A recent report from cybersecurity firm Sophos has revealed that recovering from a ransomware attack is costing organisations in South Africa an average of R17m. This significant financial burden highlights the ongoing risk of ransomware attacks to businesses. Ransomware attacks involve hacking a company’s systems, stealing data, and threatening to release that data unless a ransom is paid. In some cases, attackers take control of critical systems, crippling business operations until a payment is made.
The Sophos report, titled “State of Ransomware in South Africa 2026,” is based on responses from 135 IT and cybersecurity leaders at South African organisations that experienced attacks in the previous 12 months. The report notes that while the average cost of recovering from a ransomware attack decreased from R21m in 2025 to R17m, it remains a considerable financial burden. The median ransom demanded from South African organisations fell by 57%, from R16m last year to R6.8m, and the median ransom payment decreased by 28% to about R5m.
Ransomware attacks often begin with an identity, device, or security weakness that the organisation is aware of, according to Pieter Nel, regional head for Sadc at Sophos South Africa. The report found that 63% of ransomware incidents in South Africa resulted in data being encrypted over the past year, exceeding the global average of 56% and increasing from 60% reported in 2025. This suggests a strong connection between ransomware and identity-based attacks in South Africa.
The report also revealed that 85% of South African organisations surveyed reported that their ransomware incident was the same event as their most significant identity attack during the year. This is significantly higher than the global average of 67%. Nel emphasised that addressing these risks requires strong identity controls, properly configured security technologies, and sufficient skilled capacity to monitor and respond to threats.
The findings from Sophos, combined with those from other sources, paint a concerning picture of the risk to organisations and individuals. According to the Allianz Risk Barometer, cyberincidents, including ransomware attacks, data breaches, and IT outages, are now the top global business risk. A decade ago, only 12% of global respondents cited cyberattacks as a major concern, but this number surged to 38% in 2025.
Israeli cybersecurity firm Check Point Software Technologies recently reported that South African businesses, particularly in the corporate sector, face an average of 1,863 attacks per organisation per week. Organisations in South Africa have generally been reluctant to disclose losses due to cyberbreaches or admit when they occur, fearing reputational damage. To protect their information and data, Sophos recommends strengthening identity security by implementing an identity threat detection and response system and enforcing multi-factor authentication.
Sophos advises organisations to regularly audit human and nonhuman credentials to safeguard their information and data. Nel noted that the most effective response to ransomware attacks begins before the attack, by closing the gaps that allow criminals to enter the environment. The impact of ransomware attacks can be severe, as seen in the recent cyberattack at Mustek subsidiary Rectron, which affected certain IT systems and operations, resulting in unlawful access to certain data.
Key points
- The average cost of recovering from a ransomware attack in South Africa is R17m.
- 63% of ransomware incidents in South Africa resulted in data being encrypted over the past year.
- Organisations can mitigate risks by strengthening identity security and implementing multi-factor authentication.