Site navigation

Report: 90% of Security Leaders Suffered Cyber-attacks Last Year

Tom Quinn

,

global cyber-attacks
“The persistence of ransomware attacks, coupled with the exploitation of hybrid cloud vulnerabilities, shows that threat actors are always one step ahead,” said Joe Hladik, head of Rubrik Zero Labs.

Nearly a fifth of global organisations experienced more than twenty-five cyber-attacks last year alone, an average of at least one breach every other week, according to a new survey of IT and security leaders from Rubrik.

The cybersecurity firm’s latest report, The State of Data Security in 2025: A Distributed Crisis, found that 90% of security teams suffered a cyber-attack in 2024, with the most common attack vectors being data breaches (30%), malware on devices (29%), cloud or SaaS breaches (28%), phishing (28%), and insider threats (28%).

Of the more than 1,600 IT and security leaders polled across ten countries, Rubrik found that nearly three-quarters reported that attackers were able to reach and ‘hurt’ their data, with 86% admitting to paying a ransom to try and recover their losses.

The research found that threat actors are trying to corner firms into paying out, with 74% saying threat actors were able to partially compromise their backup and recovery systems, and 35% reporting that their systems were completely compromised.

As a direct result of such attacks, 40% of organisations reported increased security costs, 37% suffered reputational damage and loss of customer confidence, and 33% went on to experience a forced leadership change following a cyber incident.

The data suggests that more firms this year will suffer similar consequences after a cyber-attack, as the widespread adoption of AI exacerbates the challenge of data sprawl across varied ecosystems, with Rubrik suggesting this will make it more difficult to safeguard sensitive information. 

Almost all (92%) of organisations reported using between two and five cloud and SaaS platforms, with attackers exploiting weak points in identity and access management to move laterally and escalate ransomware attacks.

This has added to the already demanding workloads of IT and security leaders, with 90% saying that they have been forced to add hybrid cloud environments to their purview, and half of IT leaders reporting that the majority of their workloads are cloud-based

The polling shows that taking on this extra responsibility is proving essential to effective defence postures.

According to Rubrik’s study, 36% of sensitive files stored in the cloud are considered high risk, with the majority containing Personally Identifiable Information (PII), followed by digital assets and business-critical data like intellectual property and source code, while 27% of high-risk sensitive files contain digital data such as API keys, usernames, and account numbers.

More than a third (35%) reported that securing this data across these complex network environments was their top challenge, followed by a lack of centralised management (30%), and low visibility and control over cloud-based data (29%).


Recommended reading


“Many organisations that move to the cloud assume their providers will handle security,” said Joe Hladik, head of Rubrik Zero Labs.

“The persistence of ransomware attacks, coupled with the exploitation of hybrid cloud vulnerabilities, shows that threat actors are always one step ahead. 

“Companies must take action and adopt an attacker’s mindset by identifying – and protecting – the most valuable data before it’s too late. The need for a data-centric security strategy that prioritises visibility, control, and quick recovery has never been more urgent.”

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data