Evaluating the Impact of Ransomware Prevention and Recovery Capabilities on Business Continuity: An Empirical Study
DOI:
https://doi.org/10.70917/ijcisim-2026-4812Keywords:
Ransomware, Business Continuity, Cybersecurity Governance, Cyber Resilience, Incident ResponseAbstract
Ransomware has become one of the greatest cyber threats and can severely impact organisations around the world, not only operationally and financially, but also reputational. This study is an empirical investigation of the impact of ransomware prevention capability, ransomware incident response readiness, backup and recovery capability, cybersecurity awareness and cybersecurity governance on business continuity, and how cyber resilience in the organization serves as a mediator in this impact. A cross sectional research design of quantitative approach was used and data were collected from 400 cybersecurity and information technology professionals using a structured questionnaire. Descriptive statistics, reliability analysis, exploratory factor analysis, Pearson correlation analysis, multiple regression and structural equation modeling were used to analyze the data. All the factors proposed were found to be significant and positive and they were positively correlated with business continuity with the highest correlation being cybersecurity governance. Correlation between organizational Cyber Resilience and business operation continuity was seen to be higher with Cybersecurity capabilities. The findings of the study lead to the Ransomware Resilience and Business Continuity Framework (RRBCF) that combines the following components: governance, preventive security controls, detection and monitoring, incident response and recovery, and continuous improvement. The framework provides concrete advice that organisations can use to enhance their cyber resilience and continue to operate in the face of the constantly evolving ransomware threat.