For any CSO or CISO, it’s the stuff of nightmares – the moment years of defence and planning collapse, the network paralysed, vital data encrypted and out of reach. Your files are gone. In their place, a demand:
“To the board of directors. Your network has been attacked through various vulnerabilities found in your system. We have gained full access to the entire network infrastructure.
All your confidential information about all employees and all partners and developments has been downloaded to our servers and is located with us.
Don’t try to terminate unknown processes, don’t shutdown the servers, do not unplug drives.
All your data will be successfully decrypted immediately after your payment.”
That’s a real ransomware note, one of hundreds collected by security firm Group-IB, covering years’ worth of cyber-attacks committed by some of the most prolific threat actors operating around the world.
They’re intriguing to scroll through, and offer some insight into the psychology of hackers, but it’s hard to forget that each one represents probably the lowest point in a business’s existence, a moment when it might lose everything to nameless, faceless tormentors hiding in the binary shadows.
The sheer number of ransom notes available for a casual observer to peruse is also proof of just how prolific these cyber-attacks have become, but recent studies provide ample evidence that this hoard of ransom notes is simply the tip of the iceberg.
To take just a few examples, data from Check Point released in April showed a surge of ransomware attacks in the first months of this year, with a 126% rise in incidents, while a Bitdefender Threat Debrief found February 2025 to be the worst month in ransomware history, an achievement quickly outdone weeks later, with March setting a new record of over 100 publicly disclosed attacks.
Add to that figures which show nearly a fifth of global organisations experienced more than twenty-five cyber-attacks last year alone (an average of at least one breach every other week), while UK Government figures place the number of British businesses experiencing a ransomware attack up from less than 0.5% in 2024 to 1% in 2025, equating to around 19,000 businesses in the last year.
Put it all together, and the message is clear – if your company hasn’t been hit by ransomware yet, it’s probably just a matter of time.
It’s a scary thought, but one that STORM Guidance CEO Neil Hare-Brown deals with on a daily basis. Hare-Brown’s London-based cyber risk consultancy specialises in incident response, threat actor engagement, and post-breach investigation, working alongside insurers like QBE, Munich Re and Chubb.
As one of a handful of outfits in the UK able to assess the damage after an attack and guide businesses through the legal, technical, and operational challenges of recovery, the team at STORM have seen it all, and Hare-Brown knows just how terrifying those first critical hours after a hack can be.
Ghosts in the Network
Inevitably, panic and paranoia often take hold immediately following a cyber-attack.
“The first thing that most organisations want to know is, are the bad guys still in our network?
“Do they still have unauthorised access to our data and applications? And if they do, what does that unauthorised access look like? Is it complete access to the network? Do we know where they’re coming in?”
“There are so many unanswered questions at that moment, but recovery can’t begin until there is eradication of any intrusion,” says Hare-Brown.
It’s an understandable fear. Recent data from Sophos shows that while the average dwell time might be decreasing, ransomware attackers were still managing to stay hidden inside networks for around four days before being discovered.
That window gives them ample time to deepen their foothold, complicating both containment and recovery efforts. Looking at backups provides a perfect example.
Almost all (94%) of ransomware incidents last year involved attackers deliberately targeting backups, with more than half (57%) of these attempts succeeding in their destruction.
When backups are hit, ransom demands can double – from around $1 million to $2.3 million – while overall recovery costs balloon to nearly $3 million, roughly eight times higher than if backups stay intact.
Ransomware victims whose backups are compromised also experienced longer recovery timelines, with just 26% fully recovered within a week compared to 46% of those whose backups are not impacted.
“Most organisations back up their data, but they don’t think about a total blackout,” says Hare-Brown.
“They don’t think about losing everything, and how they’re going to start from bare metal and build everything back. Most of the backup regime is not optimised for that type of scenario.”
Threat actors also often use dwell time to plant multiple backdoors or create persistence mechanisms designed to survive initial eradication efforts. Attempting recovery or forensic analysis while an attacker still has that access risks reinfection, data loss, or even tipping off the intruder to the organisation’s defensive moves.
Which is why, until any lingering presence of threat actors are removed from the system, nothing else can proceed safely.
Preserving the Digital Crime Scene
Just as critical as ejecting intruders, stresses Hare-Brown, is the need to preserve every shred of evidence.
“Talking about recovery is generally not something that any organisation should begin to think about until evidence is preserved,” he says.
It’s tempting for any firm hit by a cyber assault to pull the plug on their attackers quickly and rebuild systems to get back to business, but moving too fast risks wiping out vital evidence.
When a system is shut down, or even just disturbed, everything in RAM can disappear, literally in seconds, while one forensic guide notes that if the machine is still live, “volatile data stored solely in RAM may be lost if not recovered before shutting down the system”, as live response can unintentionally overwrite critical evidence.
Gathering this data is an incredibly tricky process, but digital forensics and incident response (DFIR) teams rely on volatile data to piece together exactly what might be at risk, and missing these memory snapshots means losing key parts of the puzzle, essentially whitewashing the crime scene and at risk the chance of a full recovery.
“To minimise the investigation time and maximise recovery time, you want to make sure that you’ve got forensic preparedness,” says Hare-Brown.
“Make sure that evidence is preserved so that recovery activities can begin, even if they’re just beginning at a low level.”
After forensic teams secure as much evidence as they can comes perhaps the hardest, most daunting phase of those recovery activities – direct engagement with the very threat actors who hold a company’s fate in their hands.
How Threat Actor Engagement Actually Works
Ransomware negotiations follow a surprisingly structured process. Cybercriminals have been found to operate like twisted customer service departments, often providing dedicated communication channels and ‘support’ staff to communicate with their victims.
The engagement usually begins through encrypted messaging platforms or dark web portals, with many ransom notes giving explicit instructions regarding how victims should make contact, typically involving a demand to download a Tor browser or other darknet navigation software.
Professional negotiators, like those at STORM, are key in handling these conversations. Not only do they better understand criminal psychology, but they can verify technical claims and work to reduce demands while ensuring decryption tools work.
“Most organisations are very unlikely to have the necessary skills and experience to investigate, recover and negotiate ransoms in-house,” says Hare-Brown.
“They don’t have the experience, and they’re very likely to make some significant mistakes, which leads to a lot more loss than is necessary.”
The numbers back up that claim. Arctic Wolf recently found that among those hit by ransomware, 90% engaged the services of a professional negotiator, which led to reduced payments in more than half of the cases, while only 30% of organisations that handled negotiations themselves are able to secure a reduction.
However, according to Hare-Brown, talking numbers with the hackers is one of the least important aspects of the negotiating phase.
“With threat actor engagement, it may well be that although there’s no intention to pay the ransom we still want to learn things from the criminals.”
“We want to understand what data they’ve stolen, and we want to get some idea how they’ve broken through affected networks, and introduce some delays before they release all of the data that they’ve stolen on their leak sites.”
Collecting intelligence is a far safer strategy than rushing to pay.
Recent studies show that only half of organisations that pay ransoms to cybercriminals actually recover their data, while four in five organisations who shell out to their attackers are hit a second time, with nearly two thirds of victim organisations being forced to pay more the next time around.
These numbers underscore why the goal of threat actor engagement should never be limited to simply striking a deal, because ultimately its prevention, not payment, that stops the cycle of repeat attacks.
Smart Security Beats Big Budgets
“Most organisations can make themselves very resilient to cyber-attack. They don’t even have to spend that much money, but they do need to have the skills necessary to do it.”
Rather than throwing money at cyber vendors hawking their latest big ticket security software, Hare-Brown is adamant that in his experience most firms can rebuff cyber-attacks simply by being prepared. It really is that simple, he says.
“Lack of preparedness, lack of knowledge, essentially, is the single biggest mistake that organisations make.”
Senior management should know where the impacts of an attack are likely to flow, what the regulatory obligations are, what the contractual obligations are. They need to know whether to put a budget together, or even how to acquire Bitcoin if considering a ransom payment.
They need to think about the legal aspects, as well as how they might communicate with the press, as well as with stakeholders and staff to maintain a sphere of control when an incident hits.
AI tools are proving to be the future in cyber defence, helping to cut time and shave millions from security budgets, but without answers to those fundamental questions the most sophisticated plans are being built on sand.
“You have to really have some practical, realistic scenarios that align to your business to figure out what you’re going to do,” recommends Hare-Brown.
That might seem like obvious advice, but it’s surprising how many organisations don’t heed it. Government figures show that less than a third of UK businesses have carried out risk assessments covering cybersecurity, while only 18% have tested their staff response, and just 12% have undertaken a cyber vulnerability audit.
By testing defences and taking part in wargaming or tabletop exercises, firms are essentially speeding up their recovery and post-incident process.
Studies suggest that organisations with proactive incident response plans recover 77% faster than those without, while firms that regularly train their staff to spot security concerns like phishing threats see a 50x ROI, proving that education is still the best security investment.
Recommended reading
- 87% of Firms Hit By AI Cyber-attacks
- Cyber-Attack Surface “Impossible to Control”
- Report: AI is Supercharging a Ransomware Boom
Cybersecurity is Not Just IT’s Problem
Breaches are as much about human response as about malware. Human error contributes to 88% of data breaches, underscoring the need for prepared, confident staff.
As with the systems, building resilience isn’t just about bolting on the latest tech – it’s about making sure staff are ready, composed, and coordinated when the pressure hits. As Hare‑Brown points out, that process begins well before any alert.
“You need to find out if staff take things in their stride. Or are they likely to be panicked? Do they find making decisions under that sort of stress hard? You need to do that psych evaluation in advance of an incident.”
Senior leadership, legal, communications, HR, and even facilities staff all have parts to play so when a real attack hits, teams don’t freeze. It’s about identifying all of those different roles and how they should interact, and then building in muscle memory so that an entire organisation can act together, confidently and coordinated, to limit the damage of a cyber-attack and speed up recovery.
“It’s not just an IT issue,” warns Hare-Brown
“It’s HR departments, procurement, senior management, regulatory compliance, anti money laundering. They all need to have some level of cyber skills that are relevant to their role.
“Don’t look at a cyber incident as an IT problem alone.”





