The Most Boring Finding in the 2025 Sophos Report Is Also the Most Important
Every year, the ransomware conversation gets louder about new attack techniques. AI-generated phishing. Deepfake social engineering. Adversarial machine learning. Living-off-the-land binaries. Supply chain compromises through obscure dependencies. The narrative reliably suggests that defenders are facing a fundamentally new threat that requires fundamentally new tools.
And every year, the Sophos State of Ransomware report returns from a vendor-agnostic survey of thousands of victims with the same unfashionable answer.
For the third year running, exploited vulnerabilities are the most common technical root cause of ransomware incidents — responsible for 32% of attacks in 2025.
Not novel AI techniques. Not zero-days. Not exotic supply chain attacks. Patches that existed but were not applied. Configurations that were known to be wrong. CVEs with public exploits and vendor advisories that landed in a queue and never came out.
This is the finding that should make every enterprise security leader uncomfortable, because it cannot be solved by buying a new tool. It is a structural problem with how enterprise environments accumulate technical debt — and the 2025 data suggests that no amount of investment in advanced detection is closing it.
At BackupSec, we read the persistence of vulnerability exploitation as the #1 root cause as a strategic signal: the gap between known security weaknesses and closed security weaknesses is the single most reliable predictor of which organizations will appear in next year's "paid the ransom" column. This article unpacks why that gap persists, why it cannot be closed by prevention alone, and what the architectural implications are for organizations operating in 2026.
What the Sophos Data Actually Shows
The 2025 Sophos report surveyed 3,400 IT and cybersecurity leaders across 17 countries, all from organizations that had been hit by ransomware in the previous twelve months. When asked about the technical root cause of their incident, the breakdown was remarkably consistent year over year:
- Exploited vulnerabilities: 32% of attacks — the #1 cause for three consecutive years.
- Compromised credentials: 23% — down from 29% in 2024.
- Malicious email: 19%.
- Phishing: 18% — up from 11% the previous year.
The sector-specific reports reinforce the pattern. In manufacturing, exploited vulnerabilities accounted for 32% of incidents — again the leading cause. In retail, the figure was 30%, also leading. Across virtually every industry cut Sophos published, the same finding persists: a third of all successful ransomware attacks start with a vulnerability the vendor has already patched, the security team is theoretically aware of, and the attacker simply got to first.
What makes this finding strategically important is not just its consistency. It is the fact that it has remained the #1 cause despite three years of intense industry investment in vulnerability management tools, attack surface management platforms, exposure assessment services, and patching automation. The investment has been substantial. The outcome has been unchanged.
That should tell us something architectural about the problem.
Why Patching Fails — Even When Organizations Do It
The intuitive response to "32% of attacks start with known vulnerabilities" is "then patch faster." This response is correct but operationally insufficient, and the reasons it falls short are worth examining honestly.
The denominator problem. A typical mid-sized enterprise manages thousands of distinct software components across operating systems, applications, firmware, container images, and SaaS configurations. Vendor advisories arrive continuously. Even a security team operating at the top of its game cannot patch every component on the day a CVE is published. The denominator of "things that could be exploited" is structurally larger than the bandwidth of "things that can be patched this week."
The criticality problem. Many patches require downtime, regression testing, or coordination with business owners who are protecting revenue continuity. The systems that most need patching — the externally facing applications, the legacy production systems, the OT and industrial control infrastructure — are often the ones where the business cost of downtime is highest. So patches get scheduled, deferred, batched, and eventually forgotten. Attackers know this; they specifically target the categories of systems most likely to carry maintenance debt.
The discovery problem. You cannot patch what you cannot see. Sophos's own data shows that unknown security gaps were cited by over 40% of victims as contributing factors. In retail specifically, 46% of incidents traced back to unknown gaps. These are not vulnerabilities organizations chose not to patch — they are vulnerabilities organizations did not know they had. Shadow IT, undocumented systems, forgotten cloud workloads, third-party integrations with their own dependency trees: the modern enterprise attack surface is genuinely difficult to enumerate, and the gap between what your asset inventory shows and what an attacker can actually reach is where most exploited vulnerabilities live.
The window problem. Even when a vulnerability is known and a patch is available, the time between disclosure and active exploitation has compressed dramatically. Threat actors monitor vendor advisories with the same diligence security teams do, and weaponized exploits for high-impact CVEs now routinely appear within days — sometimes hours — of disclosure. The patching window that existed five years ago no longer exists for any vulnerability serious enough to attract attention.
None of these problems are solved by buying another vulnerability management tool. They are structural features of how enterprise environments work, and they explain why the 32% figure has not moved in three years despite enormous defensive investment.
The AI Distraction
Worth addressing directly: the 2025 Sophos data is also a useful corrective to the dominant narrative about AI-driven attacks.
The industry conversation in 2025 was heavily oriented around AI-generated phishing campaigns, deepfake-driven social engineering, and machine-learning-enabled evasion. These threats are real, and they deserve attention — particularly given research showing that a large majority of phishing emails now contain AI-generated content.
But the Sophos data is a useful reality check on where dollars and attention should actually be allocated. AI-enhanced phishing is contributing to the rise in phishing-related incidents (from 11% to 18% year over year). It is not, however, displacing vulnerability exploitation as the dominant entry vector. The third of all attacks that start with unpatched systems is not getting smaller because attackers have access to better language models. If anything, the AI conversation has functioned as a distraction from the unglamorous, structural problem that has been quietly causing a third of all ransomware incidents for three consecutive years.
The strategic implication for enterprise risk leaders is to be skeptical of any vendor narrative that suggests the most important defensive investment is the newest one. The Sophos data points in a different direction: the most important defensive investment may be the one that makes the boring, structural problem of vulnerability management less load-bearing for overall outcomes.
What "Less Load-Bearing" Actually Means
Here is the architectural insight that follows from accepting that vulnerability exploitation cannot be fully eliminated: if a third of all attacks will continue to start with a patch you did not apply in time, then the strategic question shifts from "how do we patch faster?" to "what happens when we don't?"
This is the question most enterprise security architectures are still avoiding.
In a defense model where prevention is assumed to work, vulnerability exploitation is treated as a failure that needs to be eliminated. In a defense model that takes the Sophos data seriously, vulnerability exploitation is treated as a recurring condition that the rest of the architecture must absorb without producing catastrophic outcomes.
The shift from elimination to absorption is the same architectural shift that mature reliability engineering went through a decade ago. You do not eliminate failure in distributed systems. You design systems that degrade gracefully when failures occur. You measure mean time to recovery, not just mean time between failures. You treat resilience as a primary architectural property, not as a secondary cleanup after prevention fails.
Enterprise security is, very slowly, beginning to apply the same logic. The Sophos 2025 data is, in our reading, the strongest empirical evidence yet that this transition is overdue.
Where Backup Architecture Becomes the Pivot Point
When a vulnerability is exploited and an attacker establishes a foothold, the chain of events that follows is well documented: lateral movement, privilege escalation, reconnaissance of valuable data, exfiltration, and eventually payload deployment. Modern threat actors spend an average of 12 to 22 days inside compromised environments before deploying ransomware — time they use specifically to identify and neutralize the controls that would otherwise enable recovery.
The single most important of those controls is the backup environment.
If your backup infrastructure can be reached from a system that started with an exploited vulnerability, then the vulnerability did not just enable an attack — it enabled the attack to win. The exploited CVE on an internet-facing application becomes architecturally significant not because of what it does on the host where it was exploited, but because of what it enables an attacker to do to your recovery layer over the following two weeks.
This is the architectural pivot point the Sophos data implies. Vulnerability exploitation will continue to be the #1 root cause for the foreseeable future. The variable that determines outcomes is whether your recovery architecture is reachable from the systems where those vulnerabilities will inevitably be exploited.
Concretely, this means:
Identity separation. The credentials that protect production systems must not grant access to backup infrastructure. If a compromised domain administrator account can reach your backup repository, your backups are part of the attack surface that the unpatched vulnerability exposed.
Validated immutability. Software-based retention policies can be modified by anyone with sufficient privilege. Hardware-enforced or platform-enforced retention locks are designed to resist that — but the gap between "configured" and "actually working as intended" is where many enterprise backup environments fail in real incidents. Whether your immutability is enforced by your backup platform, your storage layer, or a hardened repository, the property that matters is whether it has been tested under adversarial conditions, not merely enabled in a settings panel.
Network and trust isolation. A backup environment that sits on the same network domain as production systems is part of production from a threat-modeling perspective. Logical and physical isolation are what convert backup infrastructure from "another target" into "the layer that survives when other targets do not."
Continuous restore validation. A backup that has not been tested against the specific conditions of a real attack is a hypothesis, not a control. The 2025 data shows that 53% of enterprises did not use backups to recover from successful ransomware incidents, despite having backups. The most likely explanation is that the backups they had were never validated against the scenarios that actually played out. Architecting against that failure mode requires testing, not just running.
The Strategic Reframe
For enterprise risk leaders, the persistence of vulnerability exploitation as the #1 root cause is not an indictment of vulnerability management programs. It is evidence that vulnerability management — however well executed — is structurally incapable of carrying the full weight of ransomware defense on its own.
The Sophos finding that 32% of attacks start with known vulnerabilities should be read alongside the finding that 48% of enterprise victims paid the ransom. Those numbers are connected. They describe a defensive posture in which prevention is asked to be infallible because the recovery layer cannot be relied on. The strategic correction is not to make prevention more infallible — it is to make recovery reliable enough that prevention failures do not determine business outcomes.
That correction is architectural. It is also overdue. The organizations that close the gap in the next twelve months will be the ones whose recovery layer can absorb the inevitable third-of-incidents that will continue to start with an unpatched system. The organizations that do not will continue to appear, year after year, in the same line of the Sophos report.
Where BackupSec Comes In
At BackupSec, our service is built on the premise that prevention will fail in roughly the proportion the Sophos data describes — and that the layer determining outcomes when it does is the recovery infrastructure that holds clean, isolated copies of business-critical data and the operational discipline that proves they can be restored.
Each of our three services addresses a specific gap that the persistence of vulnerability exploitation as the #1 root cause exposes:
- ZeroMON delivers continuous observability over backup operations, configuration drift, and security signals — so that when a vulnerability is exploited and an attacker spends two weeks inside the network, the reconnaissance activity targeting your backup environment is visible, not silent.
- ZeroTAM gives your team a dedicated backup security advisor for architecture decisions, capacity planning, and recovery strategy — addressing the structural expertise gap that determines whether your backup layer is reachable from the systems most likely to be compromised through unpatched vulnerabilities.
- ZeroPEN is, in our view, the most directly relevant response to the 32% finding. We pentest your backup management planes, access controls, immutability settings, and isolation posture the same way an attacker who started with an exploited vulnerability would — then we run real restore scenarios to validate that recovery works cleanly, completely, and on time. The output is not a list of findings to remediate. It is documented evidence that your backup layer survives the specific conditions the Sophos data describes.
BackupSec is deployed on-premise. We connect to your backup applications through read-only API access. Your backup data, telemetry, and configuration details remain inside your environment.
The 32% figure is not destiny. It is a description of a structural condition that determines outcomes only when the recovery layer is structured to fail alongside the prevention layer. Organizations that decouple the two stop being vulnerable to the dominant root cause of ransomware in 2026 — not because they patched faster, but because they validated that patching is not load-bearing for their recovery outcomes.
Talk to BackupSec about backup penetration testing and recovery validation →
This analysis draws on the Sophos State of Ransomware 2025 report and the broader 2025 ransomware research landscape. The interpretation and framework presented here are BackupSec's own. To discuss how this analysis applies to your specific environment, get in touch with our team →
