Statistics Canada's biennial Cyber Security and Cybercrime Survey samples roughly 12,000 enterprises across nearly every sector. The sample includes thousands of small businesses with limited digital exposure, restaurants, contractors, regional operators, for whom a ransomware "incident" may mean an encrypted laptop or a ransomed website backup.
Those organizations have less reason to pay. The data isn't critical enough to extort effectively, and they can rebuild from scratch faster than they can negotiate.
CIRA's annual survey targets roughly 500 Canadian IT decision-makers, by definition, organizations with active cybersecurity programs, dedicated security spend, and the kind of operational complexity that makes downtime catastrophic.
These are the organizations attackers actually target. They run data and operations that make ransom payment a serious option, and increasingly, the only fast option. Of those who paid, typical payments exceeded $25,000, and 74% also had data exfiltrated as part of the attack.
Backup posture, identity controls, segmentation, monitoring, and incident response readiness are what move an organization from the CIRA cohort to the Statistics Canada cohort. The cost of getting this right is measurable. The cost of getting it wrong now runs to hundreds of millions in Canadian courts.