Ransomware in South Africa: What Recovery Actually Costs
When a South African business gets hit by ransomware, the first call is usually to us. The second question, after “can you help?”, is always “how much is this going to cost?” The answer depends on how prepared they were before the attack.
Most businesses think they are prepared because they have backups. Having a backup is not the same as being able to recover. We have walked into situations where the backups were there, encrypted along with everything else, because they were on the same network with no air gap. Or the backups were fine, but nobody had ever tested a restore, and the recovery process took three weeks instead of three days.
The maths nobody does before it happens
Take a mid-sized business, 80 staff, turning over R30 million a year. A ransomware incident that takes systems down for a week costs roughly R150,000 in lost productivity alone, assuming everyone is sent home and nothing runs. Add the cost of the forensic investigation, the rebuild, the emergency IT support, the customer communication, and the lost orders during downtime. You are looking at R200,000 to R500,000 before you even get to the ransom demand, if you consider paying one.
The ransom itself, if paid, is usually negotiated down from the opening number, but it is still substantial. The problem is that paying does not guarantee you get everything back. Some ransomware families are well-run operations with customer support and decryption tools that work. Others are destructive. You pay and you get partial recovery, or nothing.
Why “we have backups” is not a recovery plan
A recovery plan answers specific questions. How long can we be down before the business is damaged? How much data can we afford to lose? What is the order of systems we bring back, and in what sequence? Who makes the call that we are failing over to DR? When did we last test a full restore?
If the answer to that last question is “we have not tested it” or “we tested it once when we set it up,” you do not have a recovery plan. You have a backup, which is a component of a recovery plan, not the plan itself.
What proper recovery looks like
Immutable backups are the starting point. Copies that cannot be altered or deleted, even by an admin account, even by ransomware that has domain admin rights. If your backup is on a share that a compromised account can reach, it is not immutable.
Tested restores are the next step. Not a full DR exercise every month, but at minimum a quarterly restore of a critical system to a test environment, with a documented recovery time. If it takes 18 hours to restore your file server and your business can only tolerate 4 hours of downtime, you need to know that before an attack, not during one.
We use Acronis Cyber Protect as our backup and recovery platform. It combines backup, disaster recovery, and endpoint protection in one stack, which means the same tool that protects your endpoints can also run your recovery. But we have also worked with clients who use Veeam, Commvault, or their own solution. Each of those is a capable platform. The plan around the tool is what makes recovery work. If you have a plan and you test it, your backup tool will do its job. If you do not have a plan, you have backups, not recovery.
The cost of prevention vs recovery
A proper backup and recovery setup for a mid-sized business costs a fraction of one ransomware incident. Immutable backups, tested restores, documented recovery procedures, and endpoint protection that includes anti-ransomware behaviour detection. All of that combined is less than the cost of a single bad week.
The businesses that recover fastest are the ones that planned for it. The ones that take the longest, and pay the most, are the ones who assumed it would not happen to them. If you want to know where you stand, contact us. We will tell you what we find, not what we want to sell.
What happens in the first 24 hours
The first 24 hours after a ransomware attack determine the shape of the recovery. The decisions made in that window — who to call, whether to isolate systems, whether to pay, whether to involve law enforcement — set the trajectory for everything that follows. Businesses that have a plan make those decisions in minutes. Businesses that do not make them in a state of panic, and the decisions are usually wrong.
The cost of a ransomware incident in South Africa is not just the ransom demand. It is the downtime, the lost revenue, the cost of rebuilding systems, the cost of recovering data, the reputational damage, and the regulatory consequences under POPIA. The ransom itself, if paid, is often the smallest line item. The businesses that recover well are the ones that planned for it before it happened.
Ransomware gets expensive long before the ransom demand arrives. We run a free attack-surface scan for South African companies. It’s passive, so nothing gets touched. You get a plain English report in your inbox. Start here: free security scan
Need Help With Your Security or IT?
We work with South African businesses to assess, deploy, and manage security and IT that actually fits. No jargon, no scare tactics. Practical advice and real support.
Contact Us →






