By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Ransomware resilience may be improving in the health sector | Computer Weekly
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Ransomware resilience may be improving in the health sector | Computer Weekly
News

Ransomware resilience may be improving in the health sector | Computer Weekly

News Room
Last updated: 2025/11/18 at 3:03 PM
News Room Published 18 November 2025
Share
Ransomware resilience may be improving in the health sector | Computer Weekly
SHARE

In a possibly encouraging sign that cyber messaging is cutting through among healthcare providers, the sector appears to be becoming increasingly resilient to ransomware and cyber extortion, with fewer victims experiencing data encryption, fewer paying up and average time to recovery dropping according to a new Sophos report.

Based on global data collected by Vanson Bourne for a wider study, Sophos found that that this year, just 36% of victims in the healthcare industry paid a ransom, down from 61% in 2022, and over half of those that paid handed over less than what was demanded of them.

Demands from ransomware gangs also plummeted during the observed period, down 91% to $343,000 (£260,800) on average this year, with average payments dropping from $1.47m to just $150,000, the lowest of any sector reported in the wider dataset.

The mean cost of recovery – excluding any ransoms – was also down by 60% to $1.02m. And 58% of healthcare respondents said they recovered within a week, a strong improvement from 21% last year.

“It’s … encouraging to see signs of stronger resilience. In the study, nearly 60% of providers reported they recovered within one week, up from just 21% last year, which reflects real progress in preparedness and recovery planning. In a sector where downtime directly affects patient care, faster recovery is critical, but prevention remains the ultimate goal,” said Alexandra Rose, director at the Sophos Counter Threat Unit (CTU) – formerly a Secureworks unit.

However, improvement against some metrics should not be taken as a sign that the ransomware ecosystem is dwindling or the threat landscape becoming any less volatile; ransomware remains as pervasive a threat as ever and the healthcare sector is no more or less immune than any other.

“Healthcare continues to face steady and persistent ransomware activity. Over the past year, Sophos X-Ops identified 88 different groups targeting healthcare organisations, showing that even moderate levels of threat activity can have serious consequences,” said Rose.

In the past 12 months, the X-Ops team said that the most prominent ransomware gangs targeting the health industry were Qilin, INC Ransom and RansomHub – which it tracks as Gold Feather, Gold Ionic and Gold Hubbard respectively.

The data also reveal that although data encryption from ransomware has dropped to its lowest level since 2020, with only a third of attacks resulting in this scenario, the proportion of healthcare providers hit by extortion-only attacks, where data is not encrypted but rather stolen and a ransom demanded has tripled to 12% of attacks this year, from 4% a couple of years ago. The Cl0p/Clop gang, which last week claimed to have conducted a ransomware attack against an unspecified NHS body, is a great exponent of this tactic.

Root causes

Sophos’ data also reveal some insight into the root causes of cyber extortion and ransomware attacks in the healthcare industry, finding that for the first time since 2022, exploited vulnerabilities were the most common technical cause, seen in 33% of incidents, overtaking credential-based attacks, which topped the list in 2023 and 2024.

Respondents also described “multiple organisational factors” that contributed to their falling victim to such attacks, with 42% describing a lack of suitably qualified cyber security people or overall capacity, and 41% describing known but unaddressed security gaps.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Thieves are returning Android phones because they ‘don’t want no Samsung’ Thieves are returning Android phones because they ‘don’t want no Samsung’
Next Article UJET acquires Seattle conversational analytics startup Spiral to boost AI customer service tools UJET acquires Seattle conversational analytics startup Spiral to boost AI customer service tools
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

I’ve reviewed the top Android tablets – these are worth looking out for over Black Friday
I’ve reviewed the top Android tablets – these are worth looking out for over Black Friday
Gadget
Here’s everything we know about Google’s Gemini 3
Here’s everything we know about Google’s Gemini 3
Computing
Parts of the internet stop working globally after major network goes down
Parts of the internet stop working globally after major network goes down
News
TheCUBE at AWS re:Invent 2025: AI infrastructure and custom silicon –  News
TheCUBE at AWS re:Invent 2025: AI infrastructure and custom silicon – News
News

You Might also Like

Parts of the internet stop working globally after major network goes down
News

Parts of the internet stop working globally after major network goes down

7 Min Read
TheCUBE at AWS re:Invent 2025: AI infrastructure and custom silicon –  News
News

TheCUBE at AWS re:Invent 2025: AI infrastructure and custom silicon – News

10 Min Read
Best Gifts Available on Amazon: From  to 0
News

Best Gifts Available on Amazon: From $25 to $250

0 Min Read
The UK’s place in global tech – Will Hutton, Journalist – UKTN
News

The UK’s place in global tech – Will Hutton, Journalist – UKTN

1 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?