Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Why Paying The Ransom Isn’t The Answer For Ransomware Victims
Articles

Why Paying The Ransom Isn’t The Answer For Ransomware Victims

Anastasios ArampatzisBy Anastasios ArampatzisApril 7, 2022Updated:July 4, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
ransomware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Increased reliance on multiple cloud environments during the last couple of years and the growing number of employees opting for a hybrid working norm have created numerous opportunities for ransomware gangs to target organizations. As a response to the increasing impact of ransomware attacks, businesses of all sizes are investing in a zero-trust approach to security where digital identities and multi-factor authentication (MFA) play a key role.

The state of the ransomware threat

Ransomware attacks have become more advanced and complex during the past years, evolving from simple malware deployment and extortion to a multi-tiered Ransomware-as-a-Service (RaaS) business model where “service providers” like Initial Access Brokers develop and then sell or rent their services. So-called “double extortion” attacks also heighten the risk, where cybercriminals exfiltrate the data before encryption and ransom demand. All these developments contribute to a more dire threat to organizations.

Research from CyberRisk Alliance indicates that 43% of the surveyed businesses suffered at least one ransomware attack during the past two years (2020 – 2021). 32% believe they cannot prevent ransomware attacks because threat actors are too well-funded and sophisticated.

According to the 2022 Thales Data Threat Report attacks significantly impacted 43% of the ransomware victims. The impact ranges from hard costs, such as financial losses from penalties, fines, and legal expenses, to softer costs, including lost productivity, recovery costs, and brand reputation.

To pay or not to pay? This is the question

Ransomware attacks are sometimes even worse than the worst-case scenario for which an organization has planned. The data stolen by the ransomware group might be so sensitive or damaging that allowing it to be released would destroy the organization. With all other options exhausted, an organization realizes they may have to pay the ransomware group.

In fact, the percentage of ransomware victims choosing to pay the ransom is higher than you think. The CyberRisk Alliance report findings indicate that 58% of the victims paid a ransom, while 29% found their stolen data on the dark web.

However, paying the ransom might not be the solution to your nightmare. Even if a company pays, there is no guarantee that attackers will return the data or that the decryption key gets data back where it was before the attack. According to a 2021 Sophos report, 92% of these organizations don’t get all their data back, and 29% of them don’t even recover half the encrypted data.

An inconsistent return of the data is not the only reason businesses should avert from paying the ransom. Federal agencies like CISA and other security professionals stress that paying the ransom does more harm than good. While paying may appear to be a viable option and a quick solution to your problem, there are many reasons why you shouldn’t:

  • Ransomware gangs are encouraged as the ransoms are funding them
  • Double extortion tactics only escalate the ransom in demand
  • Businesses paying the ransom might face future legal issues for funding terrorism

Prevention is better than reaction

Before even discussing the possibility of paying the ransom, businesses should start planning how to reduce the likelihood of being the next victim of a ransomware attack. 

Ransomware business model

The first step is to understand how ransomware gangs operate. These criminals often go after Big Game Hunting. The higher the expectation for service reliability, quality, and trust, the more likely the business will be targeted. For these companies, the impact of disruption on business operations is much more significant than the payout. When an energy or utility grid is compromised, this can lead to blackouts and gridlocks, and when safety mechanisms are breached, the release of toxic chemicals, oil spills, fires, or explosions.

The problem is exacerbated by the fact that the skills required to execute a ransomware attack have been dramatically reduced. Ransomware-as-a-service models are offering a complete package for potential attackers. Ransomware software packages exist along with millions of stolen access credentials on the dark web that allow people with relatively little technical background to execute ransomware attacks effectively.

Build your defenses – a zero-trust approach

Identity-based access and multi-factor authentication can help reduce the incidence of such attacks. Businesses should be proactive and build capabilities to identify the source of repeated, excessive login attempts and block such attempts. Having this capacity is crucial for detecting and reducing the impact of ransomware attacks.

In line with the recent Executive Order, an Americas Market Owner for IAM said,”Adding identify verification gates (#MFA) in front of every app cannot just reduce the chance of getting hit with #ransomware but also limit that damage done”.

One of the most effective ways to prevent ransomware attacks is by adopting zero trust architecture. Built on the principle ‘never trust, always verify,’ a zero trust security strategy would have prevented ransomware attacks like the Colonial Pipeline and JBS, preventing it from spreading across the operations while keeping the operation running.

Zero trust isn’t a silver bullet for ransomware either, but it can help create a much more robust security defense against ransomware attacks if implemented well. One of the key pillars of zero trust focuses on user identity and access management.  Others include monitoring, detection, and threat inspection capabilities necessary to prevent ransomware attacks and exfiltration of sensitive data. Zero trust frameworks help reduce the attack surface significantly as employees and third parties only have access to the resources they need at a given time.

Zero trust is a strategy that facilitates digital transformation. It needs a commitment from the entire organization and requires a change in mindset, executed with due diligence. However, the bonus is that businesses that implement zero-trust security successfully will be much stronger to combat evolving threats like ransomware and emerge as a genuinely cyber-resilient organizations.

Anastasios Arampatzis
Anastasios Arampatzis

Anastasios Arampatzis is a cybersecurity content strategist, writer, and consultant with expertise in cybersecurity, digital identity, and regulatory compliance. Tassos has a strong background in creating thought leadership content, marketing materials, and strategic communications tailored to CISOs, security professionals, and business leaders. He has contributed to various cybersecurity publications and collaborates with organizations to develop compelling, insightful content that addresses industry challenges. He is a privacy advocate and a member of the ISC2 Hellenic Chapter. Before joining Bora, Tassos was an Hellenic Air Force Officer with a solid background on IT and Infosec.

  • Anastasios Arampatzis
    The quiet revolt: what the world happiness report 2026 tells security professionals
  • Anastasios Arampatzis
    Cybersecurity and the Power of Words: Why Security Must Be in Our DNA
  • Anastasios Arampatzis
    Have You Read the F***ing Policy?
  • Anastasios Arampatzis
    When Innovation Meets Education: Caution Before Celebrating ‘OpenAI for Greece’

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}