Warehouse worker standing beside a stopped truck
Insights··7 min read

The Cost of Downtime for South African SMEs

When systems go dark, the ransom is rarely the biggest number on the invoice. The latest South African data puts the real cost in lost weeks, lost customers and lost sleep.

What "downtime" actually costs

Ask a business owner what a cyberattack would cost and most will think of the ransom note. The data says otherwise. In Sophos' State of Ransomware in South Africa 2026 survey of 135 local organisations that were hit in the previous 12 months, the average cost of recovering from an attack was more than R17 million (about $1.08 million) — and that figure excludes any ransom paid.[1]

What is in that number? Sophos counts downtime, staff time, replacing or repairing devices, restoring networks and lost business opportunities.[1] In other words, it is the cost of the business standing still while people work around the clock to bring it back. It is down from R21 million in the 2025 report, which suggests defences are improving, but it remains a sum most small and medium enterprises simply cannot absorb.[1]

R17m+Average cost of recovering from a ransomware attack in South Africa in the past year, excluding ransom payments (Sophos, 2026).[1]

The clock is the real enemy

Downtime cost scales with duration, and South African recoveries are slow. Only 40% of affected organisations were fully back within a week. 13% needed between one and six months.[1] For an accounting practice in the middle of tax season, a manufacturer with orders waiting or a clinic that cannot reach patient records, every one of those days has a rand value.

Part of the reason is that attacks here are more likely to succeed in doing damage. Almost two-thirds (63%) of South African incidents resulted in data being encrypted, above the global average of 56%.[1] Once files are locked, the business is choosing between restoring from backup, paying, or rebuilding from nothing — and each path takes time.

Ransom is only part of the bill

The ransom itself is still substantial. The median demand in South Africa was R6.8 million (about $427 000) and the median payment almost R5 million — victims paid, on average, 71% of what was demanded.[1] More than half (58%) of those whose data was encrypted paid to get it back, while 54% used backups (many did both).[1]

Globally the trend is moving the other way: Verizon's 2025 Data Breach Investigations Report found the median ransom payment fell to $115 000 and that 64% of victims did not pay, up from 50% two years earlier.[4] The gap suggests South African businesses are paying more often because they have fewer alternatives when the attack lands — usually because backups were not there, were not tested, or were encrypted too.

Why SMEs are hit hardest

Large enterprises make headlines, but the burden falls disproportionately on smaller firms. Verizon found ransomware present in 88% of breaches at small and medium businesses, compared with 44% of breaches overall.[4] Smaller organisations tend to lack the segmentation, monitoring and recovery readiness that let bigger companies contain an incident.

The macro picture confirms South Africa is a preferred target. INTERPOL's African Cyberthreat Assessment Report 2026 found that South Africa accounted for 92% of all ransomware detections in Africa in 2025 and 70% of business email compromise detections.[5] At the larger end of the market, IBM's Cost of a Data Breach Report 2025 put the average South African breach at R44.1 million, with lost business alone accounting for R13.1 million of it.[3] An SME will not face numbers that size — but it also has far less cushion to survive a fraction of them.

88%Share of breaches at small and medium businesses that involved ransomware, versus 44% of breaches overall (Verizon DBIR, 2025).[4]

The costs that never make the spreadsheet

Several costs sit outside Sophos' recovery figure:

Where the bill actually starts

The encouraging news is that most incidents start in one of three well-understood places. In South Africa, compromised credentials were the most common technical root cause (27% of incidents), followed by exploited vulnerabilities (25%) and malicious email (22%).[1] Operationally, 47% of victims cited a lack of adequate protection and 43% a lack of cybersecurity capacity or expertise.[1]

Each of those maps to a concrete, affordable control: multi-factor authentication on every account; a patching routine that prioritises internet-facing systems; email authentication and filtering; and — above all — backups that are offline, encrypted and tested, so that recovery is measured in days rather than months. The cheapest hour of downtime is the one you never have.

References

  1. IT-Online, Defences improve, but ransomware still threatens SA businesses, 18 September 2026 — reporting Sophos, The State of Ransomware in South Africa 2026 (survey of 135 South African IT and cybersecurity leaders). it-online.co.za
  2. Sophos, The State of Ransomware 2026 (global report). sophos.com
  3. IBM, Cost of a Data Breach Report 2025; South African figures as reported by Hypertext, 31 July 2025. ibm.com · htxt.co.za
  4. Verizon, 2025 Data Breach Investigations Report, 23 April 2025 (22 000+ incidents, 12 195 confirmed breaches). verizon.com
  5. INTERPOL, African Cyberthreat Assessment Report 2026, 3 August 2026; South African figures as reported by Conviction. interpol.int · conviction.co.za
  6. Republic of South Africa, Protection of Personal Information Act 4 of 2013, section 22 (Notification of security compromises). gov.za

Get your free
Cyber Security Review.

In 30 minutes, we'll assess your current security posture and show you exactly where you're exposed — at no cost, no pressure.