5 min read

The Real Cost of Ransomware in 2026

5 min read
August 4, 2026
By: Eye Security
the real cost of ransomware
By: Eye Security
4 August 2026

The average ransom demand facing a European mid-market organisation is now $613,000. 15% of the cases we investigated came in above $1m.

Across three years of incident response work between 2023 and 2025, our team found that the ransom demand is rarely what determines how much a ransomware attack costs. Only 27% of the cases we handled ended in a payment at all. What separated the organisations that recovered in days from the ones that spent weeks in crisis was not the size of the demand. Rather, it was how the threat actors got in, how quickly anyone noticed, and whether there was a plan for the hours that followed.

How much is the average ransom demand in 2026?

Across known ransomware engagements since 2023, demands ranged from under $100,000 to well above $2 million.

The distribution matters more than the average. Most cases fell below $100,000, which tells you something about how ransomware operators think about the mid-market: they set a number they believe an organisation of your size can move quickly, without a board debate. Around a third of incidents involved demands up to $700,000. Fifteen percent went past a million.

The median sat between $400,000 and $700,000. The average landed at approximately $613,000.

For a company of 200 people, a $613,000 demand is not a line item. It lands simultaneously on liquidity, operations, and the insurance relationship.

The trend worth watching is the top of the range. Multi-million-dollar demands against European businesses are no longer outliers reserved for large enterprises. 

 

How ransomware gets in

The most common root cause in our dataset was an exposed application that had not been patched.

Exploitation of public-facing applications accounted for 30% of ransomware incidents. External remote services, that is, unsecured RDP, exposed VPN endpoints, accounted for another 17%. Phishing came in at 13%. High-risk vectors such as supply chain and domain-level breaches made up 6.7%.

Nearly half of all ransomware cases started with something facing the internet that should not have been reachable, or should have been patched.

Phishing at 13% is worth pausing on too. Social engineering remains a challenge; it is the leading initial access vector for data breaches generally. But in this specific dataset, it was not the dominant ransomware driver. Threat actors going after mid-market organisations with encryption in mind mostly did not need to trick anyone but found an open door.

One more finding: the vast majority of cases involved organisations with no 24/7 detection and response capability. In the three cases in our dataset involving MDR clients, root causes traced back to unmonitored infrastructure and Shadow AI, areas that sat outside the protected scope.

Negotiation is not payment

70% of our ransomware cases between 2023 and 2025 involved negotiation with the threat actor.

27% ended in payment.

This gap is the single most misunderstood part of ransomware response. Talking to a threat actor is not a step towards paying them. Handled by people who do it regularly, negotiation is an intelligence exercise. It tests whether the claims are credible: does this group have the data they say they have? It reveals intent and sophistication. It slows escalation, particularly the pressure tactics around leak-site countdowns. And critically, it buys hours for the recovery assessment to finish before anyone has to make an irreversible decision.

Several negotiations in our dataset ended with no funds transferred at all. In most of those cases, the reason was mundane: the organisation had viable backups, containment had held, or the investigation had established that the attacker's leverage was weaker than claimed.

Where negotiation did take place, it reduced initial demands by an average of 35%.

"Effective recovery and decision-making continue to limit financial impact."

— Lodi Hensen, VP Security Alliances, Eye Security

The lesson for the mid-market is about the balance of power. An organisation with tested backups, a contained incident and a clear picture of what was taken negotiates from a different position than one that is still trying to work out which systems are affected. 

Why speed decides the cost

Of every incident type our team handles, ransomware consumes the most incident-handling hours. Even when containment works, the work does not stop: systems isolated, access paths traced, backups validated, recovery sequenced, and a series of business decisions made.

Organisations with Managed Detection and Response (MDR) in place spent an average of 39 hours handling an end-to-end ransomware incident. Organisations without continuous monitoring averaged 71 hours.

That is a 46% reduction in handling time.

The difference is about what you know at hour one. A ransomware case in a monitored environment usually starts with answers: this is when the initial access happened, these are the systems touched, this is the lateral movement path, this account was compromised. A case in an unmonitored environment starts with questions, and every one of them has to be answered by forensic reconstruction before recovery can safely begin. When did they get in? What did they touch? Are the backups clean, or did the attacker reach those too? Is this actually contained, or is there a second foothold?

"Resilience today is not the promise that technology will stop every attack; it's the ability for humans and technology together to make the right decisions under uncertainty, at speed, in an environment you must treat as already compromised."

— Lodi Hensen, VP Security Alliances, Eye Security

The costs nobody puts in the business case

Once a threat actor is inside, cost accumulates across categories: operational downtime, forensic investigation, negotiation support, recovery and rebuild work, customer and partner communication, legal and regulatory assessment, insurance handling, and the management time that all of it consumes.

Then there are the deadlines. An organisation classified as an important entity under NIS2 has 24 hours from becoming aware of a significant incident to file an early warning, 72 hours for a full notification, and a month for a final report. If personal data is involved, the GDPR Article 33 clock runs in parallel, to a different authority. Financial entities in scope of DORA face a tighter initial deadline still. These clocks start whether or not the investigation has produced answers yet.

That is why the 39-versus-71-hour gap is significant. Slower detection does not just extend the outage. It pushes technical uncertainty into regulatory windows that do not move.

Ransomware is still a business continuity test

Ransomware becomes expensive at three specific failure points: when the organisation cannot see what is happening, cannot contain it quickly, or cannot recover cleanly.

These are questions about visibility, preparation and decision-making discipline.

The earlier suspicious activity surfaces, the more options remain on the table: isolate affected systems, revoke access, cut off lateral movement, protect the backups before they are targeted, preserve evidence for the insurer and the regulator, and make recovery decisions from information rather than guesswork.

The cost of ransomware is shaped by readiness

Based on what consistently separated the manageable incidents from the severe ones:

  1. Know what is exposed. Nearly half of cases started at an internet-facing application or remote service. Inventory what is reachable from outside and fix the gap between what should be exposed and what actually is.

  2. Treat patch cadence as ransomware defence. Exploitation of unpatched public-facing applications was the single largest root cause at 30%.

  3. Secure remote access properly. Unsecured RDP and exposed VPN endpoints accounted for 17% of incidents.

  4. Test your backups before you need them. The organisations that walked away from a negotiation without paying were, in most cases, the ones with restores they had actually verified.

  5. Get continuous monitoring across the whole estate. Not just the parts that were in scope when the contract was signed. Two of our three MDR-client incidents traced back to infrastructure nobody was watching.

  6. Decide now who decides. Who authorises isolating production systems? Who calls the insurer, and in what order? Who files the NIS2 early warning? Answering these during an incident costs hours you do not have.

  7. Rehearse the regulatory clock. A 24-hour early-warning window is unforgiving for a three-person IT team that has never walked through it.

How much does ransomware cost in the European mid-market: the bottom line

The average ransom demand is $613,000, and most organisations in our dataset did not pay it. 70% negotiated; 27% paid. Negotiation cut demands by 35% on average. Continuous monitoring cut handling time by 46%.

Read together, these numbers say something simple. The cost of ransomware is set by what you knew, how fast you knew it, and whether you had decided in advance what to do.

Let's talk

Curious to know how we can help?

Get in touch
GET IN TOUCH
Share this article.