A Quiet Number That Should Be Setting Off Alarms
Every year, Sophos publishes its State of Ransomware report based on a vendor-agnostic survey of thousands of IT and cybersecurity leaders. The 2025 edition surveyed 3,400 respondents across 17 countries, including 1,733 from enterprise organizations (1,000+ employees). The headline findings make for compelling reading: data encryption rates are falling, recovery is getting faster, and more organizations are refusing to pay the ransom.
But buried inside the enterprise data is a number that ought to be on every CISO's whiteboard:
The use of backups to recover from ransomware attacks dropped from 73% in 2024 to 53% in 2025 — a four-year low.
Read that again. In the year when defenders supposedly got better at stopping ransomware, they got measurably worse at relying on their own backups to recover from it.
This is not a minor footnote. It is the most strategically important finding in the entire Sophos dataset — and almost no one is talking about it.
At BackupSec, we read the 2025 Sophos report differently than most analyst summaries did. The headline numbers tell one story; the underlying operational data tells another. This article walks through what we believe the report actually reveals about modern ransomware resilience — and why backup confidence has quietly become the most important metric in enterprise cyber defense.
The Surface Narrative: Defense Is Winning
Let's start with the good news, because there is genuinely some.
According to Sophos:
- Data encryption rates fell to 50% globally — the lowest level in the six-year history of the report, down from 70% the year before.
- In enterprise organizations, encryption rates dropped to just 49%, down from 66% in 2024.
- The percentage of attacks stopped before encryption more than doubled over two years — from 22% in 2023 to 47% in 2025.
- The average cost of recovery dropped from $2.73 million to $1.53 million globally.
- The median ransom payment fell by 50% — from $2 million in 2024 to $1 million in 2025.
- 53% of organizations fully recovered within one week, up sharply from 35% the year before.
If you read only these numbers, you would conclude that the industry has turned a corner. EDR is maturing. Detection times are dropping. Negotiation is becoming more sophisticated. Insurance carriers are pushing harder on minimum controls. All true.
But then you arrive at the recovery data — and the story stops making sense.
The Contradiction That Reveals Everything
Here is the data point that breaks the optimistic narrative:
Across enterprise organizations hit by ransomware in 2025, only 53% used backups to recover their encrypted data. That number was 73% just one year earlier. Meanwhile, 48% of enterprises paid the ransom anyway — broadly flat versus prior years.
In other words: encryption is happening less often, but when it happens, fewer organizations trust their backups to get them out. They reach for the wallet instead.
Sophos's own analysis frames this as "reduced confidence in backup recovery capabilities." That is a polite way to say something sharper:
The backup infrastructure that enterprises were told would protect them is, in real incidents, failing to deliver.
This is the contradiction at the heart of the 2025 report. Defenders are getting better at stopping attacks early. But the moment an attack actually succeeds and data gets encrypted, the recovery layer that should be the safety net is increasingly being bypassed in favor of paying criminals.
That is not a story about ransomware getting harder. That is a story about backup architecture getting exposed.
Why Are Backups Failing at the Moment of Truth?
The Sophos report does not directly answer this question, but the surrounding data points connect into a coherent picture. From an architectural standpoint, three patterns explain the collapse in backup confidence.
Pattern 1: Backups Are Being Compromised Alongside Production
The 2025 report shows that 75% of ransomware attacks now involve data exfiltration before encryption. That means modern threat actors are spending days or weeks inside the network, identifying and accessing critical systems — including backup infrastructure — before they ever deploy the encryption payload.
In incident-response engagements we observe across the industry, this dwell time is consistently used to do one specific thing: locate the backup repository, harvest its credentials, and either encrypt it, corrupt it, or delete its retention policies hours before the production payload detonates.
If your backup system shares a domain, an identity provider, or a credential set with your production environment, it is not a recovery layer. It is the second target on the kill chain.
Pattern 2: "Backup Success" Does Not Equal "Restore Success"
Sophos's data shows the human cost clearly: all respondents in organizations that had data encrypted reported that their IT/cybersecurity teams were impacted in some way. Increased stress (40% of enterprise respondents), increased pressure from senior leadership (41%), and leadership changes following the incident were all common outcomes.
A pattern that recurs in these stories is that the team discovers, mid-incident, that the backups they have been operating for years cannot actually be restored at the speed or completeness the business requires. The job logs say "success." The restore tells a different story.
This is exactly the failure mode the "0" in the 3-2-1-1-0 rule was designed to address: zero errors in backup verification. But verification is something most organizations claim to do and very few do continuously, at scale, against the actual recovery scenarios they will face in a real incident.
Pattern 3: The Organizational Layer Is the Weakest Link
For the first time in 2025, Sophos asked respondents about the organizational factors that contributed to their being hit. The findings are striking:
- 40.2% cited "lack of expertise" — insufficient skills or knowledge to detect and stop the attack in time.
- 40.1% cited "unknown security gaps" — weaknesses in defenses they were unaware of.
- Respondents identified an average of 2.7 contributing factors per incident.
Translate this from survey language: enterprise security teams know they are under-resourced, know they have blind spots, and know that complexity has outpaced their ability to manage it. Backup infrastructure — typically the least-loved, least-modernized layer of the enterprise stack — sits right at the intersection of all three weaknesses.
When the people who run your backup environment are the same people running incident response, patching, identity, and a dozen other priorities, the backup layer does not get the architectural attention it needs. And so when it is asked to deliver in an incident, it doesn't.
What the Industry-Specific Reports Add to the Picture
Sophos published several sector-specific cuts of the 2025 data, and each adds nuance worth attention.
In manufacturing, encryption rates fell to a five-year low of 40%, but the median ransom paid still reached $1 million, and 47% of manufacturers reported increased team stress after an incident. The sector's dependency on operational continuity — where minutes of downtime ripple through entire supply chains — makes recovery confidence existentially important.
In retail, 46% of incidents were traced to an unknown security gap, and 58% of organizations with encrypted data paid the ransom — the second-highest payment rate in five years. Median ransom demands in retail doubled to $2 million.
The pattern across sectors is consistent: organizations are getting better at stopping attacks. They are not getting proportionally better at recovering from them. The gap between prevention maturity and recovery maturity is widening — and that gap is where ransom payments live.
What the Sophos Report Recommends (And What It Leaves Out)
Sophos's own recommendations focus on four areas: prevention, protection, detection, and response. These are sensible and well-supported by the data. Specifically, the report recommends:
- Eliminating common technical and operational root causes (exploited vulnerabilities, weak identity controls).
- Strengthening foundational security with hardened configurations, MFA, and patch discipline.
- Investing in Managed Detection and Response (MDR) capabilities.
- Preparing detailed incident response plans.
All correct. All necessary. But there is a fifth pillar the report does not center, and the 2025 backup-usage numbers are the reason it should:
Recovery architecture itself must be modernized — not just defended.
A backup environment designed to recover from hardware failures and accidental deletions is not the same as a backup environment designed to recover from a determined adversary who has been inside the network for two weeks. The first is a redundancy problem. The second is an architectural problem. And the data shows that most enterprise backup environments are still operating as the first.
The Backup Confidence Gap: What to Measure Instead
If you take only one operational change away from the Sophos 2025 report, let it be this: stop measuring backup success rate, and start measuring backup confidence.
Backup success rate is the metric your backup software gives you for free. It says: "Did the job complete?" That metric is now meaningless as a recovery indicator. Threat actors know it, defenders are slowly learning it, and the gap between what the dashboard shows and what an incident actually delivers is precisely where the 20-point drop in backup-based recovery came from.
Backup confidence is a different metric. It asks:
- Can we restore tier-one systems from immutable storage within our stated RTO, today, under contested conditions?
- Do our recovery procedures work when production identity providers are compromised?
- Have we validated that our retention policies cannot be modified by any production-tier credential?
- Do we monitor backup-system telemetry for adversary behavior — not just job completion?
- When the IR team is asked "should we pay?" — what is the technical basis for the answer?
These questions have answers. Most enterprises do not currently know what theirs are, and the Sophos data is the consequence of that uncertainty playing out at scale.
What We Take From the 2025 Sophos Data
Reading the full report carefully, the story we see is not the one most summaries told. It is this:
The industry has gotten meaningfully better at preventing ransomware from reaching its full payload. That is a real and important improvement, and it deserves recognition.
But the recovery layer — the architectural promise that organizations would never have to pay ransom because they could restore from clean backups — is being quietly hollowed out. The 20-point drop in backup-based recovery is the smoke. The architectural gap underneath is the fire.
For enterprises operating in regulated sectors, managing complex hybrid estates, or simply unwilling to fund the next ransomware campaign with their own treasury, this is the priority conversation for 2026. Not "do we have backups?" — every organization in the Sophos survey had backups. The question is: does our backup architecture survive a real adversary, and can we prove it before we need it?
How BackupSec Approaches the Confidence Gap
At BackupSec, we built our service around the premise that backup environments must be observable, advisable, and provable under adversarial conditions — not just operational under nominal ones. Every element of our approach maps to the failures the Sophos data exposes:
- ZeroMON — our observability platform — provides continuous monitoring of backup operations and security signals: real-time job tracking, configuration drift alerts, forensic audit trails, capacity analytics, and Veeam-ready visibility. This is the layer that catches the silent backup failures the Sophos data implies. It is the operational answer to "are our backups actually doing what the dashboard says they are doing?"
- ZeroTAM — our expert advisory service — gives enterprise teams a dedicated backup security advisor for architecture reviews, ransomware recovery planning, capacity strategy, and crisis response. This is the human layer that addresses the "lack of expertise" finding cited by 40.2% of Sophos respondents — without rotating support tickets or generic guidance.
- ZeroPEN — our backup penetration testing and recovery validation service — directly addresses the 53% backup-usage gap. We pentest your backup management planes, access controls, immutability settings, and isolation posture the way an actual adversary would. Then we run real restore scenarios against your RTO/RPO targets and verify that the recovered data is clean, complete, and free from attacker persistence. The output is not a list of findings — it is documented evidence that recovery works.
BackupSec is deployed on-premise. We connect through read-only API access. Your backup data, telemetry, and configuration details never leave your environment. We do not replace your backup platform — we make the one you already operate observable, advisable, and provable.
The 53% backup-usage rate in the Sophos enterprise data is not destiny. It is the consequence of an architectural era that is ending. The organizations that close the confidence gap in the next twelve months will be the organizations that stop appearing in the "paid the ransom" column of next year's report.
Talk to BackupSec about validating your recovery readiness →
This analysis draws on the Sophos State of Ransomware 2025 report and related sector-specific publications. The interpretation and framework presented here are BackupSec's own. To discuss how the 2025 findings apply to your specific environment, get in touch with our team →
