Truvo CyberStats Truvo analysis · Canadian incident-response patterns
Sources: Truvo Cyber analysis based on Canadian incident-response patterns. Population framing per Statistics Canada CSCSC 2023 (88% non-payment) and CIRA 2025 Cybersecurity Survey (74% payment).
Ransomware decision matrix · Canadian context
Whether your organization pays a ransom is mostly determined before the attack.
Two factors drive payment outcomes more than any post-incident decision: backup posture and data sensitivity. Click any quadrant to see the scenario in detail. The position you sit in today is the position you'll respond from when the attack arrives.
Data sensitivity / regulatory exposure
High ↑
↓ Low
← No backups
Backups verified and restorable
Backups verified →
High sensitivity · No backups
Highest pressure to pay
No clean restoration path. Regulatory clock ticking. Sanctions exposure on every payment decision. The worst possible position.
See scenario
High sensitivity · Backups verified
Restore, notify, hold the line
Indigo's posture in 2023. Costly to recover but able to refuse payment without losing the business.
See scenario
Low sensitivity · No backups
Rebuild from clean
Painful, but manageable. Most StatCan small-business "non-payers" sit here. The data isn't valuable enough to pay for.
See scenario
Low sensitivity · Backups verified
Restore, document, report
The strongest position. Standard incident response runs cleanly. Insurance and counsel handle the residual.
See scenario
Click a quadrant to expand
Find your quadrant
The Statistics Canada / CIRA paradox. StatCan reports 88% of Canadian ransomware victims didn't pay (sample = 12,462 enterprises with 10+ employees, all sectors). CIRA reports 74% of victims paid (sample = ~500 cybersecurity decision-makers at organizations with active programs). Both numbers are correct. The difference is which quadrant the sampled organizations sit in.
What this means for your organization

Backup posture and data sensitivity are the two levers that move you across this matrix. Both are programmatic decisions, not technical ones.

Backups that aren't routinely tested are not really backups. Data sensitivity that isn't classified is treated as low until a regulator decides it wasn't. Moving to the bottom-right quadrant requires structured discipline, exactly what an effective security program produces.

An effective security program moves your organization from the top-left quadrant to the bottom-right. Truvo Cyber builds the backup, classification, and response architecture.
Talk to Truvo
Citation copied