According to Sophos, The State of Ransomware in the UK 2025, British businesses are experiencing significantly higher rates of data encryption and ransom demands than the global average.

The study, based on data from 201 UK organisationsthat have been hit by ransomware in the past year, reveals a worrying increase in both the intensity and cost of attacks. The data is part of a wider global analysis involving 3,400 IT/cybersecurity professionals from organisations that have been hit by ransomware.
Specifically, 70% of victims in the UK reported that their data was encrypted during the attack – a figure that far exceeds the global average of 50% and is a jump from the 46% recorded in the country in 2024. The main methods of access for cybercriminals were vulnerability exploitation (36%), malicious emails (20%) and compromised credentials (19%).
See also: Members of the Revil ransomware group released
The cost of attacks is also on the rise: the average ransom demand in the UK reached $5.4 million – more than double the $2.5 million recorded in last year’s Sophos report. In fact, 89% of attacks were accompanied by demands of more than $1 million (compared to 71% in 2024).
Even more worrying is the fact that British businesses are giving in to pressure (103%) and paying the ransom. The figure for other countries is 85%. This high rate is believed to be a result of the fact that more victims in the country lose access to their data due to encryption.
This picture stands in stark contrast to the general downward trend in ransom payments worldwide. According to data from Chainalysis, ransomware payments have fallen by 35% year-on-year, with experts estimating that cybercriminals are increasing demands to compensate for the decline in their overall revenue.
Sophos: British companies are recovering faster
The financial toll of ransomware attacks appears to be weighing heavily on UK businesses’ decisions. According to the latest Sophos report, the average cost of recovery will hit $2.6 million in 2024 – up half a million dollars on the previous year.
This amount includes not only the ransom, but also the cost of downtime, human resources, hardware, network infrastructure and lost business opportunities, as the cybersecurity company points out.
See also: Anubis ransomware acquires wiper module
However, within this risk landscape, there are also positive developments: organizations in the UK appear to be achieving faster recovery from ransomware attacks. According to the report, 59% of organizations reported fully recovering their data and operations within a week, a clear improvement from 38% the previous year. It is not yet clear whether this faster recovery is related to the higher payout rate.
At the same time, 99% of businesses that saw their data encrypted were able to recover it, a rate that is close to the global average. Despite recovery, however, remains risk of data leakageif attackers have already copied it.
Also notable is the drop in the rate of data theft in cases where encryption was present: in only 26% of incidents was data stolen, compared to 49% recorded in 2024.

New regulations bring changes to response strategy
The landscape in Britain could change dramatically as the upcoming Security and Resilience Bill proposes a ban on ransom payments for certain categories of organisations – such as those managing critical national infrastructure– and mandatory incident reporting for all victims of attacks.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Sophos urges security managers to focus on a holistic ransomware strategy, which includes:
- Prevention by addressing the main causes of breaches – vulnerabilities, phishing and credential abuse,
- Protection with modern endpoint solutions and anti-ransomware tools,
- Early detection and response, so that attacks are stopped before they spread,
- Complete incident response planning and frequent backups.
See also: Fog ransomware attack uses open source tools
When it comes to ransoms, experts recommend not paying them. When victims refuse to pay the ransom, the attackers lose their source of income. Ransomware is the main way for ransomware attackers to make money.
Furthermore, refusal to pay can lead to increased insecurity and uncertainty for attackers, which can force them to reconsider their tactics or look for new ways to generate income.
Finally, failure to pay can lead to increased pressure from . law enforcementRansomware attacks are illegal, and failure to secure ransom can make perpetrators more vulnerable to detection and arrest.
Source: www.infosecurity-magazine.com
