
REPORT
The State of Data Security: Measuring Your Data's Risk
The Rubrik Zero Labs report discusses how humans make decisions, and how this affects cybersecurity thinking, why organizations are optimistic about their data security despite the realities and trusted methods to improve your data security.
Executive Summary
Executive Summary
This year, 2025, marks the much-anticipated implementation of The Digital Operational Resilience Act (DORA) in the European Union. While businesses ready themselves for implementation, what are the true costs to those in the financial sector? What stress has that put on the workforce? What are the biggest threats to financial services security?
This is a story about data. The data types you own, how data changes, and a pragmatic view of data threats.
It’s
also
a
story
about
risk.
How we measure it, our ability to plan for it, how it changes, and its never-ending presence. But first, let’s explain how we got here.
Data and Methodology
Data and Methodology
Rubrik Zero Labs strives to deliver actionable, vendor-agnostic insights to reduce data security risks. To that end, we incorporated findings from four primary sources:
Rubrik Telemetry
We utilized Rubrik telemetry in an effort to understand a typical organization’s data estate and the risk realities.
Wakefield Research
Perspectives from 1,600+ IT and security leaders
Rubrik Partners
Research and guidance from two Rubrik partner organizations
Contributing Organizations
Research from respected cybersecurity organizations and institutions
Rubrik Telemetry
Rubrik Zero Labs believes if organizations trust us with their data, we must be transparent about what their data tells us. Speaking of transparency, here’s what makes up our telemetry and how it influences our perspective.
Note: This study contains the first use of Laminar-derived data. Laminar is a leading data security posture management platform acquired by Rubrik in 2023.
68 Countries
6,000+
38.4+ Billion Sensitive Data Records
- 42 EB secured
- 41 exabytes of logical storage
962 backend petabytes (BEPB) of physical storage
Data covers 1 January 2023 through 31 December 2023
EB vs BEPB
A reminder from the data nerds: When most of the world hears “data,” they think of logical storage, also known as frontend storage. Those of us in the data business focus on backend storage. Rubrik takes the entirety of an organization’s data and performs a number of different techniques—including deduplication and compression—to reduce the amount of frontend data to backend storage. We’ll use backend storage throughout this report.
How much is 42 EB?
Think about your healthcare record with all the forms, images (x-rays, MRIs, etc.), notes, and other data. If you’re like most people, your healthcare record is about 80MB. If Rubrik’s 42 EB of protected data consisted of nothing but healthcare records, it would be the equivalent of five healthcare records for every one of the 117 billion people who lived on earth for all of humanity’s history. It’s like… a lot.
Wakefield Research
We partnered with Wakefield Research to conduct a study that gathered additional insights from both IT and security leaders. This data supplements our Rubrik telemetry to give us insight into both the leaders’ point of view and what they see on the ground. No Rubrik clients are included in this dataset to be as objective as possible.
1,600+
IT and Security Leaders
50%+
CIO or CISOs
50%
1,625
Decision-Makers at companies with at least 500 employees across 10 countries (Australia, France, Germany, India, Italy, Japan, Netherlands, Singapore, United Kingdom and the United States); in three regions (Americas, APAC and EMEA)
50%
Rubrik Partners
We leveraged datasets and received guidance from two Rubrik partners in ongoing efforts to improve data resiliency.

Microsoft provided data from the 2023 Microsoft Digital Defense Report, specifically data exfiltration rates and resiliency recommendations
Aon provided data from the 2023 Aon Cyber Resilience Report, specifically data backup realities and post-intrusion outcomes.
Contributing Organizations
Rubrik included key data from various organizations with unique visibility compared to Rubrik telemetry in an effort to provide as objective a view as possible.

Mandiant provided dwell times observed in its incident response/MDR events across 2023.

Palo Alto Networks Unit 42 provided findings on ransomware demands and payments from their incident response/MDR events across 2023.
Proofpoint provided information on cloud targeting based on their 2023 Human Factors Threat Report.

Recorded Future provided publicly reported ransomware trends across 2023.

The University of Minnesota Twin Cities - School of Public Health provided ransomware impacts on public health institutions based on their research "Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients," which is published and currently undergoing final peer review.
The University of Minnesota Twin Cities - School of Public Health provided ransomware impacts on public health institutions based on their research.“Hacked to Pieces? The Effects of Ransomware Attacks on Hospitals and Patients [6],” which is published and currently undergoing final peer review.
Let's Talk About Risk
First, we’re going to make the “risk math” easy:
Second, we’re going to focus on data.
As a data security company, our strongest insights involve an organization’s data— as opposed to its infrastructure or architecture—so we focus on risks in and to your data.
Specific Focus Areas
Let’s be honest. You’re busy. None of us have time for a full deep-dive on every aspect of data security. We intentionally narrowed this study to a few key topics:
The existence of commercially available clouds can now be measured in decades. Yet, confusion about cloud data security remains. The cloud is targeted with more frequency—and more success—than its on-premises counterparts. It also contains blind spots making it difficult to defend.
Not too long ago, experts predicted ransomware’s decline. It didn’t really happen, and ransomware continues to wreak havoc on organizations of all kinds.
With few exceptions, healthcare organizations produce and store more sensitive data and are subject to more regulatory scrutiny than other industries. A fringe benefit of the regulatory pressures on healthcare is more publicly available data to study.
Third, who is this study for? Intelligence should inform the right decision-maker, and risk decisions typically happen at the senior-leader level. Our goal is to inform and aid these senior-leader discussions across business, cybersecurity, and IT functions. By giving these decision-makers a common place to start from, they’ll be better prepared to tackle risk together.
Now let’s talk a little about how people perceive risk. Humans don’t deal with uncertainty well. When faced with the possibility of something happening, we like to think either:
“Yes, this most definitely will happen,” or “No, this definitely won’t happen.” In reality, things are a bit more squishy.
Humans
don’t
deal
with
uncertainty
well.
If a meteorologist tells you there’s a 52% chance of rain in your area, they’re not telling you definitely, “Yes, it will rain,” or “No, it won’t.” What they can say is the risk of rain is about the same as a coin flip. Then there’s the details we really want: How much rain? Is it a sprinkling or a deluge? Do I just stay home? Because I didn’t want to go to the office anyway.
These decisions are yours and yours alone. It would be nice if you only had to make these decisions once, but it just doesn’t work that way.
Today’s reaction to rain impacts how we think about tomorrow’s weather report and also provides lessons learned in dealing with the rain.
These factors combine to set new conditions the next time we have to tackle the storm. That’s true of the rain and it’s true of cyber risk. Let’s start with the external threats you should consider.
Is Data at Risk From Attackers?
Is Data at Risk From Attackers?
Let’s start with a basic question: Are attackers likely to target my data?
How much of your newsfeed is real versus FUD?
Fear, Uncertainty, Doubt
Nobody can tell you with 100% certainty if you’ll be hit with a cyberattack, but we can tell you what happened to your peers last year.
Almost
ALL
your
peers
dealt
with
cyberattacks
about
every
other
week.
Here’s what that looked like across IT and security leaders:
0%
of IT and security leaders reported their organization experienced a significant cyberattack last year.
0%
The average frequency was 30 malicious events brought to senior leaders’ attention across 2023.
0%
of external organizations conducted a formal data loss notification to a governing organization.
Cyberattacks are far more likely than physical theft or fire. To put the likelihood of cyberattacks into perspective, a European insurance company [7] compared cyberattacks to traditional threats in the same timeframe and found:
0%
Organizations are 67% more likely to experience a cyberattack than physical theft.
0x
Organizations are five times more likely to experience a cyberattack than a fire.
0%
of organizations do not know what actions to take in the event of a cyberattack.
Attackers are comfortable targeting hybrid environments. So if you’re likely to be targeted, it’s useful to understand where and what is likely to happen. Of the 94% of external organizations victimized in a cyberattack, many were attacked across multiply environment types:
0%
SaaS
0%
Cloud
0%
On-Premises
Wakefield
And here’s some perspective on the two most common types of attacks in these environments:
0%
of these organizations had at least one data breach from a cyberattack.
0%
of these victims endured at least one ransomware attack
Almost ALL cloud tenants were targeted, and 2 out of 3 were compromised in 2023. We didn’t just find this in our research, Proofpoint reports [4]:
Cloud Tenants Targeted Every Month in 2023
Proofpoint
Attackers have access to your data for days before being found. Mandiant measures dwell time [3] as the number of days an attacker is present in a victim’s environment before detection. The global median dwell time across all events was 10 days last year. The global median dwell time for a ransomware event is 5 days.
The good news
These are the shortest dwell times ever observed by Mandiant.
The bad news
This still represents a significant length of time for malicious actors to accomplish their goals.
You’re
not
imagining
it.
There’s
more
ransomware.
Recorded Future [5] tracked a significant increase in publicly reported ransomware attacks last year:
- 4,399 reported attacks across all industries (70% increase YoY)
- 358 reported ransomware attacks against healthcare (46% increase YoY)
Now, let’s shift our focus and look at your data.
Is There Risk in Your Data?
Is There Risk in Your Data?
If you know the odds of an attack (and let’s face it, they aren’t great), it makes sense to do everything you can to minimize your risk by reducing the likelihood of an attack succeeding the fallout from an attack. At the end of the day, what we’re trying to do is deceptively simple (on paper):
We’re
trying
to
protect
data
from
threats.
We must examine both sides of that equation. Let’s take a look at what our operations expect our defenders to secure.
Data is growing rapidly and expanding the defensive boundaries. Healthcare defenders are responsible for securing a larger data surface area, with more sensitive data, and that is growing faster than the global average.
Healthcare organizations secure 22% more data than the global average.
EB vs BEPB
A reminder from the data nerds: When most of the world hears “data,” they think of logical storage, also known as frontend storage. Those of us in the data business focus on backend storage. Rubrik takes the entirety of an organization’s data and performs a number of different techniques—including deduplication and compression—to reduce the amount of frontend data to backend storage. We’ll use backend storage throughout this report.
The typical healthcare organization saw their data estate grow by 27% last year (23% for a global organization). A typical healthcare organization has 50% more sensitive data than the global average. Sensitive data records in healthcare grew by more than 63% in 2023— far surpassing any other industry by more than five times the global average (13%).
Organizations had a record-setting number of issues to tackle last year. Vulnerabilities are not a perfect exposure measure, but they do provide
a solid view on the scope and scale of inherited risk from vendors.
2022 was a record setting vulnerability year with the highest reported amount ever. Then, 2023 set a new record, a 16% increase over the previous record.
Vulnerabilities Discovered
CVE Details
Organizations are becoming more dependent on cloud and SaaS. Demands on a modern business necessitate an increased focus on the cloud. We see the nature of hybrid environment consistently moving towards cloud and SaaS while deprioritizing on-premises architecture growth.
7770
913
1417
The Cloud Contains Blind Spots
Cloud Data Security
70% of all data in a typical cloud instance is object storage.
Object storage represents a common blind spot for most security appliances because it’s typically not machine readable by these same technologies.
Most backup solutions are not up to the task. Backup and recovery technologies are critical components for virtually all organizations. They’ve been used for disaster recovery and business compliance for decades. However most organizations struggle getting these solutions to actually work.
0%
Rubrik Zero Labs previously stated [8] more than 99% of external organizations reported having an existing backup solution.
0%+
However more than 93% of these organizations encountered significant issues with their existing solution.
0%
Aon reported [2] 70% of organizations do not store backups offsite or their backups are not immutable.
0%
Almost 40% of Rubrik-observed organizations have not set compliance policies for their data backups.
Bad News
Cybercriminals are hip to the backup game and routinely target backups. Attackers almost universally attempted to remove backup and recovery options from defenders. External organizations that reported a successful attack observed attackers tried to affect the backups in 96% of these attacks, and were at least partially successful in 74% of those attempts.
Cybercriminals are taking out insurance policies against effective restores. Attackers are evolving their approach to ransomware based on defender actions. Instead of simply encrypting data, cybercriminals also steal data and threaten to publish it. If their target can thwart the encryption event with a swift recovery, ransomware actors have another way to drive a payout.
0x
Microsoft determined the number of times threat actors potentially exfiltrated data after an initial compromise has doubled since November 2022.
0%
Aon assessed data breaches have a 12% higher overall impact on organizations than ransomware alone.
0%
93% of external organizations that endured a successful ransomware attack reported paying a ransom demand with 58% of these payments motivated by threats to leak stolen data.
Now
that
we
know
the
likelihood,
lets
take
a
look
at
the
impact.
How Bad Will it Be?
How Bad Will it Be?
Folks often think the cyberattack is the end of the story, but it's really the middle.
Going back to our weather forecast example, the story of your day doesn't end when it rains. You still have to live your life. But now you need to adjust to the conditions. How are you going to stay dry? Does the dog get walked in the rain? What happens when you inevitably get rained on?
Likewise, a cyberattack sets off a whole slew of remediation, recovery, and reporting efforts. How painful these efforts are depends on how well you prepared for these outcomes in the first place. Let's look at the fallout from cyberattacks, specifically ransomware, against healthcare organizations last year.
This is what happens after the cyberattack. Approximately 1 in 3 Americans had their personal records compromised during healthcare intrusions last year [9]. An average of 244,000 people were affected during a single cyberattack against healthcare last year. Over 133 million people had their records compromised from cyberattacks against U.S. healthcare organizations last year, a 186% increase from 2022.
Records Compromised from Cyberattacks (2023)
U.S. Department of Health and Human Services, Office for Civil Rights
Ransomware
attacks
on
healthcare
organizations
impact
almost
five
times
more
sensitive
data
than
the
global
average.
Rubrik measures both the ransomware encryption blast radius and the sensitive data impacted by this blast radius. Impacted files include encrypted files, deleted files, and exfiltrated files.
Here's the impacted data for a typical healthcare ransomware encryption event in a production environment.
The average global organization at large typically experiences a much smaller impact to its sensitive data. Virtualization really matters for healthcare and ransomware.
16.8M
Total impacted files per encryption event in healthcare organizations
8.4M
Sensitive data records within these impacted files
20%
Affected data holdings with each successful ransomware encryption event
Now let's examine where ransomware encryption happens.
0%
0%
This is likely driven by two factors:
Security Dead Spots
Virtualized architectures typically have less security coverage compared to traditional endpoints. This creates security dead spots and simultaneously allows attackers unfettered access.
Moving with Speed
Once attackers gain access to virtualization control panels, they can often move at speed and scale using only
compromised credentials.
Ransom payments vary wildly.
Initial ransom demands are often higher than the actual payouts. Palo Alto Networks Unit 42 noted the following trends in ransom payments across last year:
Backups and data theft greatly affect a victim's likelihood to pay a ransom. The University of Twente [10] studied factors that caused victims to pay a ransom and separately what impacted the size of an actual ransom payment.
Their
findings
indicated
organizations
with
recoverable
backups
were
27.5x
less
likely
to
pay
a
ransom.
Paid the ransom with data exfiltration
Paid the ransom without data exfiltration
Storage overload: The recovery blindside nobody sees coming
When it rains, it pours. Few organizations are prepared for the data deluge caused by ransomware.
If a single healthcare ransomware event encrypts or modifies 16.8 million files, it essentially means the encryption event created 16.8 million "new" files for the victim (compared to 13.7 million new files for a typical global organization).
These files are backed up as new files, which consumes vast amounts of storage capacity at the moment of the encryption event.
If a victim's pre-ransomware storage is over 70% capacity, this "new" data could max out an organization's recovery capacity within one to two weeks.
Data exfiltration led to a higher likelihood of paying a ransom and higher ransom payment amounts. Data exfiltration led to a higher likelihood of paying a ransom and higher ransom payment amounts. When data exfiltration was involved, ransom payments were 5.5x larger than encryption-only events.
In the 200+ recovery operations in the Rubrik Ransomware Response Team's history, this issue typically leads to one of two outcomes. The organization either needs to:
Data Capacity
Rapidly increase data capacity, which requires financial investments and workforce pressures.
Recovery
Degrade recovery capabilities to slow data growth, which in turn limits recovery options in critical timeframes.
Ransomware fallout directly contributed to at least 42 U.S. deaths.
In any ransomware event, there's the data impact. The real risks—particularly for healthcare—are also measured in operational impacts and lives.
The University of Minnesota Twin Cities - School of Public Health studied real-world impacts to hospitals and patient care caused by ransomware events between 2016 and 2021 [6]. They found patient care throughput dropped by 20% across the first week of a ransomware attack.
1 in 4
While only 5% of US hospitals were directly affected by ransomware during the study’s timeframe, an additional 20% of hospitals suffered ripple effects when patients were transferred or diverted from the victim hospitals to surrounding hospitals.
0.5–1.0%
A typical hospital lost between 0.5 and 1% of their total annual revenue as a direct result of a single ransomware attack.
2–3 Weeks
Hospitals averaged two to three weeks for a return to typical patient care levels following a ransomware attack.
42–67 Deaths
The fallout from ransomware attacks directly contributed to the deaths of between 42 and 67 patients [11].
Patient care dropped by 20% across the first week of a ransomware event.
These
attacks
aren't
just
affecting
data,
business,
or
individual
privacy
anymore.
There's
direct
evidence
cyberattacks
are
a
life
and
death
issue.
Recovery to Reset
Recovery to Reset
After the initial response is done and organizations return to relatively normal operations, the fallout from a ransomware attack continues producing risk impacts. There's bad news and good news here for us.
Cyberattacks impact our organizations and people.
Executives will need to be convinced their organizations can recover from the next attack.
60%
of IT and security leaders are extremely or very concerned about their organization’s ability to maintain business continuity during a cyberattack.
28%
of external organizations believe their Board of Directors or C-suite has little to no confidence in the organization’s ability to recover critical data and applications in a cyberattack.
Cyberattacks produce predictable problems to solve. Here are the most frequently identified problems during a cyberattack and the most common changes organizations should prepare to encounter after a cyberattack:
01
19% – Issues working across a hybrid environment
02
18% – Lack of alignment across teams
03
18% – Ineffective backup and recovery solutions
04
17% – Lack of leadership involvement
05
16% – Visibility challenges
Cyberattacks can drive positive outcomes. Organizations prepared to capitalize on these crisis moments can reshape their future. Aon reported companies that successfully navigated a cyberattack saw an 18% shareholder value increase compared to their peers. After a cyberattack, external organizations reported:
55%
Increased spending on new technologies or services
42%
Switched vendors or third party relationships
37%
Hired additional staff
You cannot eliminate risk, but you can influence the risk cycle and affect your new risk baseline.
Resetting Data Risk
Resetting Data Risk
We'd love to tell everyone those final outcomes end the story, but in truth it's the beginning of another chapter.
Just because you weathered one storm doesn't mean it'll be the last one you face. In fact, you'll almost certainly encounter another one and that storm will bring new, perhaps unforeseen risks, with the potential to catch you off-guard.
We'd also love to tell you there are options to change the risk factors controlled by the attackers, but unfortunately our analysis tells us that pursuit is almost as futile as trying to control the weather.
Like most things in life, you cannot control what happens to you, but the good news is you can control the risk reset and subsequent impacts.
Let's dig into the data on how to successfully navigate the risk reset. Each of the risk recommendations is derived from findings about the cyberattacks, the data impacts, or the expected outcomes.
What actually impacts your new data risk?
Here are the most impactful levers you can pull to significantly improve your data risk:
1. Prepare to challenge attackers across all aspects of a hybrid environment
Attackers are already working successfully in hybrid environments, and our organizations are moving that way.
2. Increase your data visibility, specifically:
- Expand your view across all aspects of hybrid environments.
- Know where your sensitive data is located and what type of regulatory aspects apply to specific data elements.
3. Prepare to address new leader scrutiny
Anticipate increased leadership scrutiny and proactively communicate your efforts following a cyberattack to demonstrate how recent investments will lead to anticipated outcomes.
4. Prepare to recover, and prepare for attackers to contest your recovery
- Ensure backups are fully immutable and available during a cyberattack.
- Automate as much of the recovery process as possible.
- Test recovery outcomes across hybrid environments.
- Leverage existing security services and technologies to test the immutability and integration of backup technologies.
5. Find ways to unify different teams
Before, during, and after a cyberattack, this includes:
- Create combined playbooks and perform tabletop exercises.
- Determine which team is best suited for specific risk decisions.
- Establish the best way to get the right data to the assigned risk owner.
- Ensure all teams have the same data viewpoint to enable faster decisions and decrease potential resistance from competing viewpoints.
Know your data (especially your sensitive data) is growing. Learn to control that growth and prioritize the defense of critical data.
Prepare to answer regulatory and legal questions in the middle of a ransomware event with an actively encrypted environment and attackers threatening to leak stolen data.
Know that cyberattacks often lead to new technology, increased staff, and switching vendors or partners. Be prepared to capitalize on these change periods to make the most impact.
Communicate plans and outcomes regularly across your entire organization to address dropping morale from cyberattacks and re-instill confidence across teams.
Another Perspective
Admittedly, Rubrik Zero Labs approaches risk from a data-driven perspective. Let's expand our view to include key resiliency recommendations from Microsoft's 2023 Digital Defense Report [1]. Microsoft's vantage point is decidedly different from Rubrik's, which in turn, we hope, strengthens risk reduction efforts.
Microsoft
assesses
basic
security
hygiene
for
data
will
protect
against
99%
of
all
attacks.
Specific recommendations are:
- Enable multi-factor authentication
- Apply zero trust principles especially for assets securing critical data and functions
- Use extended detection and antimalware to cover critical parts of hybrid environments
- Keep up to date on patching key systems and applications
- Protect your data by understanding what data is critical, where is it located, and implementing appropriate defensive measures for these enclaves
01
Modern authentications with phish-resistant credentials
02
Least privileged access applied to the entire technology stack
03
Threat and risk-free environments
04
Posture management for compliance and the health of devices, services, and assets
05
Automatic cloud backup and file-syncing for user and business critical data.
We started this report by simplifying our risk math: We need to defend THIS from THAT. In practice, risk is an incredibly complex topic where one massively complicated surface area (your data) collides with another equally nuanced and constantly changing threat surface area.
Because of the literal millions of variables involved, you'll never be able to fully pin down your risk—or completely eliminate it. What you can do is get a handle on the most impactful levers, work to address predictable outcomes, and take distinct actions to change the risk calculus in your favor.
We hope this study provided some insight on data risk reduction and prepares you for the evolving risk cycle.
Acknowledgements
Rubrik would like to extend our appreciation to the organizations providing their hard-earned data
knowledge to this study.
Our partners at Microsoft and Aon provided both strategic direction and supporting data.
The following organizations allowed us to use their analysis and provided clarifying material to ensure appropriate categorizations:
- Proofpoint > Palo Alto
- Recorded Future (Allan “Ransomware Sommelier” Liska)
- Mandiant (Kirstie “Swiftie” Failey)
- Palo Alto Networks Unit 42 (Ingrid Parker)
The University of Minnesota Twin Cities School of Public Health (Hannah Neprash, Claire McGlave, and Sayeh Nikpay) allowed us to leverage their findings, provided a deepdive into their research, and worked with Rubrik Zero Labs to ensure their academic research aligned with Rubrik Zero Labs industry research.
As with all things Rubrik Zero Labs, it takes a village to pull off these studies. Wakefield Research provided external data to make this research as objective as possible. Shaped By found a way to take the data and bring it to life. Finally, many Rubrikans worked hard to provide capability, context, and guidance. We’d like to extend a specific appreciation to Amanda “Danger” O’Callaghan, Linda “Taskmaster” Nguyen, Lynda “Go Niners” Hall, Ben Long, Peter “I’m the Law” Chang, Ajay Kumar Gaddam, Ryan Goss, Derek Morefield, Josh Burns, Gunakar Goswami, Prasath Mani, Ethan Hagan, Kevin Nguyen, Caleb “Social King” Tolin, Kelly Cooper, Hannah Battillo, Sindhu Nagendra, Caitlin “Plz stop letting Steve talk to reporters” O’Malley, and Fareed Fityan.