1.7 million per incident, up 11% year over year
- 48% of victims with encrypted data still paid
So fewer mega-ransoms, yes. But more attacks reaching their goal, and recovery getting more expensive even when no ransom is paid. That is not a problem shrinking. That is a problem changing shape.
Where the Pressure Went
Look at who is actually getting hit:
- Over two-thirds of ransomware attacks in 2024-2025 targeted businesses with fewer than 500 employees, per VikingCloud’s analysis
- Ransomware shows up in 88% of small business attacks, versus 39% of breaches at large companies
- Sophos found only 34% of small organizations (100 to 250 employees) stopped attacks before data was encrypted. Larger firms managed 46%
That last statistic is the whole story in one line. Big companies increasingly catch the attack in progress. Small companies increasingly find out when the ransom note appears.
Why Attackers Moved Downstream
Ransomware crews do math like any business. Large enterprises spent the last five years investing in detection and response, tested backups, and cyber insurance policies that come with negotiators. More of them refuse to pay. Hitting them costs more and pays worse, which is exactly why demands at the top collapsed.
Small businesses offer the opposite deal: thinner defenses, no security staff, backups that have never been tested, and owners for whom a week of downtime is an existential threat. A $50,000 demand a small business will actually pay beats a $5 million demand a hardened enterprise will not.
We saw the same dynamic in the Stryker cyberattack: attackers go where the return is, and the return is increasingly in the mid-market and below.
What the Resilient Businesses Do Differently
The encouraging part hiding in Sophos’ data: among businesses whose data was encrypted, 66% recovered using backups, up 12 points in a year. The playbook that made large companies expensive targets is not secret, and most of it scales down:
- Backups that actually restore. Offline or immutable copies, tested quarterly. A backup you have never restored from is a hope, not a plan
- Detection and response on every device. Modern EDR/MDR tooling is affordable at small-business scale now. The 34% versus 46% gap above is largely this
- MFA everywhere that matters. Email, remote access, admin accounts, banking
- Patching on a schedule, not a whim. Most ransomware still walks in through known, unpatched holes and phished credentials
- A written incident plan. Who do you call first? Where are the backups? Who talks to clients? Deciding during the attack is the expensive way
- Know your insurance. Read the security requirements on your cyber policy before you need it. Gaps there become denied claims
None of this requires an enterprise budget. As we argued in Why Cybersecurity Is No Longer Optional for Mid-Sized Businesses, it requires deciding that “too small to be a target” is a myth the data retired years ago.
The Bottom Line
Falling ransom payments are a scoreboard for companies that invested in defense. The attackers did not quit. They re-priced, re-tooled, and aimed at businesses that have not made those investments yet. Whether the headline trend is good news for you depends entirely on which side of that line you are standing on.
Want to know whether your business would catch an attack before the encryption starts? We can assess where you stand and close the gaps that matter most. Contact us today.
Sources:

Comments are closed