Sophos has recently released their eagerly-awaited State of Ransomware Report 2025, which provides an in-depth analysis of the current ransomware landscape and highlights the evolving tactics and techniques used by cybercriminals. The report emphasises the increasing sophistication of ransomware attacks, which now leverage AI and machine learning, and the huge impact these are having on businesses in 2025. Worryingly, these trends are set to continue.
Here are Minerva’s main takeaways from the Ransomware Report 2025:
- Evolving Tactics and Techniques: The increasing sophistication of ransomware attacks, whereby AI and machine learning are employed to identify vulnerabilities and execute tailored attacks
- Supply Chain Attacks: The notable rise in supply chain attacks, where malicious actors target third-party vendors to compromise larger organisations
- Financial Implications: The financial impact of ransomware attacks, with the resulting downtime and financial losses being devastating for businesses
From the findings in the report, here are Minerva’s key recommendations for businesses:
- Implement Advanced Threat Detection: Businesses should invest in advanced threat detection systems that leverage AI and machine learning to identify and mitigate ransomware threats before they can cause significant damage
- Enhance Data Encryption: Encrypting sensitive data can prevent unauthorised access and reduce the impact of ransomware attacks. This ensures that even if data is compromised, it remains unreadable to attackers
- Adopt Data Loss Prevention (DLP) Measures: Implementing DLP measures can help businesses monitor and protect critical data, ensuring that it is not exfiltrated or misused during a ransomware attack
- Focus on Supply Chain Security: Given the rise in supply chain attacks, businesses should
ensure that their third-party vendors and partners adhere to robust cybersecurity practices to prevent indirect compromises - Importance of Robust Cybersecurity Measures: There is a need for advanced threat detection,
encryption, and data loss prevention to mitigate the impact of ransomware incidents, and a need for comprehensive cybersecurity strategies that include both preventive and responsive measures to ensure operational continuity and regulatory compliance

The aim of our recommendations from the ransomware report 2025 is to help businesses strengthen their defences against ransomware and minimise the potentially devastating impact of such attacks. Minerva has been protecting SMEs against cyber threats for decades and we can assist you on any of the issues outlined above. Now more than ever before, we need to be working together to stay ahead of the game and outsmart the ever-evolving threats.
If you would like to read the full Sophos Ransomware Report 2025, it is available to download here.
If you would like to discuss any of the issues raised in this blog, or you would like Minerva to carry out a FREE audit of your current cybersecurity provision, please contact us on 01707 607100, email contactus@minervauk.com or book an appointment via Calendly and we would be delighted to assist you.