Shocking Vulnerability Exposed in Indian SMEs to Ransomware Attacks

Indian SMEs Are Still Easy Targets

In 2025, a new report by global cybersecurity firm Sophos revealed something alarming — small and medium-sized businesses (SMEs) in India are still very vulnerable to ransomware attacks. Despite some signs of progress, many of these companies are not well prepared to defend themselves against cybercriminals.

Until a ransom is paid, a malicious virus known as ransomware prevents access to a company’s data or systems.   Sophos studied 378 Indian companies that were hit by ransomware in the past year. The findings show that although awareness is growing, the vast majority of businesses still do not take strong action to protect themselves.

India has over 50 million SMEs. But only a small fraction of them are currently aware of cybersecurity threats and are taking steps to safeguard their data. Most others remain exposed. Sophos says that ransomware does not target only big companies — it goes after anyone it sees as a potential source of money. Since most SMEs don’t invest much in cybersecurity, they are much easier to attack.

Signs of Improvement but Big Gaps Remain

The report does show some positive changes. For instance, the average ransom demand in India has come down by 52%. It now stands at around $961,289. The actual amount paid by companies has fallen even more by 79% to an average of $481,636. This means fewer companies are giving in to ransom demands.

This year, just 53% of Indian businesses paid the ransom to recover their data. That’s better than last year when 65% ended up paying. More companies are now using data backups and preparing in advance, which helps them recover without paying criminals.

However, many gaps still remain. The report points out that exploited system weaknesses were the biggest reason for ransomware attacks. These were responsible for 29% of the cases. Other common entry points included stolen passwords (22%) and bad email links (21%).

Apart from technical issues, businesses also struggled with internal weaknesses. Around 41% of the companies said they didn’t have enough skilled people or good protection tools. Another 39% admitted that their companies lacked the right cybersecurity services and systems to fight back.

These weaknesses make it easy for cybercriminals to break into company systems and hold them hostage.

The Real Cost and Emotional Pressure

Ransomware attacks don’t just cost companies money. They also cause stress, loss of time, and emotional pressure. Even if a company decides not to pay the ransom, the cost of fixing the damage is huge. On average, Indian companies spent $1.01 million to recover from a ransomware attack. This includes the cost of network repairs, lost business time, recovery of devices, and the effort of the employees involved.

Many employees, especially in cybersecurity teams, reported feeling burnt out and anxious. About 46% of them said they constantly worry about the possibility of another attack. Another 42% felt that their top bosses were putting more pressure on them. Around 30% of professionals said they felt guilty for not being able to prevent the attack from happening in the first place.

🛑 Sanctions Slam Aeza! U.S. and UK Team Up to Shut Down Russia’s Ransomware Powerhouse

When looking at which industries were affected the most, the Banking, Financial Services, and Insurance (BFSI) sector stood out. This industry faced the highest number of ransomware incidents. However, experts warned that no industry is safe anymore. As hackers become smarter, every sector is at risk.

To fight back, companies are being urged to fix system flaws and improve staff knowledge. They should also set up strong antivirus systems, prepare clear emergency plans, and keep updated data backups in safe places.

Renuka Bangale
Renuka Bangale
Renuka is a distinguished Chartered Accountant and a Certified Digital Threats Analyst from Riskpro, renowned for her expertise in cybersecurity. With a deep understanding of cybercrimes, malware, cyber warfare, and espionage, she has established herself as an authority in the field. Renuka combines her financial acumen with advanced knowledge of digital threats to provide unparalleled insights into the evolving landscape of information security. Her analytical prowess enables her to dissect complex cyber incidents, offering clarity on risks and mitigation strategies. As a key contributor to Newsinterpretation’s information security category, Renuka delivers authoritative articles that educate and inform readers about emerging threats and best practices.

TOP 10 TRENDING ON NEWSINTERPRETATION

Remote jobs exploited in global scheme as Amazon halts 1,800 North Korea-linked applications

Amazon has recently blocked more than 1,800 job applications...

Romania hit by ransomware attack as 1,000 government computers taken offline in water authority breach

Romania’s water management authority has been hit by a...

“Democracy under siege”: Sanders warns Meta and Big Tech are buying U.S. elections to block AI rules

U.S. Senator Bernie Sanders has issued a strong warning...

AI Didn’t Kill Jobs — It Quietly Made Them More Valuable

Workers around the world have been worried about artificial...

Redacted Epstein files trigger backlash as AOC names DOJ and demands accountability

Representative Alexandria Ocasio-Cortez (AOC) triggered widespread attention after posting...

House committee releases photos from Jeffrey Epstein estate with candid and unsettling content

New photos have emerged from the estate of Jeffrey...

Kamala Harris responds to criticism over Biden’s handling of Epstein-related documents

The controversy surrounding documents linked to disgraced sex trafficker...

Julian Assange challenges Nobel Peace Prize award, seeks to block payment to Venezuelan opposition leader

WikiLeaks founder Julian Assange has filed a complaint against...

“This is a huge red flag”: AOC says Trump used force against cartels without sharing intelligence with Congress

The debate in Washington has intensified after strong criticism...

Food Giants Call It “Efficiency” — Workers Call It Tens of Thousands of Layoffs

The food and beverage industry experienced a very difficult...

AI Didn’t Kill Jobs — It Quietly Made Them More Valuable

Workers around the world have been worried about artificial...

Redacted Epstein files trigger backlash as AOC names DOJ and demands accountability

Representative Alexandria Ocasio-Cortez (AOC) triggered widespread attention after posting...

Kamala Harris responds to criticism over Biden’s handling of Epstein-related documents

The controversy surrounding documents linked to disgraced sex trafficker...

Related Articles

Popular Categories

error: Content is protected !!