Every few months a headline declares the average ransomware payment, and every few months that number tells you less than it seems. Averages blend together organizations of wildly different sizes, sectors, and leverage. They include victims who paid within hours and victims who negotiated for weeks. They say nothing about the quality of backups, the presence of stolen data, or whether the attackers could actually decrypt anything. For defenders, the interesting questions live underneath the statistic.
Incident response teams learn quickly that ransomware groups are not monolithic. Some operate with a kind of grim professionalism: responsive chat, consistent pricing, and a reputation to protect because repeat business depends on it. Others are chaotic, overpromise, or disappear mid-negotiation. Understanding which type you are dealing with shapes strategy. A group that values its brand may honor a decryption key; a group that does not may take payment and leak data anyway.
The hardest calls in a ransomware incident are rarely technical. They are about disclosure, downtime, and whether to engage. Legal counsel, cyber insurance carriers, and communications teams all have seats at the table, and their priorities do not always align. A manufacturing plant may face safety issues if systems stay offline. A hospital faces patient care. A software company faces customer trust. The same event produces different calculus depending on what the organization does.
Preparation is what makes those calls possible under pressure. Tabletop exercises that include executives, not just security staff, surface the disagreements early, when there is time to resolve them. Who has authority to approve a payment? What is our stance on disclosure? How long can we operate degraded? Writing answers down does not guarantee good decisions, but it prevents the worst ones from being made by default at 3 a.m.
Backups remain the most reliable leverage. Not just having them, but testing restores, isolating copies from the production network, and knowing how long a full recovery takes. An organization that can rebuild in two days negotiates from a different position than one that needs three weeks. Attackers know this and price accordingly.
The focus on whether to pay obscures a larger truth: the incident began long before encryption. Initial access often comes through stolen credentials, exposed remote services, or a phishing click weeks earlier. Detection and response capabilities determine whether that dwell time is measured in hours or months. Investing in identity hygiene, network segmentation, and alerting on unusual lateral movement reduces the odds of ever facing the negotiation table.
After the event, the pressure to move on is immense. But the post-incident review is where the real value sits. What failed? What worked? Which assumptions turned out to be wrong? Documenting these honestly, without hunting for a single person to blame, turns a painful episode into durable improvement.
Ransomware coverage tends to chase the spectacle. Practitioners know the substance is quieter: backups that restore, identities that resist theft, and leaders who have already thought through the hard choices before they are forced to make them.
This incident opened my eyes to the value of Insurance in general, so I decided to examine my personal and business insurance.
Comment (3)
The payments are made directly from one person to another without passing through a central bank or clearing house.
22 feb,2025
ReplyReading the Room: How to Brief Executives on Cyber Risk
23 feb,2025
ReplyThe Slow Bleed of Credential Stuffing Attacks
23 feb,2025
Reply