Onapsis, the cybersecurity development company, has published new data showing the extent of ransomware attacks over the last year.
According to their survey of 500 cybersecurity professionals, 38% of companies experienced between one and three ransomware attacks, while 14% suffered ten or more, with only 15% of firms saying they hadn’t had any attacks.
Of the respondents who experienced at least one ransomware attack in the last year, overall 61% said it resulted in downtime of at least 24 hours. For 45% it resulted in downtime of between 24 and 36 hours, while 6% said their downtime lasted three days or more following a ransomware attack.
Ransomware attacks also impacted Enterprise Resource Planning (ERP) applications, systems that help businesses run by automating and managing some core processes, including running finances, managing supply chains and procurement services.
Overall, 89% of companies said their ERP applications were affected by ransomware attacks at least once, with 93% of respondents agreeing that dedicated ERP security solutions are becoming business-critical.
When asked if they communicated with the threat actor executing the ransomware attack, the majority (69%) said yes. As for whether organisations are paying the ransom, respondents were split with 34% paying every time, 21% paying only some of the time and 45% never paying.
Notably, many organisations are turning to outside support to help manage ransomware, with 83% of respondents who paid ransoms at least once saying they have worked with a ransomware broker.
Recommended reading
- UK Businesses Face New Cyber-attacks Every 44 Seconds in Q2 2024
- Ransomware Crisis Escalating Globally, New Report Shows
- What Were the Key Ransomware Trends in July?
When asked how ransomware has influenced their cybersecurity investment, 57% said they had invested in new solutions, 54% invested in employee training, and 36% hired an outside threat research team.
“While the volume of these attacks isn’t surprising, the increasing impact to ERP applications is notable and it will only get worse amidst AI-enabled threats,” said Mariano Nunez, CEO of Onapsis.
“The research is also very clear in that generic security solutions on the market are falling short. Enterprises need a purpose-built, comprehensive solution that protects their mission-critical ERP platforms from this increasing threat.”
A Gartner survey from earlier this summer cited AI-enhanced malicious attacks as the top emerging risk for executives, with AI-assisted misinformation also causing concern.
Other research from this year has found that 2024 is expected to be the highest-grossing year for ransomware payments yet, raking in a record $459.8 million (£353.24m) in the first six months of the year.





