The Ransomware Recovery Figure Everyone Quotes Is the Wrong Average
Sophos reports a USD 375,000 median ransomware recovery cost and a USD 1,700,200 mean. Both are real. Quoting the wrong one in front of your CFO costs you the room.
Introduction
Two numbers describe the same event. Sophos puts the cost of rectifying the most significant ransomware attack at a median of USD 375,000. It puts the mean at USD 1,700,200. Same survey, same respondents, same question, and both figures exclude any ransom paid.
The gap is not a typo. It is the shape of the risk. And the way most people quote it costs them credibility in the exact meeting where they need it.
Two numbers, one survey
The source is The State of Ransomware 2026 from Sophos, seventh edition. Vanson Bourne surveyed 2,158 organisations of 100 to 5,000 employees across 17 countries between January and March 2026. Respondents reported what it cost to rectify the impacts of their most significant ransomware attack. Ransom payments were excluded.
| Median recovery cost | USD 375,000 |
| Mean recovery cost | USD 1,700,200 |
| Respondents under USD 250,000 | 33% |
| Respondents under USD 500,000 | 51% |
| Sample | 2,158 organisations, 100-5,000 employees, 17 countries |
About a third of victims came in under a quarter of a million dollars, and just over half under half a million. The median has not moved since the previous edition. The mean is more than four and a half times larger.
Why the mean is so much bigger
The distribution has a long right tail. Twenty-nine percent of respondents reported recovery costs above USD 1 million, and 10% above USD 5 million. That upper third of the distribution pulls the mean far above the typical case while leaving the midpoint almost untouched.
Which means the two numbers answer different questions.
The median answers: what does a ransomware incident typically cost an organisation like this one? Around USD 375,000, excluding ransom. Painful. Survivable for most companies with a real balance sheet.
The mean answers: what is the expected value of the loss if I model this event many times? USD 1,700,200. That number is inflated by the tail, and the tail is the part that closes companies.
Here is the practical failure mode. You put the mean in a board deck because it is the scarier number. Your CFO finds the median in the same report inside ten minutes. Now every other figure you present gets discounted. You did not only lose the argument. You lost the standing to make the next one.
The opposite mistake is quieter and worse. Quote only the median, and the board decides USD 375,000 is a manageable one-off, so nobody funds the control that exists to prevent the tail event. Median-only framing understates exactly the risk that justifies the spend.
The qualifiers that have to travel with the numbers
If you use these figures, carry three caveats with them.
- Both exclude the ransom. If a payment is made, it lands on top of the recovery cost, not inside it.
- The sample starts at 100 employees. This is not a benchmark for a 20-person engineering firm in Conroe. A company that size does not have USD 375,000 of downtime to lose. The distribution shape is still instructive. The dollar figures are not yours.
- It is self-reported survey data. Respondents estimate their own costs after the fact, and the worst-hit organisations are not always able to answer surveys. Treat it as the best available structured sample, not audited accounting.
Naming those limits is not weakness. It is why the rest of your analysis gets believed.
Ransom paid is a third number, and it gets swapped constantly
The Verizon 2026 Data Breach Investigations Report found ransomware present in 48% of confirmed breaches, up from 44% in the prior report. It also found that 69% of victim organisations did not pay at all, up from 65%. Among those who did pay, the median amount actually paid was USD 139,875, down from USD 150,000.
Now hold that against Sophos. The same survey puts the median ransom payment at USD 769,000, from the 530 organisations that paid. Two credible sources, one concept, a 5.5x spread. Both are right about different populations: Sophos surveys ransomware victims of 100 to 5,000 employees, while Verizon's incident dataset spans all organisation sizes and breach types, which pulls its midpoint down. That is this article in one comparison. A payment figure without its population attached is a talking point, not a benchmark.
Read that last figure carefully. It is the median amount paid. It is not the median amount demanded. Those two get swapped constantly, and the substitution flatters negotiation. Sophos found the median payment came in at 90% of the demand among the 507 organisations reporting both, though 30% paid the demand in full and 18% paid more. Because the two medians come from different subsets, the population-level median payment of USD 769,000 sits above the median demand of USD 698,000. If a source does not say which one it is quoting, do not use it.
The more useful signal is the payment rate. Most victims refuse, and the refusal rate is climbing. That happens when organisations have restore paths they trust.
The statistic to stop repeating
You have seen the claim that 60% of small businesses close within six months of a cyberattack. Do not use it. The National Cybersecurity Alliance, credited as the source, disavowed it in 2022, and no primary study supporting it has ever surfaced. It circulates because it is a good line, not because it is true.
Cutting it from your deck does more for your credibility than any statistic you could add.
The number you can actually control
Sophos and Verizon describe a population. You operate one company. Those statistics give you the shape of the risk, not your position in it. Three things determine that, and all three are measurable in your own environment.
Detection speed. How long between initial access and the first alert a human acted on? Automated 24/7 monitoring shortens that window; a mailbox nobody reads by 6pm does not. This is where most of the tail risk gets decided, because dwell time is what lets an attacker find and destroy the backups.
Whether your backups actually restore. Not whether the job reports success. Whether a full restore of a business system completes, on hardware you have, in a time you have measured. Immutable or offline copies matter, because backup destruction is a standard step in the attack, not bad luck. The honest limitation: a clean restore returns you to your last good point, so it caps the loss rather than erasing it, and it does nothing about data already stolen.
Whether you can operate degraded. If the ERP is down for four days, can you still ship, invoice, and pay people? Sophos asks respondents to fold downtime, people time, device and network cost, and lost opportunity into one total, and does not break out the shares. Downtime is the component manual workarounds shorten most directly. They are unglamorous, and they reduce the number more than most security tooling does.
Tightening administrative access sits underneath all three. Privileged access management and endpoint controls are part of a working cybersecurity program, and they are most effective when someone owns them day to day rather than at audit time. If nobody owns that in your organisation, that is what managed IT services are for.
So here is the question worth asking your team this week: when did you last run a timed, full restore of a business-critical system, and how long did it take? A date beats a shrug. If nobody knows, that is your finding.
Frequently Asked Questions
Should I budget the mean or the median for ransomware recovery?
Use both, and say why. The median of USD 375,000 from Sophos, The State of Ransomware 2026, describes the typical incident and is the right figure for baseline planning. The mean of USD 1,700,200 from the same survey reflects a long right tail of severe incidents and belongs in the case for controls that prevent worst-case outcomes. Present one without the other and your CFO will find the other.
Do those Sophos figures include the ransom payment?
No. Both the USD 375,000 median and the USD 1,700,200 mean are costs to rectify the impacts of the attack, excluding any ransom paid. A payment lands on top.
Is the median ransom payment the same as the median ransom demand?
No, and they are confused constantly. Sophos reported a median payment of USD 769,000 against a median demand of USD 698,000, and among the 507 organisations reporting both, the median payment was 90% of the demand, with 30% paying in full and 18% paying more. Verizon, drawing on a different population, reported a median payment of USD 139,875. If a source does not specify which figure it reports, or which population it came from, do not cite it.
Is it true that 60% of small businesses close within six months of a cyberattack?
There is no primary research behind that claim. The National Cybersecurity Alliance disavowed it in 2022. Leave it out of your reporting.
What single test best predicts how a ransomware event will go for us?
A timed, full restore of a business-critical system to hardware you actually have. Backup jobs that report success are not evidence. A completed restore with a measured duration is. Our free IT assessment covers this among other recovery readiness questions.
Talk it through
If you want a second set of eyes on your restore times, backup immutability, or privileged access before you have to test them under pressure, call us at 713-571-2390. LayerLogix brings 20+ years of experience and 100% Texas-based support, with offices in The Woodlands and Round Rock. Business-hours support with after-hours emergency response, and automated monitoring that does not keep office hours.
Need Help With Cybersecurity?
LayerLogix provides expert cybersecurity solutions for businesses across Houston and nationwide.
Related Articles
Need Expert IT Support?
Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.