A comprehensive new report titled Data Health Check 2025 from Databarracks  offers valuable insights into the state of global data protection, security practices, and organisational resilience across various industries.

Based on data collected from hundreds of organisations, the report highlights significant trends shaping the cybersecurity world, including an alarming increase in cyberattacks, particularly ransomware incidents, alongside evolving corporate strategies to defend against such threats.

Ransomware Attacks Rising Despite Growing Awareness

One of the most notable findings of the report is the sharp increase in ransomware attacks across sectors. The data suggests that nearly 9 out of 10 organisations experienced a cyberattack in the past year, with ransomware being the most prominent attack vector. Governments and private sectors alike report frequent breaches, often resulting in costly operational downtime and data loss.

Indeed, the actual number of ransomware payments and successful attacks is likely underreported, creating a false sense of security and hindering comprehensive threat assessment efforts. Dr. Ilia Kolochenko, CEO of ImmuniWeb and a Fellow at the British Computer Society, offers a nuanced perspective on interpreting these figures. He comments: 

“The report is very interesting but numbers in the report may be potentially misleading for several reasons. First, in view of the growing number of legislative bans on ransomware payments in certain entities, such as for providers of critical national infrastructure (CNI), many victims – who nonetheless paid the ransom – will never admit this fact. Second, there are numerous consultants and companies that now offer their services to negotiate ransom with attackers, eventually trying to reduce the amount or even get the data for free. Sometimes the consultants are used as proxies to actually pay the ransom, while the amount paid to cybercriminals will be disguised as ‘consulting fees’, making everyone believe that no ransom was paid.”

He further explains: “Finally, ransomware actors are now even more creative and militarily pragmatic in their extortion campaigns. If the victim is slow or reluctant to pay the ransom, the attackers will quickly find another buyer, such as a direct competitor in a foreign country, who will readily pay much more for the very same data.”

Despite these disclaimers, the report notes that an increasing number of organisations are effectively avoiding ransom payments thanks to improved backup solutions and incident response strategies. 

Security Gaps & Data Breaches Continue To Escalate

The report further highlights that many organisations remain vulnerable due to outdated security measures and insufficient investment in cybersecurity infrastructure. Nearly 60% of respondents reported security gaps in their systems, and many admitted to inadequate control over third-party vendors, which often serve as entry points for cybercriminals.

Data breach incidents are also rising, with a notable increase in the number of data leaks involving personally identifiable information (PII) and sensitive corporate data.

The report emphasises that these breaches not only result in regulatory sanctions but also damage brand reputation and erode customer trust.

Compliance & Data Governance: Critical Challenges

Adherence to new and evolving data protection regulations – including GDPR in Europe and various national privacy laws – remains a key challenge. The report reveals that over 70% of organisations find compliance efforts complex and resource-intensive, often resulting in delays or gaps in enforcement.

Additionally, many firms struggle with data governance, especially around data localisation requirements and managing cross-border data flows. This fragmentary approach increases vulnerability to both legal penalties and malicious exploitation.

The Growing Role of AI & Automation

The report shows a rising adoption of AI and automation tools in cybersecurity strategies. Organisations are leveraging AI-based threat detection systems to identify anomalies and respond to attacks faster. However, adversaries are also evolving their tactics, using AI to craft more sophisticated malware and evasion techniques.

Building Resilience In A Fast-Changing Environment

The report demonstratess that resilience goes beyond just technical measures. Organisational resilience includes comprehensive incident response planning, employee training, and collaboration with external partners.

The ongoing geopolitical tensions and the increasing commercialisation of cybercrime make a proactive, layered approach essential.

Call To Action

The Data Health Check 2025 clearly indicates that cybersecurity threats are escalating, and organisations must invest more strategically in their defensive measures. As Dr. Kolochenko notes, understanding the true scope of ransomware and other cyber threats remains a challenge because of underreporting and covert tactics.

Heightened awareness, improved technical solutions, and international cooperation are vital.

In conclusion, the report strongly advises businesses to continuously review and upgrade their security infrastructure, foster a security-conscious corporate culture, and remain vigilant against evolving threats. Only through proactive measures and transparency can organisations hope to turn the tide against cybercriminals in 2025 and beyond.

Image: Ideogram

 Source: Cyber Security Intelligence