Veeam Software has published the findings of its latest research in the From Risk to Resilience: Veeam 2025 Ransomware Trends and Proactive Strategies Report. This shows that the percentage of companies impacted by ransomware attacks has declined from 75% to 69%, with improved preparation and resilience practices, as well as increased collaboration between IT and security teams, behind this reduction.
Veeam surveyed 1,300 organizations and found that ransomware attacks are becoming more refined and pervasive, meaning that organizations must adopt proactive cyber resilience strategies to mitigate risks and recover more swiftly and effectively from incidents.
“Organizations are improving their defenses against cyber attacks, yet 7 out of 10 still experienced an attack in the past year. And of those attacked, only 10% recovered more than 90% of their data, while 57% recovered less than 50%. Our latest findings clearly indicate that the threat of ransomware will continue to challenge organizations throughout 2025 and beyond,” said Anand Eswaran, CEO of Veeam. “As the nature and timing of attacks evolve, it is essential for every organization to transition from reactive security measures to proactive data resilience strategies. By adopting a proactive security approach, investing in strong recovery solutions, and fostering collaboration across departments, organizations can significantly reduce the impact of ransomware attacks.”
Key findings and trends to watch in 2025:
Law enforcement is forcing threat actors to adapt
In 2024, coordinated efforts by law enforcement agencies led to significant disruptions in major ransomware groups, such as LockBit and BlackCat. However, the rise of smaller groups and independent attackers has increased, necessitating ongoing vigilance.
Data exfiltration attacks grow
The report notes a troubling trend toward exfiltration-only attacks – when cybercriminals break into an organization’s network but do not encrypt or lock the data. Instead, they focus on stealing sensitive information — like personal data, financial records, or intellectual property — and transferring it outside the organization. Organizations with weak cybersecurity measures are particularly vulnerable, as threat actors rapidly exploit vulnerabilities, often within hours.
Ransomware payments are decreasing
The total value of ransomware payments fell in 2024, with 36% of affected organizations opting not to pay a ransom. Of those that did pay, 82% paid less than the initial ransom and 60% paid less than half that sum, emphasizing the importance of robust recovery strategies.
Legal consequences of ransom payments are emerging
New regulations and legal frameworks are discouraging ransom payments, with initiatives like the International Counter Ransomware Initiative urging organizations to strengthen their defenses rather than capitulate to attackers.
Collaboration reinforces resilience against ransomware
Enhanced communication between IT operations and security teams, along with partnerships with law enforcement and industry players, has proven vital in fortifying defenses against ransomware.
Budgets rise for security and recovery, but more is needed
While organizations are allocating more resources to security and recovery efforts, there remains a significant gap in investment relative to the growing threat landscape.
Pre-attack confidence among ransomware victims often doesn’t reflect reality
69% believed they were prepared before being attacked, while their confidence plummeted by over 20% afterward, revealing significant gaps in planning. While 98% of respondents had a ransomware playbook, less than half of organizations had key technical elements included, such asbackup verifications and frequencies (44%) and a pre-defined ‘chain of command’ (30%). Notably, CIOs experienced a 30% decline in their preparedness rating post-attack, compared to a 15% drop for CISOs, suggesting that CISOs have a clearer grasp of their organization’s security posture. These findings underscore the importance of fostering organizational alignment in cyber resilience and preparation, emphasizing the need for regular training and exercises across all teams to ensure a coordinated response during and after an attack.






