49% of orgs found out they had a ransomware actor when the ransomware actor deployed the ransomware. Only 30% detected it internally - ie read their alerts and contained it.
The other 21% found out because somebody externally told them somebody was active on their network (eg law enforcement, CISA, NCSC etc).
Key lesson - read the alerts. If you can’t afford to read the alerts, don’t buy the products, get an MSSP.