The latest findings reveal that over half of cybersecurity leaders are open to the idea of paying ransoms to cybercriminals to mitigate the impacts of ransomware attacks.
A significant 58 percent would consider such payments to prevent operational downtime, which 46 percent of respondents identified as the most severe consequence of ransomware intrusions.
Report Insights
The report, titled The Ransomware Reality: Zero Days to Recover, was published by Absolute Security. It draws insights from a survey conducted by Censuswide, involving 750 Chief Information Security Officers (CISOs) from enterprises based in the United States and United Kingdom.
"It is not surprising to learn that despite regulatory pressure, security and risk leaders remain open to paying a ransom to recover their systems and protect data when considering that prolonged downtime can lead to unsustainable losses," commented Christy Wyatt, President and CEO of Absolute Security. Wyatt emphasized that systems designed for rapid recovery from attacks could prevent enterprises from becoming ensnared in a cycle of increasing cyber threats.
Ransomware: A Chief Concern
Ransomware remains a top CISO concern, especially due to vulnerable endpoint infrastructuresRansomware remains a predominant threat on the agendas of CISOs, with a focus on the vulnerability of endpoint device infrastructures. Over the past 12 to 18 months, 57 percent of the surveyed leaders indicated that their organizations encountered attacks originating from remote, mobile, or hybrid devices, while 58 percent reported that these incidents left endpoints non-functional.
This aligns with telemetry research showing a failure in critical endpoint security controls 20 percent of the time.
Cyber Resilience Challenges
This report, the second in the State of Enterprise Cyber Resilience series, highlights additional challenges posed by ransomware. Notably, 83 percent of CISOs expressed confidence in their company's recovery capabilities; however, 57 percent said the recovery took up to six days, and 20 percent up to two weeks.
None reported being able to restore operations within a day. Furthermore, 59 percent of organizations stated the need for physical access to an endpoint for remediation and recovery, despite available remote recovery solutions, which only 53 percent employ.
Legacy System Patching Difficulties
Patching legacy systems emerged as the second most challenging method for mitigating ransomware attacks, cited by 42 percent of CISOs, surpassed only by Employee Awareness Training at 43 percent. With advancements like advanced language models accelerating vulnerability discovery, companies are challenged to address unpatched software risks efficiently.
Consequently, while patching is crucial, expediting recovery from evolving vulnerabilities should become a primary focus for maintaining security resilience.
Over half (58 percent) of cybersecurity leaders would consider paying cybercriminals to end a ransomware attack, with 46 percent ranking operational downtime as the most significant impact ransomware is likely to have on their organizations.
Report details
These are among findings revealed in The Ransomware Reality: Zero Days to Recover. This new report from Absolute Security includes results from a survey of 750 enterprise Chief Information Security Officers (CISOs) across the United States and United Kingdom, conducted by independent polling provider Censuswide
“It is not surprising to learn that despite regulatory pressure, security and risk leaders remain open to paying a ransom to recover their systems and protect data when considering that prolonged downtime can lead to unsustainable losses,” said Christy Wyatt, President and CEO, Absolute Security.
“CISOs who build systems that can quickly restore continuity after disruptive attacks can avoid getting trapped in a cycle which will only grow alongside cybercriminals’ increasing use of AI-powered attacks.”
Threat topping CISO's ledgers
Ransomware continues to top CISOs’ ledgers as one of the most menacing threats they face, with their endpoint device infrastructures significantly vulnerable. Over the past 12-18 months, 57 percent reported their enterprises experienced an attack that originated on a remote, mobile, or hybrid device, with 58% in agreement that an incident left endpoints inoperable.
Neither finding was unpredictable, when considering that additional telemetry-based research from millions of PCs revealed critical endpoint security controls fail to operate 20 percent of the time.
Cyber Resilience research series
This second edition in the State of Enterprise Cyber Resilience research series surfaced additional salient findings that further expose how ransomware is impacting operational resilience. Included in the report were additional results, including several top takeaways:
83% of CISOs reported being confident in their businesses’ ability to recover from ransomware, yet 57% took as long as six days to bounce back and 20% took as long as two weeks. No CISOs reported having the ability to recover within a day.
Despite knowing that ransomware continues to cause operational disruptions, 59% of organizations agree they must take physical possession of an endpoint to remediate and restore the device after an incident. Only 53% of organizations have remote recovery capabilities in place, despite the wide-spread availability of such tools.
Legacy system patching
CISOs reported that legacy system patching is the second most challenging ransomware mitigation method at 42% (this was only 1% behind the top-ranked challenge—Employee Awareness Training at 43%). With Claude Mythos showing that advanced LLMs in the hands of defenders and attackers can surface vulnerabilities at speeds the industry cannot keep pace with, organizations will face continued disruption caused by threats that leverage unmitigated software risks.
This means that while patching must remain a key security tactic, the ability to recover from increasing vulnerabilities and exploits must rise to the top of the priority stack.