Skip to main content
New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
blog

Ransomware Complacency Has a Real Cost

Published

Nov 6, 2025

Updated

Sep 3, 2026

INTRODUCTION

Ransomware, ransomware, ransomware.

It's starting to sound like the cybersecurity version of "Marcia, Marcia, Marcia," the Brady Bunch sister who absorbed all the attention.

CISOs have heard the warnings so many times that many have stopped prioritizing them. That's not fatigue, that's ransomware complacency, and it's exactly what attackers are counting on.

The 2026 Ransomware Report found the threat hasn't slowed down. It has moved to the place organizations are least prepared, inside their third-party ecosystem.

Ransomware Fatigue Turns Into Complacency

It's not surprising that CISOs have tuned out ransomware headlines. The industry has pounded the same drum for years. And, after all, AI is the only risk that matters :-) For readers who want the fundamentals refreshed, Black Kite's Ransomware Knowledge Center covers how these attacks work and how they've evolved. That reaction doesn't signal indifference. It signals desensitization, like the bad smell that fades the longer you're exposed to it. The constant warnings have dulled our senses.

Part of the problem is that some CISOs have convinced themselves they've done all they can. Their teams have implemented the right controls: patching, MFA, backups, the usual checklist. Vendors may have promised silver bullet solutions, often powered by AI, that claim to make ransomware "go away." Add the false sense of relief that came with high-profile takedowns of groups like LockBit and AlphV, and it's easy to see how some organizations feel like the worst is behind them.

But while attention wanes, threat actors are finding easier entry points through the supply chain. The 2026 Ransomware Report shows exactly how much ground they've covered:

  • 7,551 publicly disclosed ransomware victims between April 2025 and March 2026, a 24.9% increase over the previous reporting period and the fourth straight year disclosures have set a new high
  • 127 active ransomware groups, as operators reorganized and rebranded rather than disappearing

The landscape today is more fragmented and less predictable than it's ever been, and attackers are finding new ways in.

The Real Exposure Point is Your Vendor Ecosystem

Big-name breaches still make headlines, but the 2026 Ransomware Report found the middle of the market, not the top, drove this year's growth.

The Middle Market Is Driving Growth

  • Victims in the $50M–$100M revenue band grew from 25.1% to 29.3% of the year's disclosures
  • The $100M-plus tier fell from 13.9% to 9.5%

Large enterprises still matter, but they stopped being the engine of the growth. For a closer look at why smaller and mid-sized vendors remain such a frequent target, see Why Ransomware Groups Are Targeting SMBs.

Trusted and Commonly Deployed Vendor Platforms Are the New Attack Path

The report also found trusted vendor platforms becoming one of the year's primary attack paths. Campaigns that moved through compromised OAuth tokens and connected SaaS applications, rather than through a company's own perimeter, hit organizations that had done everything right on their own systems.

For ransomware groups, this is a low-effort, low-risk, high-reward formula. And the damage doesn't stop with one victim. When a vendor is compromised, the impact ripples far beyond the initial target.

This played out with Knights of Old, a 158-year-old British logistics company that collapsed after a ransomware attack. Upstream and downstream businesses were left waiting for the company's trucks. Shipments of raw materials, parts, and consumer goods never arrived. It wasn't just one company that suffered. The attack impacted every business that relied on the logistics company to keep operations running.

The pattern repeated at national scale in September 2025, when a cyberattack shut down Jaguar Land Rover's UK production for five weeks. The Cyber Monitoring Centre estimated the incident cost the UK economy £1.9 billion and affected roughly 5,000 organizations across JLR's supplier network and dealerships, making it the most financially damaging cyber event in British history. The Bank of England cited the shutdown as a drag on UK GDP growth that quarter.

That's the risk of ransomware in the modern supply chain. One weak link can lead to cascading failures across entire industries.

A Pattern That Keeps Repeating

  • CDK: a dealership software outage that froze auto sales nationwide
  • Cleo: a mass file-transfer exploit that hit dozens of downstream companies at once
  • Change Healthcare: a pharmacy and claims-processing disruption that delayed patient prescriptions
  • Salesloft Drift and Gainsight (2026): compromised OAuth tokens exposed Salesforce customers who never suffered a direct breach of their own systems

Read more on how these and similar  incidents unfolded in the 2026 Third-Party Breach Report. These weren't just isolated "third-party breaches." They set off domino effects that hit everyone down the line.

An attack doesn't need to hit your front door to bring your house down. You might have robust defenses and a strong security posture, but it's almost guaranteed that your third parties don't. That's what today's ransomware environment demands you watch for.

Two Shifts Turn Complacency Into Proactive Ransomware Defense

This is the pushback to complacency. Two concrete shifts move a security program from reactive to proactive.

Replace Point-in-Time Assessments With Continuous Vendor Monitoring

You've likely invested heavily in hardening your internal systems, but that's only part of the picture. In an interconnected third-party ecosystem, your next breach might come from a vendor with five employees and no security lead.

Too many organizations still rely on point-in-time assessments, such as security questionnaires and static risk scores. These approaches are inherently limited. They don't reflect real-time shifts in exposure or account for the rapidly evolving tactics of ransomware groups.

That's why continuous monitoring is essential. Black Kite's Ransomware Susceptibility Index® (RSI™), part of Black Kite's ransomware threat intelligence capabilities, provides a real-time view into third-party risk, helping security teams identify vendors most likely to appear on a ransomware group's radar. The data behind it makes the case on its own:

  • Organizations with an RSI above 0.8 are 291 times more likely to have suffered a ransomware attack than those scoring below 0.2
  • 93.5% of this year's victims showed a meaningful RSI increase in the months before they were hit, a signal visible from the outside well before disclosure

Complacency sets in when teams feel like they're reacting to everything and solving nothing. Proactive third-party risk management changes that. It helps you identify, prioritize, and remediate potential vulnerabilities before they disrupt operations, with continuous monitoring doing the heavy lifting instead of a once-a-year questionnaire.

Quantify Ransomware Risk in Terms the Business Understands

Complacency isn't just about hearing the same message on repeat. It's a sign the risk isn't being explained in a way that resonates with stakeholders.

A CEO recently told me he was worried about ransomware. When I pressed further, he couldn't articulate why. He knew it was a threat, but not what it meant for his business.

That disconnect is still too common, and it feeds the cycle that wears everyone down. CISOs understand the technical risks, but until they translate those into business terms, they'll keep getting the same questions from their CEO. What does this mean for us? Should we be worried? How much could this cost us? Those repeated conversations reinforce complacency because leadership stays concerned without being equipped to make decisions.

Black Kite's Cyber Risk Quantification (CRQ) solution closes that gap. Built on the Open FAIR™ methodology, it converts a vendor's security posture into a dollar figure instead of a color-coded score. Instead of saying "this might be bad," a CISO can say "this supplier getting hit could cost us $12M in revenue." For a closer look at how those scenarios get built, see FAIR Scenarios for Ransomware Business Interruptions.

That reframes cybersecurity as a business risk, making it easier for executives to engage. CRQ strengthens your position when requesting budget, negotiating with vendors, or making the case for prioritization. When leadership can see how cyber risk maps to business impact, whether downtime, financial loss, or reputational damage, they're far more likely to buy in and commit the resources needed.

Complacency Is Every Ransomware Attacker's Best Friend

Ransomware complacency is real, but it also serves as a warning sign. It tells us the way we're communicating about and managing cyber risk isn't working. When every headline sounds the same and every alert feels like background noise, critical threats get lost in the shuffle.

Security leaders don't need more noise. They need sharper focus:

  • Knowing where you're exposed through third parties
  • Understanding which risks actually matter
  • Being able to show what's at stake in business terms

Talking about ransomware might feel like a broken record, and that repetition is exactly what breeds complacency. The moment security teams stop paying attention is the moment attackers get what they want. Complacency is what keeps the door wide open.

Ready to move past complacency and into action? Read the 2026 Ransomware Report, browse Black Kite's full library of ransomware reports, and explore how RSI™ can help you spot risk before it hits.