CrowdStrike survey of 2,200 organizations reveals 56% were hit by ransomware at least once in the past 12 months, 27% paid the ransom at an average of ~$1.1M
Arielle Waldman / SearchSecurity :
Context & Ripple Effects
The CrowdStrike survey lands mid-arc in ransomware's shift from nuisance to board-level risk. In 2016, Cisco counted 9.5K victims a month paying an average ransom of about $300; by H1 2020, ransomware was driving 41% of cyber insurance claims with demands up 47%. The new data — 56% of 2,200 organizations hit within twelve months, 27% paying at ~$1.1M on average — shows both the attack surface and the price tag have moved into a different league.
It also feeds the debate over whether paying works. A follow-on study found 80% of organizations that paid were hit a second time, and Coveware tracked the average payment rising another 43% from Q4 2020 to Q1 2021 — evidence that payment buys recovery, not immunity.
First-order effects
- The 27% of surveyed organizations that paid are out ~$1.1M each on average before recovery costs, while the majority that refused or weren't hit still carry the incident-response burden — the survey makes ransom payment a mainstream budget line, not an edge case.
Second-order effects
- Insurers, already carrying ransomware as their largest claims category, face pressure to reprice coverage or tighten requirements as payouts scale toward seven figures; attackers, seeing a reliable payer base, can justify bigger, more targeted demands.
Third-order effects
- If the pattern holds, corporate security spending structurally shifts from pure prevention toward negotiation, insurance, and recovery — and the recurring-reattack data strengthens the case for regulators and insurers to treat ransom payment as a failed control rather than a resolution.
The trend: Ransomware is industrializing from small opportunistic extortion into high-stakes attacks where million-dollar payments are routine, sustained by insurance and repeat victimization.