IBM's 2025 Cost of a Data Breach Report has put a hard number on something security professionals have warned about for years: the ransom demand is never the real cost of a ransomware attack. According to the report, the average total cost of a ransomware incident reached $4.4 million, more than 38 times higher than the average ransom demand of $115,000. When the analysis narrows to breaches specifically involving ransomware or extortion, the average cost climbs even further, to $5.08 million.

For small and midsize enterprises (SMEs), these figures aren't abstract. They represent a gap between what businesses budget for (a ransom payment they hope never to make) and what an attack actually drains from the organization once recovery, downtime, legal exposure, and reputational damage are factored in.

The Numbers Behind the Headline

The 38x multiplier between ransom demand and total incident cost is the most important figure in IBM's report, and it deserves more attention than it typically gets. Most conversations around ransomware focus on the ransom itself: how much attackers are asking for, whether to pay, and how to negotiate. But IBM's data suggests that fixation on the ransom figure obscures the real financial threat.

A $115,000 ransom demand sounds like a manageable, if painful, business expense. A $4.4 million total cost is a different conversation entirely, one that touches payroll, vendor contracts, customer trust, and in some cases, the survival of the business itself. The $5.08 million figure for ransomware and extortion breaches specifically confirms that this category of incident is consistently among the most expensive types of data breach an organization can face.

Why the Ransom Demand Is the Smallest Part of the Bill

The gap between the ransom and the total cost exists because ransomware doesn't just encrypt files, it disrupts operations. Systems go offline. Employees can't access the tools they need to do their jobs. Customer-facing services stop working. Recovery teams have to be brought in, often on an emergency basis, to rebuild infrastructure from scratch rather than simply trusting a decryption key from the attacker.

On top of operational disruption, there are the costs that accumulate long after systems are restored: regulatory notifications, potential fines, customer churn, legal fees, and the reputational hit that can follow a public breach disclosure. IBM's broader Cost of a Data Breach research has consistently shown that these downstream costs, rather than the initial extortion demand, make up the bulk of what an organization ultimately spends. Ransomware simply concentrates all of these costs into a shorter, more chaotic timeframe.

Why Small and Midsize Businesses Are Target #1

SMEs are attractive targets precisely because they tend to have smaller security budgets and leaner IT teams than large enterprises, while often holding valuable customer or financial data. Attackers know that a smaller organization is less likely to have redundant systems, dedicated incident response staff, or the cash reserves to absorb a prolonged outage without serious consequences.

This dynamic has played out visibly in recent ransomware campaigns. Groups like Qilin and The Gentlemen have been escalating attacks specifically against small and midsize businesses, competing for dominance in the ransomware-as-a-service space by focusing on organizations that are less equipped to fight back. IBM's cost figures help explain why: for attackers, SMEs represent a combination of real payout potential and comparatively weak defenses, a combination that keeps this segment squarely in the crosshairs.

What This Means For You

If you run or work in a small or midsize business, these numbers should reframe how you think about ransomware risk. The relevant question isn't "can we afford to pay a ransom if it comes to that," it's "can we survive the total cost of an incident, including weeks of downtime, recovery expenses, and the aftermath." That total cost, per IBM's data, is measured in millions, not tens of thousands.

This also has direct privacy implications. Ransomware incidents frequently involve data theft alongside encryption, meaning customer and employee personal information can end up exposed even if a ransom is paid. Businesses that treat ransomware purely as an IT outage risk underestimating the privacy and compliance obligations that follow a breach involving stolen data.

Practical Takeaways

Given the scale of these costs, prevention and preparedness matter far more than negotiation strategy. A few concrete steps worth prioritizing:

  • Maintain regular, tested backups that are stored offline or in a way attackers can't reach and encrypt alongside your primary systems.
  • Build an incident response plan before an attack happens, not during one, including clear roles for who makes decisions about downtime, disclosure, and law enforcement contact.
  • Invest in basic security hygiene: multi-factor authentication, timely patching, and employee phishing awareness, since many ransomware infections start with a single compromised credential or email click.
  • Understand your data breach notification obligations in advance, since ransomware that involves data theft can trigger legal requirements regardless of whether a ransom is paid.

IBM's 2025 findings make one thing clear: the ransom demand is a distraction from the real financial threat ransomware poses. For SMEs, closing the gap between a $115,000 demand and a $4.4 million bill starts long before an attacker ever sends the first message.