Site navigation

Should You Ever Pay a Cyber-ransom?

Graham Turner

,

Ransomware attack guidance
The Counter Ransomware Initiative (CRI) and key insurance bodies have released non-binding guidelines for organisations dealing with ransomware attacks.

The Counter Ransomware Initiative (CRI), in collaboration with key insurance bodies, has released updated guidance for organisations dealing with ransomware attacks.

As ransomware incidents become more complex and widespread, this guidance is designed to support victim organisations and their partners through the critical decision-making process while emphasising the need for a unified international approach to this global threat.

The Problem With Paying Ransoms

The guidance strongly advises against paying ransoms. The CRI points out that 2023 saw the highest recorded global ransomware payments, with criminal groups continuing to profit from their activities. Paying a ransom not only fuels this illegal business model but often fails to resolve the issue. Paying does not guarantee that attackers will return access to systems or delete compromised data.

Moreover, criminals frequently use the funds to expand their operations, potentially causing further harm to others.

At the CRI Summit, member countries collectively discouraged ransom payments, acknowledging that such payments:

  • Do not guarantee the end of an attack or the removal of malware.
  • Encourage further criminal activity.
  • Support other forms of illicit activity.
  • Do not guarantee the safe return of stolen data.

Guidance for Handling Ransomware Incidents

The newly issued guidance is non-binding and does not supersede existing national laws but aims to provide a structured approach for organisations navigating ransomware crises. Some of the key steps organisations are encouraged to follow include:

  1. Preparation: Before an attack occurs, businesses should establish continuity plans, policies, and procedures, ensuring they’re prepared for possible incidents.
  2. Legal and Regulatory Considerations: Organisations need to understand that paying ransoms may be illegal in some jurisdictions, particularly if payments are made to sanctioned entities. Legal counsel and advice from cyber insurance providers can be invaluable here.
  3. Reporting the Incident: Victims are encouraged to report attacks to authorities as soon as possible. Timely reporting supports law enforcement in disrupting ransomware networks and can help prevent future incidents.
  4. Evaluating Options: Ransomware criminals aim to pressure their victims into quick decisions. CRI advises businesses to slow down, assess all available options, and consult experts before making critical decisions. This allows for better-informed responses that minimise harm.
  5. External Support: Organisations are urged to seek guidance from cyber insurers, law enforcement, and cybersecurity professionals. Many insurance policies provide access to incident response teams, whose expertise can be pivotal in navigating the aftermath of an attack.
  6. Alternatives to Paying: CRI stresses that paying a ransom should be the last resort, noting that payment does not always guarantee system restoration or the deletion of stolen data. Even after a ransom is paid, victims remain vulnerable to further exploitation.

Cyber Insurance’s Role

Cyber insurance has emerged as a vital tool in managing ransomware risk. CRI acknowledges that insurance providers play an important role in both helping organisations prepare for potential attacks and assisting them during recovery. Insurers can direct victims to legal and technical experts, assist with recovery efforts, and support ongoing resilience-building measures.


Recommended reading


Key Considerations Before Payment

The guidance advises organisations to carefully consider:

  • The technical state of their systems, including the availability of backups and decryption tools.
  • The potential business impact, such as operational disruption, legal penalties, or damage to customer relationships.
  • The likelihood of data exfiltration, as many ransomware attacks now involve data theft. Victims should remain cautious, as paying a ransom does not guarantee that stolen data will not be released.

Documenting and Evaluating Responses

It is critical for organisations to maintain detailed records of their response to ransomware incidents, including the decision-making process and any actions taken. This documentation can support post-incident reviews, legal compliance, and future resilience efforts.

Finally, the guidance calls on businesses to involve key stakeholders across the organisation, from technical staff to senior decision-makers, in deciding whether to pay. It also highlights the importance of post-incident evaluations to investigate the root causes of attacks, address vulnerabilities, and prevent future breaches.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data