SA organisations are identity-compromised, slow to recover, and more likely to pay ransoms
Selected ransomware metrics, South Africa vs global benchmark, 2026 (% of organisations surveyed)
+18pp
SA identity-linked attack gap above global rate
+10pp
SA ransom payment rate above global average
South African organisations in 2026 saw 85% of ransomware attacks linked to identity or credential breaches — 18 percentage points above the global rate — and more than half chose to pay the ransom rather than recover independently. But despite paying ransoms at a higher rate than any other surveyed region, only 40% of SA organisations managed to restore operations within one week, compared to 55% globally. Credential hygiene and resilience investment therefore remain the two most urgent intervention points for South African security leadership.