
South African Organisations Face Ransomware Pressure: Report Highlights Compliance Risks
Pieter Nel, regional head for SADC at Sophos in South Africa. (Image: Supplied) South African organisations continue to fall victim to ransomware , with compromised credentials the most common technical root cause of attacks, a lack of protection the leading operational cause and user devices the most common entry point. This is according to the latest State of Ransomware in South Africa 2026 report from cyber security firm Sophos, whose South African business was officially established in June 2026. The report is based on responses from 135 IT and cyber security leaders at South African organisations that experienced ransomware in the previous 12 months. Almost two-thirds (63%) of ransomware incidents resulted in data being encrypted over the past year, above the global average of 56% and up from 60% among South African respondents in the 2025 report. The research found that 58% of South African organisations paid the ransom and recovered their data, down from 71% in 2025. The median ransom demand was R6.9 million. The average cost of recovering from a ransomware attack was more than R17 million, excluding ransom payments. This was down from R21 million in the 2025 report. The figure includes downtime, staff time, replacing or repairing devices, restoring networks and lost business opportunities. Pieter Nel, regional head for SADC at Sophos in South Africa, said: ��These figures show the extent of the disruption ransomware continues to cause in South Africa. Once attackers are able to encrypt data, the organisation faces the immediate challenge of restoring systems, maintaining operations and managing the financial and human impact of the incident. The most effective response begins before the attack, by closing the gaps that allow criminals to enter the environment.” Compromised credentials were the most common technical root cause of ransomware attacks, accounting for 27% of incidents. Exploited vulnerabilities followed at 25%, down from 28% in 2025, while malicious e-mails were responsible for 22%. A lack of adequate protection was identified as the most common operational root cause by 47% of South African respondents, the highest proportion recorded in any country surveyed. A lack of people or cyber security capacity was cited by 43%, while 42% said attackers exploited a known security gap. For attacks that did not originate through e-mail or phishing, user devices were the most common entry point, accounting for 43% of incidents. Exposed applications and systems accounted for 38%, followed by firewalls at 13%. The link between ransomware and identity-based attacks was also pronounced. Among the South African organisations surveyed, 85% said their ransomware incident was the same event as their most significant identity attack during the year, compared with a global average of 67%. “Ransomware attacks frequently begin with an identity, device or security weakness that the organisation already knows exists,” said Nel. “Compromised credentials allow criminals to appear as legitimate users, while unpatched vulnerabilities and exposed systems provide additional routes into the business. Addressing these risks requires strong identity controls, properly configured security technologies and enough skilled capacity to monitor and respond to threats.” Sophos also highlighted the growing role of AI agents in both cyber attacks and defence. The company said there are now attacks orchestrated and executed entirely by AI, which can use its speed and sophistication to achieve objectives without human involvement. Of the organisations whose data was encrypted, 99% were able to recover it. The proportion using backups to restore encrypted data increased from 35% in 2025 to 54% this year, while the percentage paying a ransom and recovering their data fell from 71% to 58%. Data theft also declined. Information was stolen in 27% of attacks where data was encrypted, compared with 39% in the 2025 report. The median ransom demand fell by 57%
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Finish Reading the Full Story and the Expert Analysis.
Get the latest legal & regulatory intelligence in South Africa
Wansom is AI and can make mistakes.
