Impacts were small.
Just a few years ago, one of the most high profile financially-motivated ransomware attacks, WannaCry, hit the NHS and various other government agencies and companies around the world and demanded the unbelievable sum of $300 per computer [1], an amount that most of those organizations could only find by looking through their pocket lint for amounts so small. They spent 100x-1000x more money solving the residual problems than they did or would have needed to pay dealing with the ransom itself.
Just a few years ago, the worst case impacts were so small that the problem was not even worth caring about. What they did not realize is that the amounts were small because the ransomware groups likely consisted of young people with more technical ability than business sense. They did not realize how deep the money well went and how much they could really ask for, the criminal equivalent of a bunch of college students making a B2B startup and being worried that their $1k price tag might be too expensive since they would personally think that is a lot to spend. This is borne out by the fact that the targets even a few years earlier were mostly personal computers of random people who might actually have a problem paying $300 to get their family photos back. However, these ransomware groups have been rapidly wising up and now realize they were doing the effective equivalent of robbing the bank for their pens. They are starting to ask for reasonable amounts of money that businesses might actually worry about and with that money they are expanding their operations as fast as they can to try to exploit the entire market. They just have not gotten there quite yet since they do not have access to vast gobs of VC cash and need to instead bootstrap themselves up to a multi-billion dollar criminal enterprise.
The unfortunate problem for all of their targets is that none of their things work and they did not think the problem was serious since the impact of failure was so small. They did not realize that was not because more could not be done, but because the people doing it did not know what they were doing and that they were actually at the start of a serious exponential ramp.
If you want more technical reasons, it is because every commercially available solution is completely inadequate for an environment where people with modest amounts of money want to attack your system. Nobody selling commercial IT systems has the first clue how to make systems that are actually robust against credible threat actors. The absolute best of the best can maybe protect a system against attacks funded at the ~$10M level, but when you are talking about companies with literally $100B revenue streams, that is a rounding error of a rounding error. Exactly 0 executives at such a company would think that being defenseless against attackers with $10M is acceptable if told directly and I think most of their shareholders and customers would be horrified if they had to put that in their commercials in big bold letters, but that is the best that they can get.
[1] https://en.wikipedia.org/wiki/WannaCry_ransomware_attack