Friday, 25 September 2026
ZAR/USDR16.440.54%. Rand weaker against the US dollar
ZAR/EURR18.680.17%. Rand weaker against the euro
ZAR/GBPR21.730.13%. Rand weaker against the pound
Guide

Ransomware attacks on South African businesses are up 140%: what small businesses need to do now

Ransomware attacks on South African businesses are up 140%: what small businesses need to do now

South African organisations were attacked by ransomware an average of 2,145 times a week in the first half of 2026, a 36% increase on the year before, and confirmed attacks overall rose 140% over the same period. Small businesses are not incidental casualties of that surge. Attackers increasingly prefer them, precisely because a smaller business tends to run the same valuable customer, payment and supplier data as a large one, with a fraction of the IT security budget and staff to defend it.

What an attack actually costs

Sophos’s State of Ransomware in South Africa 2026 survey, covering 135 local IT and security leaders, found the median ransom demand was R6.8 million, and the average cost of recovering from an attack, excluding any ransom paid, reached R17 million. Only 40% of affected South African organisations recovered within a week, the lowest recovery rate of any country in the survey, down from 47% the year before. Pieter Nel, Sophos’s Regional Head for SADC, pointed to a lack of adequate protection as the single most common operational cause, cited by 47% of respondents, ahead of insufficient cybersecurity capacity (43%) and known, unpatched security gaps that were exploited anyway (42%).

Set against South Africa’s data breaches broadly, IBM’s 2025 Cost of a Data Breach Report put the average cost at R44.1 million across all affected organisations, financial services and hospitality businesses hit hardest at R70.2 million and R57.5 million respectively. That average leans heavily toward large organisations, but the direction it points in is the same one Sophos found at the SME end: a serious incident is not a cost a small business can casually absorb.

How attackers actually get in

The routes in are consistent and, importantly, mostly preventable. Compromised login credentials caused 27% of South African ransomware incidents, exploited software vulnerabilities caused 25%, and malicious emails caused 22%. Separately, user devices and exposed applications or systems were the two most common entry points overall. None of that requires a sophisticated, targeted campaign, a reused password, an unpatched piece of software, or one convincing phishing email is enough. State-owned logistics group Transnet’s own July 2021 ransomware attack, which forced container terminals at the country’s major ports to declare force majeure for about a week, is the case most South African businesses will recognise; it is a reminder that even organisations with real IT budgets get hit, not evidence that a small business with none is somehow a less attractive target.

Encryption is also no longer the only threat inside an attack. Sophos found 63% of South African ransomware incidents resulted in encrypted data, above the 56% global average, and 85% of local incidents involved an identity attack, credential theft or misuse, alongside the encryption itself. Attackers are not just locking files; they are also stealing logins and using them to move further into a business’s systems, which is exactly why multi-factor authentication does more work than any other single fix on this list.

Five defences that matter most, in order

  1. Multi-factor authentication on every account that allows it, especially email and any system holding customer or payment data. Compromised credentials were the single largest cause of attacks, and MFA is the cheapest defence against exactly that.
  2. Regular, offline or immutable backups, tested, not just scheduled. Businesses that used backups to recover, rather than paying, rose from 35% to 54% in Sophos’s data, the single biggest shift in the survey. A backup nobody has ever tried restoring is not a real backup.
  3. Patch known vulnerabilities promptly. A quarter of attacks exploited a vulnerability that already had a fix available; the gap was time, not a lack of a solution.
  4. Basic staff awareness on phishing and email. Malicious email accounted for 22% of attacks and does not require expensive tooling to reduce, mainly the habit of checking a sender and a link before clicking either.
  5. A written incident response plan, even a short one: who gets called first, what gets disconnected, who is legally required to be told. Working this out during an actual attack costs time a business does not have.

Where cyber insurance fits

Cyber insurance will not stop an attack, but it changes what one costs. Local cover for small businesses typically runs from around R150 to R500 a month depending on the size of the business and the limit chosen, a fraction of the R17 million average recovery cost Sophos recorded. It usually sits as an add-on to a broader policy rather than a standalone product, the same shopping exercise our business insurance cost and cover guide walks through for every other kind of cover a small business needs. Insurers generally price a policy lower for a business that already has MFA, encryption, regular backups and some staff training in place, which is one more reason to fix the basics first rather than treat insurance as a substitute for them.

If a breach happens anyway

A ransomware attack that exposes personal information is very likely also a POPIA security compromise, with its own separate notification obligations to the Information Regulator and to affected people. Our guide on what to do when your business has a data breach covers that process step by step, including the fines the Regulator has already issued for getting it wrong.