Download PDF (596 KB)
PDF version, ready to print or share with your team.
Most Canadian business owners ask the wrong question after a ransomware attack. They ask what the criminals will demand. That demand is rarely the biggest number on the final invoice. The days the business cannot operate are.
Fusion Computing has helped Canadian companies clean up incidents where the demand sat in the six figures and the eventual payout was CA$0. The real damage lives in the days a business cannot ship, bill, or serve a customer.
This benchmark sets the credible 2025 and 2026 figures against what we see at 15 to 200+ user companies in Canada. The headline numbers from Sophos, IBM, and Coveware describe an enterprise-heavy population. The lived reality for a 45-person distributor in Ontario looks different, and that gap is the whole point.
How much does a ransomware attack cost a Canadian small business in 2026?
According to the Sophos State of Ransomware (2026), the average cost to recover from an attack, excluding any payment to the criminals, reached US$1,700,200 over the trailing year. That is an 11% rise on the prior edition and still 38% below the 2024 peak. The median landed far lower at US$375,000.
Three numbers frame the range for a Canadian buyer. IBM (2025) put the average Canadian data breach at CA$6.98 million, up 10.4% in a year. Sophos puts the global mean at US$1.7 million. Statistics Canada (2024) puts total Canadian recovery spending at CA$1.2 billion.
The first two are enterprise-skewed. The third is not, and it is the one worth anchoring on, because Canadian small businesses accounted for roughly CA$300 million of that total. A serious incident at a sub-150-employee Canadian firm runs roughly CA$135,000 to CA$250,000 all in, concentrated in idle days rather than the ransom itself.
How long does ransomware downtime actually last?
According to Sophos (2026), 55% of victims recovered within one week and 16% inside a single day, while 83% were back within a month and 3% took longer than three months. For an unprepared Canadian SMB, the realistic planning window is one to three weeks before normal production returns.
The companies that recover in days have one thing in common. Their backups were immutable and proven before the attack rather than after it. Sophos recorded backup-based recovery rebounding 12 points to 66% of encrypted-data incidents in 2026, and only 2% of victims got nothing back at all.
Here is the difference in practice. When Fusion Computing responded to a ransomware foothold at a Ontario industrial-supply distributor, the company was in full production in about 62 hours. Detection landed Friday at 5:47 PM. Monday at 8:00 AM the warehouse was shipping. The full recovery timeline is published here.
The clients who recover fast are not the ones with the biggest security budget. They are the ones who tested a restore in the last 90 days and knew it worked. We treat the untested backup as the single most expensive line item a business does not know it owns.
Where does the money actually go in a ransomware incident?
According to Statistics Canada (2024), Canadian businesses spent CA$1.2 billion recovering from cyber security incidents in 2023, double the 2021 total, even though the proportion of businesses affected fell to 16%. Recovery got more expensive per incident while incidents grew rarer. Idle staff and stalled revenue form the largest line by a wide margin.
See whether your backups would actually survive a ransomware attack →
The order the costs arrive in.
The cost anatomy stacks in a predictable order. Idle staff and stalled revenue come first. Incident response and rebuild labour come second. Then breach notification and legal review, which in Canada means the PIPEDA real-risk-of-significant-harm reporting duty and, in Quebec, Law 25.
Customer churn and reputational repair trail behind, and they last longest. A business that bills CA$50,000 a day loses that whether or not a single byte is encrypted. When backups hold, the ransom line can be zero. The lost-revenue line never is.
Pay the criminals versus restore from backup: how do the two paths compare?
According to Sophos (2026), the share of victims paying to get data back fell to 48%, the lowest rate in three years, while the median payment dropped to US$769,000 from US$1 million. Paying bought neither speed nor certainty. The table sets the two recovery paths against the four factors that decide the final bill.
| Factor | Pay the criminals | Restore from tested backups |
|---|---|---|
| Speed | Slow. Decryptors are buggy and partial. | Fast when the restore was rehearsed. |
| Data integrity | No guarantee. Some files never decrypt. | Clean, known-good copy. |
| Repeat risk | Marks you as a payer. | Closes the door the attacker used. |
| Legal exposure | Sanctions screening and PIPEDA risk. | Cleaner reporting position. |
Should you pay the ransom?
Most Canadian victims do not pay, and the ones who do pay far less than global headlines suggest. Statistics Canada found 88% of Canadian ransomware victims made no payment at all. Coveware, working from incident-response casework (2025), put the paying rate at 26% in the second quarter of 2025.
One caution on the data. CIRA (2025) polled 500 Canadian cybersecurity decision-makers and found 74% of those hit had paid. That survey and the Statistics Canada census describe different populations, so the two figures should not be blended. The throughline holds either way. A decryptor is slow, partial, and legally fraught.
What makes ransomware recovery faster and cheaper?
Three controls do most of the work of cutting recovery cost. Immutable backups tested monthly, endpoint detection and response paired with a 24/7 security operations centre, and an incident response plan rehearsed as a tabletop. Each maps to CIS Controls (2024), and each shortens the recovery clock measurably.
Why containment speed decides the invoice.
That engagement shows why the security operations centre matters. Fusion Computing isolated the first compromised endpoint about three minutes after the alert fired. That containment stopped a two-endpoint foothold from becoming a site-wide encryption event. The air-gapped backups, verified every month, were never reached. The demand was roughly CA$180,000. The amount paid was CA$0, with zero data loss.
- Tested immutable backups. Sophos measured backup-based recovery rebounding 12 points to 66% of incidents in 2026, with only 2% of victims getting no data back. The deciding factor is whether the restore was proven before the attack.
- EDR plus a 24/7 SOC. How fast you contain decides the blast radius. Sophos found 79% of 2026 attacks began with an identity-based approach.
- A rehearsed IR plan. The Canadian Centre for Cyber Security playbook (ITSM.00.099) sets the sequence. The first hour is a poor time to discover who calls the insurer.
“I got the call no business owner wants. Our systems were locked and there was a ransom demand on every screen. Fusion had someone working on it within the hour, and by Monday morning our team walked in, sat down, and got back to work like nothing happened.”
What does ransomware cost by company size and sector in Canada?
Cost scales with revenue per hour and data sensitivity, not headcount alone. Statistics Canada found 16% of Canadian businesses were affected by a cyber security incident in 2023, rising to 30% of large firms, and 13% of those affected faced ransomware. A 10-person professional-services firm and a 120-person manufacturer carry very different hourly exposure.
This is where the objection we hear most often falls apart. Fusion Computing benchmarks against the incidents we are called in to clean up for non-clients. A 25-seat Canadian firm that takes a direct ransomware hit averages roughly CA$180,000 to CA$240,000 in direct cost, plus 14 to 21 days of lost productivity.
A right-sized managed security program for that firm runs CA$180 to CA$250+ per user per month. One prevented incident pays for years of the program, and in our practice no client has gone five years without an attempted one.
Architecture and engineering firms sit at the expensive end of that range, because a locked Revit or BIM model stops billable work outright. See cybersecurity for architecture and engineering firms for the file and backup decisions that set the cost.
How sector changes the bill.
Sector matters on top of size. PHIPA in Ontario, Law Society confidentiality duties, and OSFI expectations each change what a recovery costs before a single server is rebuilt.
- Healthcare. PHIPA breach duties apply to health information in Ontario.
- Legal. Client confidentiality and Law Society obligations sit on top of privacy law.
- Regulated finance. OSFI expectations shape how an incident gets reported and reviewed.
Get a real recovery-time estimate for your environment before an attacker forces one →
Why Canadian firms bring this work to Fusion Computing.
CISSP-led, a Microsoft Solutions Partner and a CompTIA Managed Services Trustmark holder, securing IT for Canadian SMBs across Toronto, Hamilton, and Metro Vancouver since 2012.
Fusion Computing helps Canadian businesses across Toronto and the GTA, Hamilton, and Metro Vancouver with managed IT, cybersecurity, and Microsoft 365. Disaster recovery planning is covered in our disaster recovery best practices guide.
Free download
The 62-Hour Ransomware Recovery Runbook
The hour-by-hour sequence behind the 62-hour Ontario restore, plus the backup verification and breach-notification checklists our CISSP-led team works before an incident rather than during one.
No sales call required. Want your restore path pressure-tested first? Book a consultation.
What a funded recovery plan requires: the pre-incident checklist.
Three things have to be true before an attack, because none of them can be arranged during one. Fusion Computing works this order with every Ontario and British Columbia client we onboard.
- A restore tested inside the last 30 days, from a copy the domain cannot reach.
- A named person who calls the insurer, counsel, and the privacy commissioner.
- A written revenue-per-hour figure, so the recovery budget has a real ceiling.
Frequently Asked Questions
Does cyber insurance cover ransomware recovery costs in Canada?
Sometimes, and increasingly with conditions. Most Canadian cyber insurers now require multi-factor authentication, endpoint detection and response, and tested backups before they will bind a policy. Carriers have denied claims where those controls were missing. Statistics Canada found 22% of Canadian businesses carried cyber risk insurance in 2023, up from 16% in 2021. Treat insurance as a backstop, not a replacement.
Do you have to report a ransomware attack in Canada?
Often yes. PIPEDA requires reporting any breach that poses a real risk of significant harm to the Office of the Privacy Commissioner and to affected individuals, plus keeping records of every breach for 24 months. Quebec’s Law 25 adds its own notification duties, and PHIPA governs health information in Ontario. The clock starts when you become aware.
What is the average ransomware payment in 2026?
Sophos reports a median payment of US$769,000 in its 2026 survey, down from US$1 million a year earlier, with 48% of victims paying at all. Canadian figures run far lower. Of the Canadian victims who paid anything, Statistics Canada found 84% paid under CA$10,000 and only 4% paid more than CA$500,000.
Can you recover from ransomware without paying the ransom?
Yes, and most Canadian victims do. Statistics Canada found that 88% of Canadian businesses hit by ransomware did not pay, and Sophos reports that only 2% of victims in 2026 got no data back at all. The deciding factor is whether your backups are immutable and were tested before the attack.
Is it legal to pay a ransomware ransom in Canada?
Paying is legal in Canada in most cases, yet it carries real risk. Sending funds to an entity on a Canadian or US sanctions list can expose your business to penalties, and paying marks you as a willing target for repeat attacks. Most incident-response counsel advises exhausting backup recovery first.
If you pay the ransom, do you get all your data back?
Rarely all of it. Attacker-supplied decryptors are slow, buggy, and frequently fail on a portion of files. Sophos found 48% of 2026 victims paid, yet backup-based recovery was used in 66% of encrypted-data incidents. A tested backup beats a decryption key on both speed and data integrity.
How fast can a managed IT provider restore operations after ransomware?
With immutable backups tested monthly and a 24/7 security operations centre, full restoration can take hours rather than weeks. Fusion Computing returned a 45-employee Ontario distributor to full production in about 62 hours, from Friday-evening detection to Monday-morning shipping, because the recovery path was rehearsed before the incident rather than improvised during it.
What is the most expensive part of a ransomware attack?
Downtime and lost productivity, not the ransom. A company that bills CA$50,000 a day loses that revenue whether or not a single file is encrypted, and recovery labour follows close behind. When backups hold, the payment line can be zero while the downtime line never is. That is where the budget belongs first.
How common is ransomware for Canadian small businesses?
Common enough to plan for. Statistics Canada found 16% of Canadian businesses were affected by a cyber incident in 2023, rising to 30% of large firms. CIRA’s 2025 survey found 24% of organizations hit by ransomware in the past year. The risk is no longer rare for a typical SMB.
Talk through your incident response plan with a CISSP before you need it →
What single control most reduces ransomware recovery cost?
A tested, immutable backup. The Sophos 2026 report shows backup-based recovery rebounding 12 points to 66% of incidents, with only 2% of victims getting no data back at all. The ones who recovered in days had verified their restore beforehand. Fusion Computing treats the untested backup as the most expensive line item a business does not know it owns.
How much should a Canadian SMB budget for ransomware readiness?
A right-sized managed security program runs CA$180 to CA$250+ per user per month, so a 25-seat Ontario firm should plan on roughly CA$3,250 to CA$4,500 a month. Set that against the CA$180,000 to CA$240,000 direct cost and 14 to 21 lost days we see on unprotected environments. One avoided incident covers several years of the program.
How do you know whether your backups would survive a ransomware attack?
Test three things. Restore a real file set from a copy no domain account can reach, and time it. Confirm the recovery points are immutable for at least 30 days. Check the date of the last successful test restore, because Sophos found 62% of 2026 victims cited a known or unknown security gap as a factor in the attack.

