• Home
  • About
  • Advertise
  • Contact
  • Signup to receive updates
 Innovation | Startups | Funding | Tech Blog in Africa
NiRA Event
  • Home
  • Startups
  • Opportunities
  • Funding
  • Women Tech
  • Expert Column
  • Blockchain
No Result
View All Result
  • Home
  • Startups
  • Opportunities
  • Funding
  • Women Tech
  • Expert Column
  • Blockchain
No Result
View All Result
Innovation | Startups | Funding | Tech Blog in Africa
No Result
View All Result
Home News & Insights

Schools Are Getting Better at Fighting Ransomware, But IT Teams Are Burning Out – Sophos Report

…Recovery Times Improving with 97% of Victims Recovering Encrypted Data; Ransom Payments Fall Sharply; Staff Burnout and Stress on the Rise

by Editor
9 months ago
in News & Insights
Reading Time: 4 mins read
A A
Ransomware
Share on FacebookShare on Twitter

RelatedPosts

Spotify Bets on AI podcasts, Smarter ads, and Fan Experiences at 2026 Investor Day

Court Ruling Safeguards Airtime and Data Access for Millions of Nigerians

Kaspersky Study Links Cyber Vulnerabilities to Poor Policies and Limited Employee Commitment

Spotify Debuts SongDNA in Beta to Map the Creative Links Behind Your Favorite Tracks

Sophos, a global leader and innovator of advanced security solutions for defeating cyberattacks, has released its fifth annual Sophos State of Ransomware in Education report.

The global study of 441 IT and cybersecurity leaders shows the education sector is making measurable progress in defending against ransomware, with fewer ransom payments, dramatically reduced costs, and faster recovery rates.

Yet, these gains are accompanied by mounting pressures on IT teams, who report widespread stress, burnout, and career disruptions following attacks – nearly 40% of respondents reported dealing with anxiety.

Over the past five years, ransomware has emerged as one of the most pressing threats to education, with attacks becoming a daily occurrence.

Primary and secondary institutions are seen by cybercriminals as “soft targets”, often underfunded, understaffed, and holding highly sensitive data.

The consequences are severe: disrupted learning, strained budgets, and growing fears over student and staff privacy. Without stronger defenses, schools risk not only losing vital resources but also the trust of the communities they serve.

Indicators of Success against Ransomware

The new Sophos study demonstrates that the education sector is getting better at reacting and responding to ransomware, forcing cybercriminals to evolve their approach.

Trending data from the Sophos study reveals an increase in attacks where adversaries attempt to extort money without encrypting data.

Unfortunately, paying the ransom remains part of the solution for about half of all victims.

However, the payment values are dropping significantly, and for those who have experienced data encryption in ransomware attacks, 97% were able to recover data in some way.

The study found several key indicators of success against ransomware in education:

  • Stopping More Attacks: When it comes to blocking attacks before files can be encrypted, both lower and higher education institutions reported their highest success rate in four years (67% and 38% of attacks, respectively)
  • Following the Money: In the last year, ransom demands fell 73% (an average drop of $2.83M), while average payments dropped from $6M to $800K in lower education and from $4M to $463K in higher education.
  • Plummeting Cost of Recovery: Outside of ransom payments, average recovery costs dropped 77% in higher education and 39% in lower education. Despite this success, lower education reported the highest recovery bill across all industries surveyed.

Gaps Still Need to be Addressed

While the education sector has made progress in limiting the impact of ransomware, serious gaps remain.

In the Sophos study, 64% of victims reported missing or ineffective protection solutions; 66% cited a lack of people (either expertise or capacity) to stop attacks; and 67% admitted to having security gaps.

These risks highlight the critical need for schools to focus on prevention, as cybercriminals develop new techniques, including AI-powered attacks.

Highlights from the study that shed light on the gaps that still need to be addressed include:

  • AI-powered threats: Lower education institutions reported that 22% of ransomware attacks had origins in phishing. With AI enabling more convincing emails, voice scams, and even deepfakes, schools risk becoming test grounds for emerging tactics.
  • High-value data: Higher education institutions, custodians of AI research and large language model datasets, remain a prime target, with exploited vulnerabilities (35%) and security gaps the provider was not aware of (45%) as leading weaknesses that were exploited by adversaries.
  • Human toll: Every institution with encrypted data reported impacts on IT staff. Over one in four staff members took leave after an attack, nearly 40% reported heightened stress, and more than one-third felt guilt they could not prevent the breach.

“Ransomware attacks on schools are among the most disruptive and brazen crimes,” said Alexandra Rose, Director, CTU Threat Research, Sophos.

“It’s encouraging to see schools getting better at responding and recovering, but the real opportunity is to stop attacks before they start. Prevention, backed by strong incident response planning and collaboration with trusted public and private partners, is essential as adversaries adopt new tactics, including AI-driven threats.”

Holding on to the Gains

Based on its work protecting thousands of educational institutions, Sophos experts recommend several steps to maintain momentum and prepare for evolving threats:

  • Focus on Prevention: The dramatic success of lower education in stopping ransomware attacks before encryption offers a blueprint for broader public sector organizations. Organizations need to couple their detection and response efforts with preventing attacks before they compromise the organization.
  • Secure Funding: Explore new avenues such as the U.S. Federal Communications Commission’s E-Rate subsidies to strengthen networks and firewalls, and the UK’s National Cyber Security Centre initiatives, including its free cyber defence service for schools, to boost overall protection. These resources help schools both prevent and withstand attacks.
  • Unify Strategies: Educational institutions should adopt coordinated approaches across sprawling IT estates to close visibility gaps and reduce risks before adversaries can exploit them.
  • Relieve Staff Burden: Ransomware takes a heavy toll on IT teams. Schools can reduce pressure and extend their capabilities by partnering with trusted providers for managed detection and response (MDR) and other around-the-clock expertise.
  • Strengthen Response: Even with stronger prevention, schools must be prepared to respond when incidents occur. They can recover more quickly by building robust incident response plans, running simulations to prepare for real-world scenarios, and enhancing readiness with 24/7/365 services like MDR.

Data for the State of Ransomware in Education 2025 report comes from a vendor-agnostic survey of 441 IT and cybersecurity leaders – 243 from lower education and 198 from higher education institutions hit by ransomware in the past year.

The organizations surveyed ranged from 100 – 5,000 employees and across 17 countries.

The survey was conducted between January and March 2025, and respondents were asked about their experience of ransomware over the previous 12 months.

Download the State of Ransomware in Education 2025 report on Sophos.com.


Don’t miss important articles during the week. Subscribe to techbuild weekly digest for updates

Join @techbuildafrica on Telegram
ShareTweetShareSendShare

Related Posts

2026 Investor Day
News & Insights

Spotify Bets on AI podcasts, Smarter ads, and Fan Experiences at 2026 Investor Day

Nairtime
News & Insights

Court Ruling Safeguards Airtime and Data Access for Millions of Nigerians

Kaspersky
News & Insights

Kaspersky Study Links Cyber Vulnerabilities to Poor Policies and Limited Employee Commitment

Subscribe Us

Recent Posts

  • Cascador Deploys $5M+ to Back Seven High-Impact Nigerian Startups
  • Celebrating a Decade of Impact: Africa Skills Hub Rebrands to ASH Africa
  • Anara Impact Capital Closes $48M First Fund to Back North Africa’s Impact Startups
  • Conversations 2026:Meet Meta Business Agent
  • Digital Encode Sounds Alarm Over Nigeria’s Rising Cybersecurity Failures
  • PayPal’s Account Crackdown in Kenya Exposes a Bigger Challenge for Cross-Border Payments
  • WhatsApp Experiments With Local Scam Detection to Strengthen User Safety
  • 7 Whale Wallet Patterns That Show Up Before Every Major Crypto Move
  • Africa’s EV Infrastructure Bet Gains Momentum as Spiro Secures $215M in Fresh Capital
  • Cube Cover, SLOT Roll Out Advanced Device Protection Service in Nigeria

Telegram

Join @techbuildafrica on Telegram
Innovation | Startups | Funding | Tech Blog in Africa

© 2013-2024 techbuild.africa. All Rights Reserved.

Navigate Site

  • About
  • Contact
  • Privacy
  • Sitemap
  • Terms
  • Blockchain
  • CleanTech

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Home
  • Startups
  • Hubs
  • Funding
  • WomenTech
  • CleanTech
  • Blockchain

© 2013-2024 techbuild.africa. All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Secret Link