Average Ransomware Payments Reach $40 Million; Management Risks Emerge Amidst Expanded AI Response
Splunk identified downtime as a major financial and operational risk for businesses. It was found that ransomware payments have increased approximately threefold since 2024, and regulatory fines have reached an average of $51 million per organization.
According to the 'Hidden Costs of Downtime' report released by Splunk on the 9th, the average ransomware payment was estimated at $40 million. 57% of tech executives responded that regulatory sanctions could have a serious or fatal impact on their organizations.
Operational burdens have also increased. 89% of technology leaders responded that a large workforce is needed to resolve issues, and 90% stated that the demand for customer support has increased. 76% of finance executives and 74% of marketing executives also experienced the same pressure. Approximately 20% of marketing professionals stated that it takes an entire quarter to fully restore brand health.
The boundary between security incidents and general IT failures has also blurred. 36% of security leaders reported that downtime is frequently misclassified as an IT issue. Only 38% of technology executives responded that they consistently identify the root causes of downtime incidents. Cybersecurity-related downtime due to SaaS and third-party application issues has also increased by approximately three times since 2024.
Companies are utilizing AI for incident classification and root cause analysis. Annual spending on AI tools for downtime prevention and response was found to be a median of $24.5 million. 74% of organizations equipped with AI workflows and incident classification capabilities reported avoiding the need to publicly disclose data breaches last year, compared to 54% of non-expert organizations.
The operational burden associated with the use of AI was also identified. All technology leaders responded that they had experienced AI-related downtime in some form, and 68% stated that they were concerned about the unpredictable behavior of AI agents.
Investment trends are shifting toward visibility and automation. 98% of organizations with low downtime costs stated that end-to-end visibility is critical to incident reduction. Approximately three-quarters of IT operations and engineering leaders identified end-to-end observability as a top investment priority. Among technology leaders, 85% selected AI-based security automation, while 65% chose AI-based observability as their primary investment areas.
This survey was conducted by Oxford Economics on 2,000 executives from 2,000 global companies across 20 countries.