If ransomware still feels like someone else's problem, the 2026 numbers say otherwise. South Africa is now the most-targeted country in Africa — 17,849 ransomware detections in a single year according to INTERPOL's Africa Cyberthreat Assessment, more than Egypt and Nigeria combined. The median ransom demand against South African organisations has jumped to around R17 million — nearly six times what it was a year earlier — and the average cost of recovering from an attack sits near R23 million before any ransom is even considered.
Those headline numbers come from large enterprises and mid-sized firms alike. But here's the part that matters if you run a 20–200 person business: attackers don't pick targets by size. They pick targets by ease. Automated tools scan for the same three weaknesses everywhere, and smaller businesses are statistically more likely to have all three open.
How ransomware actually gets in
Sophos' State of Ransomware research for South Africa found that most attacks start in one of three ways:
1. Stolen or compromised credentials (34% of attacks). A password reused from a breached website, a login sold on the dark web, no multi-factor authentication in the way. The attacker doesn't 'hack' anything — they simply sign in. What closes this door: multi-factor authentication on every account that matters — email, VPN, remote access, admin accounts.
2. Unpatched vulnerabilities (28%). A firewall, server or application running a known-vulnerable version, months after the fix was released. Attackers scan the whole internet for these; being small doesn't hide you. What closes this door: disciplined, verified patch management across servers, endpoints and network devices — not 'auto-update and hope'.
3. Malicious email (22%). Phishing that harvests credentials, or an attachment that plants the first foothold. One distracted click is enough. What closes this door: email authentication (DMARC, SPF and DKIM) so criminals can't spoof your domain, plus ongoing phishing-simulation training so your people become the alarm system instead of the entry point.
Notice what's not on this list: exotic zero-day exploits. The overwhelming majority of South African ransomware incidents begin with basics that were never locked down.
Your backups are now the first target
The most important shift in recent attacks: 89% of organisations hit by ransomware say the attackers went after their backups before the encryption started. Attackers know that a business with working backups won't pay. If your backups sit on a server on the same network — or in a cloud account reachable with the same admin credentials — assume they'll be encrypted or deleted along with everything else.
Modern protection means immutable, off-network backups: copies that cannot be altered or deleted even with admin credentials, tested with actual restore drills rather than green ticks on a dashboard. This is exactly how we build backup and disaster recovery for our clients — cloud-first, immutable, and rehearsed.
What layered protection looks like (without an enterprise budget)
No single product stops ransomware — 53% of breached South African organisations said they discovered security weaknesses they didn't know they had, and 58% pointed to a lack of in-house expertise as the root cause. The answer is layers, each one covering the gaps in the others:
- Identity: MFA everywhere, least-privilege admin accounts.
- Patching: monitored and verified across every device, monthly reporting.
- Endpoints: modern EDR/XDR (we deploy SentinelOne and Sophos) that detects behaviour, not just signatures — and can isolate a machine in seconds.
- Email: DMARC enforcement plus phishing-resistant habits, trained and tested.
- Network: properly configured next-generation firewalls and segmentation, so one infected laptop can't reach everything — see our cybersecurity services.
- Backups: immutable, off-network, restore-tested.
- Eyes on glass: 24/7 proactive monitoring so the 2am intrusion attempt is caught at 2am, not at month-end.
For most SA businesses, running all seven layers in-house is unrealistic — which is precisely why the managed model exists. One monthly fee, all seven layers, run by people who do this every day.
If you're hit: the first hour
Speed and sequence matter more than anything else in the first sixty minutes:
- Isolate, don't switch off. Disconnect affected machines from the network (unplug cables, disable Wi-Fi) but leave them running — memory contains evidence and, sometimes, decryption material.
- Call for expert help immediately. Organisations that bring in incident-response support are dramatically less likely to end up paying.
- Don't communicate with attackers on your own. Ransom negotiation without experience typically raises the price.
- Preserve everything. Logs, ransom notes, affected systems — your insurer and investigators will need them.
- Check your POPIA obligations. If personal information was accessed, the Information Regulator and affected individuals may need to be notified.
Only half of affected South African companies are back up within a week; one in five takes between one and six months. The difference is almost always preparation: tested backups, an incident plan, and someone to call.
The uncomfortable maths
Layered managed protection for a mid-sized business costs a small fraction of one recovery. Against a median demand of R17 million and recovery costs averaging R23 million — plus weeks of downtime, lost clients and POPIA exposure — prevention is not the expensive option. It never was.
Frequently asked questions
How common is ransomware in South Africa? South Africa is Africa's most-targeted country — INTERPOL's Africa Cyberthreat Assessment recorded 17,849 ransomware detections here in a single year, the highest on the continent and more than Egypt and Nigeria combined. Attacks hit businesses of every size, with SMEs increasingly targeted because their defences are thinner.
Should we ever pay the ransom? Payment is a last resort, and increasingly a poor one: paying doesn't guarantee recovery, may be restricted by your insurer, and marks you as a payer for repeat attacks. Businesses with immutable backups and tested recovery plans almost never need to consider it.
Does cyber insurance cover ransomware? Often partially — but insurers now demand evidence of controls (MFA, EDR, tested backups, patching) before they pay out, and premiums drop when those controls are in place. Weak controls can mean a rejected claim.
How quickly can a business recover from an attack? With immutable backups and a rehearsed recovery plan: typically days. Without them: half of SA companies take up to a week, and 20% take one to six months. The recovery you get is the recovery you rehearsed.
What does ransomware protection cost for a small business? A managed, layered programme — endpoint protection, patching, MFA, email security, immutable backup and monitoring — is priced per user per month and costs a small fraction of a single recovery. Book a free assessment and we'll show you the exact gaps and the exact number.
Every layer described above is something ROI Technologies runs daily for South African businesses from our Randburg base. If you'd like to know which of the three entry doors is currently open in your environment, book a free ransomware-readiness assessment — 30 minutes, no obligation, and you'll leave with a prioritised list either way.
*Sources for statistics: Sophos, The State of Ransomware in South Africa 2025; Veeam 2025 Ransomware Trends; INTERPOL Africa Cyberthreat Assessment 2025 (Trend Micro data).*
Need IT or Cybersecurity help in South Africa?
Talk to ROI Technologies — Johannesburg-based, certified, vendor-agnostic.
Contact Us