Truvo CyberStats Updated 2026 · Canadian data
Truvo Cyber · Sources: Statistics Canada (Oct 2024); CIRA Cybersecurity Survey (Oct 2025)
Canadian ransomware data · 2024–2025
Most Canadian organizations don't pay ransom. Most do.
Two of the most-cited Canadian cybersecurity surveys produce nearly opposite numbers — and both are correct. Click each side to see why the contradiction matters for your incident response strategy.
Statistics Canada
88%
of Canadian businesses hit by ransomware did not pay.
Source: Statistics Canada, 2023 Canadian Survey of Cyber Security and Cybercrime · ~12,000 enterprises with 10+ employees, all sectors except public administration
Why this number is correct
Both correct
CIRA
74%
of Canadian organizations hit by ransomware did pay — typically $25K+.
Source: CIRA 2025 Cybersecurity Survey · 500 IT decision-makers at Canadian organizations with active cybersecurity programs
Why this number is correct

Why "88% don't pay" is correct

Statistics Canada's biennial Cyber Security and Cybercrime Survey samples roughly 12,000 enterprises across nearly every sector. The sample includes thousands of small businesses with limited digital exposure, restaurants, contractors, regional operators, for whom a ransomware "incident" may mean an encrypted laptop or a ransomed website backup.

Those organizations have less reason to pay. The data isn't critical enough to extort effectively, and they can rebuild from scratch faster than they can negotiate.

When the population is "all Canadian businesses with 10+ employees," most ransomware victims walk away. The math favors not paying.

Why "74% do pay" is correct

CIRA's annual survey targets roughly 500 Canadian IT decision-makers, by definition, organizations with active cybersecurity programs, dedicated security spend, and the kind of operational complexity that makes downtime catastrophic.

These are the organizations attackers actually target. They run data and operations that make ransom payment a serious option, and increasingly, the only fast option. Of those who paid, typical payments exceeded $25,000, and 74% also had data exfiltrated as part of the attack.

When the population is "Canadian IT leaders at orgs with real security programs," most ransomware victims pay. The math favors paying.
What this means for your organization

Whether your organization pays a ransom is mostly determined before the attack.

Backup posture, identity controls, segmentation, monitoring, and incident response readiness are what move an organization from the CIRA cohort to the Statistics Canada cohort. The cost of getting this right is measurable. The cost of getting it wrong now runs to hundreds of millions in Canadian courts.

Building an effective security program is what moves you from the CIRA cohort to the Statistics Canada cohort.
Talk to Truvo
Citation copied