Data sensitivity / regulatory exposure
High ↑
↓ Low
← No backups
Backups verified and restorable
Backups verified →
High sensitivity · No backups
Highest pressure to pay
No clean restoration path. Regulatory clock ticking. Sanctions exposure on every payment decision. The worst possible position.
See scenario ›
High sensitivity · Backups verified
Restore, notify, hold the line
Indigo's posture in 2023. Costly to recover but able to refuse payment without losing the business.
See scenario ›
Low sensitivity · No backups
Rebuild from clean
Painful, but manageable. Most StatCan small-business "non-payers" sit here. The data isn't valuable enough to pay for.
See scenario ›
Low sensitivity · Backups verified
Restore, document, report
The strongest position. Standard incident response runs cleanly. Insurance and counsel handle the residual.
See scenario ›
Click a quadrant to expand
Find your quadrant
The Statistics Canada / CIRA paradox. StatCan reports 88% of Canadian ransomware victims didn't pay (sample = 12,462 enterprises with 10+ employees, all sectors). CIRA reports 74% of victims paid (sample = ~500 cybersecurity decision-makers at organizations with active programs). Both numbers are correct. The difference is which quadrant the sampled organizations sit in.
What this means for your organization
Backup posture and data sensitivity are the two levers that move you across this matrix. Both are programmatic decisions, not technical ones.
Backups that aren't routinely tested are not really backups. Data sensitivity that isn't classified is treated as low until a regulator decides it wasn't. Moving to the bottom-right quadrant requires structured discipline, exactly what an effective security program produces.