• About
  • Subscribe
  • Contact
Wednesday, January 7, 2026
  • Login
FutureCISO
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
No Result
View All Result
FutureCISO
No Result
View All Result
Home People Culture and Behaviour

Nearly half of retail ransomware attacks stem from unknown vulnerabilities

FutureCISO Editors by FutureCISO Editors
November 12, 2025
Nearly half of retail ransomware attacks stem from unknown vulnerabilities

Photo by Demian Smit: https://www.pexels.com/photo/people-inside-strucure-449559/

Share on FacebookShare on Twitter

A recent report by Sophos reveals that 58% of retailers affected by ransomware have opted to pay the ransom, a notable increase amidst rising demands, which have doubled to a median of $2 million.

As the retail sector faces mounting challenges, insights from the report are particularly salient for IT infrastructure and security leaders in Southeast Asia, navigating an increasingly complex threat landscape.

The Sophos "State of Ransomware in Retail 2025" report highlights that nearly half of the ransomware incidents stemmed from security gaps that organisations were previously unaware of.

Specifically, 46% of attacks exploited unknown vulnerabilities, while another 30% targeted known weaknesses. The increasing complexity of these attacks underscores the need for enhanced visibility across the retail attack surface.

Chester Wisniewski, director of global field CISO at Sophos, noted, “Retailers globally are facing a more complex threat landscape where adversaries are constantly on the lookout for and exploiting existing vulnerabilities.”

He added, “Without comprehensive security strategies, retailers risk ongoing operational disruption and reputational damage.” This statement stresses the urgency for Southeast Asian retailers to assess their cybersecurity posture proactively.

While the report shows a worrying trend in payment rates, it also indicates a slight improvement in defensive measures. The percentage of attacks stopped before any encryption occurred has reached its five-year high, suggesting that many retailers are enhancing their ability to detect and neutralise threats before they escalate.

Despite this, data encryption remains a significant concern, impacting 48% of attacks — the lowest rate recorded in five years.

The challenges are compounded by a lack of in-house expertise, which further complicates threat detection and response. Limited knowledge in managing cybersecurity services has resulted in 45% of operational compromises, emphasising the need for improved training and skills development among IT teams in the region.

Related:  Advanced device insights combat fraud in real time

Sophos suggested several recommendations for retailers to fortify their defences against ransomware threats. These include addressing root causes of vulnerabilities, ensuring all endpoints are protected, and maintaining continuous visibility of networks.

Partnering with Managed Detection and Response (MDR) providers can also help organisations bolster their security measures with 24/7 monitoring.

As the retail sector faces these ongoing challenges, the insights provided in the report highlight not only the vulnerabilities but also the strategies available for strengthening cybersecurity.

For IT leaders in Southeast Asia, this research serves as a timely reminder to reassess their security frameworks and enhance their preparedness against the evolving threat landscape.

Tags: managed detection and responseMDRransomwareSophos
FutureCISO Editors

FutureCISO Editors

No Result
View All Result

Recent Posts

  • Most organisations unable to guarantee Data visibility
  • Sustaining confidence in cybersecurity values
  • On-premise solution to enhance cybersecurity for APAC governments
  • Navigating human risk in the age of AI: Insights for CISOs in 2026
  • Innovations to guard against cross-domain email attacks

Categories

  • Blogs
  • Compliance and Governance
  • Culture and Behaviour
  • Cybersecurity careers
  • Data Protection
  • Endpoint Security
  • Incident Response
  • Network Security
  • People
  • Process
  • Resources
  • Risk Management
  • Technology
  • Training and awarenes
  • Videos
  • Webinars and PodChats
  • White Papers

Strategic Insights for Chief Information Officers

FutureCISO serves the interests of the Chief Information Security Officer (CISO) and the information security profession. Its purpose is to provide relevant and timely industry insights around all things important to security professionals and organisations that recognize and value the importance of protecting the organisation’s data and its customers’ privacy.

Cxociety Media Brands

  • FutureIoT
  • FutureCFO
  • FutureCIO

Categories

  • Privacy Policy
  • Terms of Use
  • Cookie Policy

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl

Login to your account below

or

[wpli_login_link]

Not a member yet? Register here

Forgotten Password?

Fill the forms bellow to register

All fields are required. Log In

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • People
  • Process
  • Technology
  • Resources
    • White Papers
    • PodChats
  • Events
  • Login

Copyright © 2024 Cxociety Pte Ltd | Designed by Pixl