Majority of Chief Information Security Officers (CISOs) Consider Paying Cybercriminals to End Ransomware Attacks, According to New Absolute Security Research

1 hour ago 3

Article content

57% of CISOs Experienced Ransomware Attacks that Started on Endpoint Devices, with Many Taking Two Weeks to Recover

Financial Post

THIS CONTENT IS RESERVED FOR SUBSCRIBERS ONLY

Subscribe now to read the latest news in your city and across Canada.

  • Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman, and others.
  • Daily content from Financial Times, the world's leading global business publication.
  • Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles, including the New York Times Crossword.

SUBSCRIBE TO UNLOCK MORE ARTICLES

Subscribe now to read the latest news in your city and across Canada.

  • Exclusive articles from Barbara Shecter, Joe O'Connor, Gabriel Friedman and others.
  • Daily content from Financial Times, the world's leading global business publication.
  • Unlimited online access to read articles from Financial Post, National Post and 15 news sites across Canada with one account.
  • National Post ePaper, an electronic replica of the print edition to view on any device, share and comment on.
  • Daily puzzles, including the New York Times Crossword.

REGISTER / SIGN IN TO UNLOCK MORE ARTICLES

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account.
  • Share your thoughts and join the conversation in the comments.
  • Enjoy additional articles per month.
  • Get email updates from your favourite authors.

THIS ARTICLE IS FREE TO READ REGISTER TO UNLOCK.

Create an account or sign in to continue with your reading experience.

  • Access articles from across Canada with one account
  • Share your thoughts and join the conversation in the comments
  • Enjoy additional articles per month
  • Get email updates from your favourite authors

Sign In or Create an Account

or

Article content

SEATTLE — Fifty-eight percent of cybersecurity leaders would consider paying cybercriminals to end a ransomware attack, with 46 percent ranking operational downtime as the most significant impact ransomware is likely to have on their organizations.

Article content

Article content

These are among findings revealed in The Ransomware Reality: Zero Days to Recover. This new report from Absolute Security includes results from a survey of 750 enterprise Chief Information Security Officers (CISOs) across the United States and United Kingdom, conducted by independent polling provider Censuswide.

Article content

Article content

“It’s not surprising to learn that despite regulatory pressure, security and risk leaders remain open to paying a ransom to recover their systems and protect data, especially when considering that prolonged downtime can lead to unsustainable losses,” said Christy Wyatt, President and CEO, Absolute Security. “CISOs that can quickly restore continuity after disruptive attacks can avoid getting trapped in a downtime cycle, which will only grow alongside cybercriminals’ increasing use of AI-powered attacks.”

Article content

By signing up you consent to receive the above newsletter from Postmedia Network Inc.

Article content

Ransomware continues to top CISOs’ ledgers as one of the most menacing threats they face, with their endpoint device infrastructures significantly vulnerable. Over the past 12-18 months, 57 percent reported their enterprises experienced an attack that originated on a remote, mobile, or hybrid device, with 58% in agreement that an incident left endpoints inoperable.1 Neither finding was unpredictable, when considering that additional telemetry-based research from millions of PCs revealed critical endpoint security controls fail to operate 20 percent of the time.2 This second edition in the State of Enterprise Cyber Resilience research series surfaced additional salient findings that expose how ransomware is impacting operational resilience. Included in the results were several top takeaways:

Article content

Confidence Paradox.

Article content

83% of CISOs reported being confident in their businesses’ ability to recover from ransomware, yet 57% took as long as six days to bounce back and 20% took as long as two weeks. No CISOs reported having the ability to recover within a day.

Article content

Sneaker Net.

Article content

Despite knowing that ransomware continues to cause operational disruptions, 59% of organizations agree they must take physical possession of an endpoint to remediate and restore the device after an incident. Only 53% of organizations have remote recovery capabilities in place, despite the wide-spread availability of such tools.

Article content

Mythos Variable.

Article content

CISOs reported that

Article content

Article content

legacy system patching is the second most challenging ransomware mitigation method at 42% (this was only 1% behind the top-ranked challenge—Employee Awareness Training at 43%). With Claude Mythos showing that advanced LLMs in the hands of defenders and attackers can surface vulnerabilities at speeds the industry cannot keep pace with, organizations will face continued disruption caused by threats that leverage unmitigated software risks. This means that while patching must remain a key security tactic, the ability to recover from increasing vulnerabilities and exploits must rise to the top of the priority stack.

Article content

Article content

Download your complimentary copy of the new report: The Ransomware Reality: Zero Days to Recover Discover how Absolute Security helps organizations defend against and stop downtime caused by ransomware and other cyber disruptions by meeting with our experts at the Cyber Resilience Hub in Las Vegas during Dell Technologies World 2026. Book a meeting, attend the Resilient CISO & CISO Workshop, and join the happy hour.

Article content

About Absolute Security

Article content

Absolute Security is partnered with more than 28 of the world’s leading endpoint device manufacturers, embedded in the firmware of 600 million devices, trusted by thousands of global enterprise customers, and licensed across 16 million PC users. With the Absolute Security Cyber Resilience Platform integrated into their digital enterprise, customers ensure their mobile and hybrid workforces connect securely and seamlessly from anywhere in the world and that business operations recover quickly following cyber disruptions and attacks. To learn more, visit www.absolute.com and follow us on LinkedIn, X, Facebook, and YouTube.

Article content

ABSOLUTE SECURITY, ABSOLUTE, the ABSOLUTE LOGO, AND NETMOTION are registered trademarks of Absolute Software Corporation ©2026, or its subsidiaries. All Rights Reserved. Other names or logos mentioned herein may be the trademarks of Absolute or their respective owners. The absence of the symbols ™ and ® in proximity to each trademark, or at all, herein is not a disclaimer of ownership of the related trademark.

Article content

____________________________

1 The State of Enterprise Cyber Resilience, 2026

2 The Absolute Security Resilience Risk Index 2026

Article content

Article content

Article content

Article content

View source version on businesswire.com:

Article content

Article content

logo

Article content

Contacts

Article content

Read Entire Article