Avoiding Ransomware
How Black Kite Pinpoints Ransomware Risk
Knowing who has been hit is useful. Knowing who is most likely to be noticed next is where prevention begins.
If you want to understand ransomware, look at the victims.
If you want to reduce ransomware risk, look at who is most likely to be noticed next.
Everything in this report so far has described the same underlying reality from different angles: ransomware groups do not pick victims at random. They weigh accessibility, profitability, exposed technology, industry, geography, and visibility. The Ransomware Susceptibility Index® (RSI™) is Black Kite’s way of measuring that logic directly, a single score that estimates how likely an organization is to land on a ransomware group's radar.

In the Black Kite platform, RSI surfaces the externally visible signals that shape a company's ransomware risk — from software vulnerabilities and stealer logs to misconfigurations and fraudulent domains alongside intrinsic indicators like organizational and industrial risk — all mapped against industry benchmarks and weighted by real-world exploitability.
What RSI Measures
RSI is a numerical score between 0.0 and 1.0, where a higher value reflects greater susceptibility to a ransomware attack. Unlike traditional security ratings that focus on technical hygiene alone, RSI is a composite signal.
RSI combines two kinds of input:

Technical Signals
misconfigurations, exposed remote access, exploitable vulnerabilities, stealer logs, leaked credentials, botnet activity, and other externally visible conditions that can support ransomware targeting.

Exploitability Context
Vulnerability exposure inside RSI is not based only on the number of CVEs or their CVSS severity. It also considers whether vulnerabilities are known to be exploited in the wild, whether they appear in KEV, whether exploitation is likely based on signals such as EPSS, and whether exploitability indicators suggest the issue is practical for attackers to use. In other words, RSI does not treat every vulnerability equally. It weighs vulnerability context through the lens of ransomware relevance.

An example of filtering vulnerabilities by CVSS severity, EPSS likelihood, and FocusTag® signals, surfacing the exposures most relevant to ransomware risk rather than every CVE in the environment.
That combination is the point. Everything in this report, from industry targeting to revenue patterns to supply chain exposure, is reflected in how RSI is constructed. Ransomware groups do not need to know an organization to find it. They use automation, leaked data, and open-source scanning to identify low-friction, high-leverage targets. RSI is built on the same logic, from the defender's side.
Where Ransomware Risk Concentrates
Ransomware is statistically rare. Across millions of companies worldwide and an estimated several thousand successful attacks each year, the base rate of victimization is low. But that rate changes sharply once an organization becomes visible to ransomware groups, and that is exactly what RSI captures.
The relationship is steep and consistent. Based on analysis of the period's ransomware victims against the full monitored population:
- 41% of companies with an RSI above 0.8 experienced a ransomware attack.
- 7.5% of companies with an RSI between 0.6 and 0.8 were hit.
- 5.1% of companies in the 0.4 to 0.6 range were attacked.
- 1.1% of companies between 0.2 and 0.4 experienced an attack.
- Just 0.14% of companies with an RSI below 0.2 were victimized.
RSI Distribution for Victims and Non-Victims, April 2025–March 2026
A company with an RSI above 0.8 was 291 times more likely to be attacked than a company below 0.2. That is not a marginal difference. It is the difference between a population at real risk and a population that ransomware groups largely pass over.
The selectivity matters as much as the correlation. Only a small fraction of all monitored companies carry an RSI above 0.8. RSI is not tuned to flag broadly and capture hits by volume. It isolates a small, high-risk population and assigns the elevated scores there, which is what makes a high RSI a meaningful signal rather than background noise.
Power of RSI

RSI in Motion: Spikes Matter
This is why RSI is useful beyond reporting. It gives security, third-party risk, and insurance teams a way to prioritize before an incident becomes public.
A high RSI can trigger deeper review, but movement matters too. In this year’s analysis, 93.5% of ransomware victims showed at least one RSI increase of 5% or more between consecutive months. Even sharper movement was common: 85.9% showed at least one RSI increase of 10% or more between consecutive months.
had at least one 5%+ RSI spike between consecutive months
had at least one 10%+ RSI spike between consecutive months
Based on analyzed ransomware victim RSI movement. Consecutive-month spikes show changes in ransomware susceptibility visibility, not proof of initial compromise path.
Commentary by Ekrem Selçuk Çelik, Cybersecurity Researcher, Black Kite
RSI Reveals Two Distinct Victim Profiles Before an Incident.
When we look across the victim population, two distinct RSI patterns emerge.
- Chronic elevation. Some organizations carry elevated RSI values for an extended period before disclosure. In these cases, the issue is not a sudden change, but sustained visibility. The longer an organization remains on the ransomware radar, the more opportunities attackers have to notice, revisit, and act. It is similar to the old saying: if you hang around the barbershop long enough, sooner or later you'll get a haircut. In ransomware terms, prolonged visibility increases the chance that exposure becomes opportunity.
- Sudden spike. Other victims show relatively lower RSI values for a period, followed by a sharp jump in the months before disclosure. This can happen when a highly exploitable vulnerability, exposed access path, stealer log finding, or cluster of ransomware-relevant signals pushes the organization into an elevated risk band.
Both patterns matter for defenders. Chronic elevation shows where exposure has persisted too long. Sudden spikes show where risk is changing quickly. That is why RSI should be monitored both as a threshold and as a movement signal.

RSI remained elevated before disclosure, showing sustained ransomware-relevant visibility.

RSI rose sharply before disclosure, showing how a small set of findings can quickly change ransomware susceptibility.
These movements do not prove how an incident began. They show something more operationally useful: ransomware-relevant visibility often changes before public disclosure. A company can become urgent not only by sitting in a high RSI band, but by moving quickly toward one.
That is where RSI becomes a workflow. A high score can tell teams where to look first. A sudden spike can tell them when to look again. KEV exposure, stealer logs, exploitable vulnerabilities, exposed remote access, and FocusTag signals can help explain why the score moved and what should be addressed first. This turns attacker-visible signals into prioritization: which vendors need attention, which business units require review, which vulnerabilities should move first, and where exposure is becoming urgent.
The broader lesson of this report applies here directly. Most victims were breached because they were visible, exposed, and reachable, not because they were uniquely weak. The signals were observable from the outside before the incident occurred.
It is not just who is weak. It is who is likely to get noticed.
RSI in Practice: When One Company Becomes Three Groups' Target
A prominent American technology company and defense contractor is the clearest example. The company appeared first under World Leaks in August 2025, with a Cyber Rating of 86 and an RSI of 0.465. In October, it appeared under Kyber, while its Cyber Rating dropped to 79 and RSI rose to 0.806. By March 2026, it appeared again under The Gentlemen, still carrying a high RSI of 0.752.
The Cyber Rating runs from 1 to 100 across 20 risk categories and is also expressed as a letter grade: A (excellent) 90 to 100, B (good) 80 to 89, C (fair) 70 to 79, D (poor) 60 to 69, and F (failing) 0 to 59.
One Company, Victimized Three Times
RSI nearly doubled after first appearance. Still elevated eight months later under a third actor brand.

RSI and Data Breach Index (DBI) scores for this company shows its ransomware susceptibility began climbing before the first leak site appearance in August 2025. The DBI spike marks the breach itself and both scores have remained elevated ever since, with RSI at 0.749 and DBI at 1.000 more than eight months later.
Its reappearance under three actor brands shows that high-value targets do not always remain attached to a single ransomware brand in a fluid affiliate economy.
Next: Payment rates stayed low. Large payments did not disappear.
Payment conversion remained low in some datasets, while large payments continued to appear. See why the pressure model changed and what actors did when direct payment failed.