TechSignal.news
Cybersecurity

79% of Ransomware Attacks Now Start With Compromised Identities, Not Software Flaws

Sophos data shows identity-based attacks overtook vulnerabilities as the primary ransomware entry point. Recovery costs average $1.7 million per incident.

TechSignal.news AI4 min read

Identity Compromise Becomes the Primary Attack Vector

Ransomware attackers have shifted tactics. According to Sophos' 2026 State of Ransomware report, 79% of ransomware incidents now begin with compromised identities rather than exploited software vulnerabilities. That reversal changes budget priorities. Enterprises that still allocate the majority of security spend to patching and vulnerability management are defending against yesterday's threat model.

The financial impact is concrete: average recovery cost is $1.7 million per incident, with a median ransom payment of $769,000. Those figures reflect the full operational cost — forensics, business interruption, remediation, and potential payment — not just the ransom demand. For comparison, 56% of attacks still encrypted data, and 66% of those encrypted cases relied on backups for recovery. That means backup integrity is now a ransomware defense control, not just a disaster recovery tool.

For enterprise buyers, this data points to budget reallocation. Identity protection, secure email controls, MDR/XDR, and tested immutable backups now carry more weight than endpoint-only or patch-centric strategies. Vendors whose positioning still centers on vulnerability scanning face a harder sell. Microsoft, CrowdStrike, Palo Alto Networks, SentinelOne, and backup-recovery vendors like Veeam gain ground because their platforms address identity and recovery, not just detection.

Mid-Market Firms Are the Primary Target

Black Kite's analysis of 13,336 ransomware incidents, published August 18, reveals that 73% of attacks struck companies with $10 million to $1 billion in annual revenue. The pattern held stable from 2023 through the first half of 2026, meaning mid-market targeting is not a temporary shift — it is the baseline.

This contradicts the assumption that ransomware focuses on large enterprises with deep pockets. Mid-market firms represent a higher volume of accessible targets with less mature defenses and smaller security teams. For CISOs in that revenue band, the buying implication is direct: third-party risk management, external exposure monitoring, and recovery readiness are not enterprise-only concerns. They are primary controls for the segment ransomware operators actively prefer.

Vendors competing in this space are splitting into two camps. Premium enterprise suites with heavyweight perimeter tooling face competition from mid-market-focused offerings that prioritize faster deployment, clearer ROI, and third-party risk visibility over comprehensive platform stacks. Black Kite's findings give mid-market buyers justification to invest in controls previously considered above their threat profile.

Recovery Models Move Toward Managed Services

Ransomware defense is increasingly sold as a service rather than software. SysGroup secured two three-year cyber resilience contracts worth over £1 million combined, using Rubrik's technology platform. SysGroup is the first UK and Ireland managed service provider to join Rubrik's MSP PayGo program, signaling a shift toward consumption-based commercial models.

For enterprise buyers, this changes procurement. Managed cyber resilience reduces up-front capital expense but increases dependency on a provider's recovery capability. The trade-off is operational: you reduce the burden on internal teams but must validate the MSP's recovery SLAs and incident response speed before an attack occurs. Rubrik's channel strategy also creates competitive pressure on Veeam, Commvault, and Cohesity, which are pursuing similar MSP partnerships to widen distribution.

The broader pattern is clear. Ransomware defense budgets are moving away from "can we prevent intrusion?" and toward "can we stop identity abuse, recover quickly, and operationalize resilience?" Prevention remains important, but recovery capability and identity controls now determine whether an incident becomes a catastrophic loss or a contained event.

What to Watch

Expect vendor messaging to shift toward identity security and backup integrity. Sophos launched its Fusion platform with positioning around identity-first defense, and competitors will follow. Watch for pricing pressure on pure endpoint vendors that lack identity or recovery capabilities.

For buyers, the decision point is whether your current stack addresses the 79% of attacks that start with compromised credentials. If your last security review focused on patching cadence and endpoint detection, the threat model has moved. Budget reviews should prioritize identity controls, phishing-resistant authentication, DMARC/DKIM/SPF implementation, and validated backup recovery tests. The cost of not doing so is now quantified: $1.7 million per incident.

ransomwareidentity securitycybersecuritybackup and recoverymid-market

Technology decisions, clearly explained.

Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.

More in Cybersecurity