Should a business ever pay a ransomware demand?

Should a business ever pay a ransomware demand?
The one word that universally incites fear, concern, stress and sleepless nights across every in a business is commonly known as Ransomware.
What is Ransomware?
Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid.
It started with a trojan called PC Cyborg and has evolved into a multitude of darkweb services examples include Petya, Cerber, Satan RaaS Platform etc.
How is it delivered?
Typically to an unsuspecting user, either through spamming hundreds of thousands of accounts with malicious links to play the numbers game. Or alternatively targeting specific individuals with an intelligence led attack. There are many social sophisticated engineering attacks deployed to get a user to open or click a link.
Should you pay?
- If you pay up, what is to stop it happening again?
- If you don’t pay, will you get your data back? This becomes slightly more desperate if you don’t have recent or an adequate backup of your data.
- If you pay, you make it worth fuel the success of the criminal actions.
- No data, no business. Will the business survive if you don’t?
The various silver bullet products, solutions, policies and system testing can and absolutely go a long way in preventing, securing and backing up your data to make your business as resilient as possible.
The other key is to raise awareness and train the weakest link, aka the users of the systems. An educated user who is aware of the basics of cyber security will make a significant difference.
Thoughts from an expert:
Clive Finlay Head of EMEA Solution Engineering Symantec (A Division of Broadcom)
Companies should never pay the ransomware, for a multitude of reasons, the main one being that you may fuel the criminal organisation to do more; and there is no reason why they will not hit your company again after you pay. Also, bear in mind that in some parts of the world like the US it is a criminal offence to pay the ransom, this is considered funding terrorism. However, we all appreciate what a difficult position a company may be in should their critical data be crypto-locked via ransomware, since there is no way of decrypting without the key due to the industrial strength of the encryption that is typically used today. This is why investment in modern cyber security endpoint protection and system back-ups are critical. Your last line of defence is backing up your data and if there is a weak link here in your current organisational back-up process then don’t delay in putting it right.
Andy Qualtro. Security Professional.
Don’t ever pay.
1) You fund the bad guys
2) There’s no guarantee that someone who was willing to blackmail you in the first place will keep to their side of any deal ... I know what I’d put my money on.
Prevention is the best course of action. Focus on keeping your malware defences up to date and your data backed up.
If you are hit you’ll have a backup, right? A simple restore and a tool such as Power Eraser (available free from Norton) will sort you out.

Latest Jobs
-
- Security Architect - Cloud - Consultancy London
- London
- N/A
-
Security Architect with a focus into Cloud (AWS, Azure or Google Cloud Platform) needed. You must have client facing consultancy experience. This mean you must have experience working with clients helping them to meet their security design needs. That could include working with existing internal teams to understand, review and mitigate / uplift existing Cloud Security designs, or perhaps helping clients set out / understand their current needs and deliver their cloud security strategy. (Or anything in between) Technical knowledge is of course essential but working with clients to understand and solve their Cloud Security design challenges is vital. You must obviously have a current history working as a cloud security architect. You will need to be commutable to London. Whilst a hybrid role the expectation is 3 days a week in the office / meeting clients. International relocation or Visa sponsorship isn’t available for this role.
-
- Cloud Architect- German Speaker
- Hungary
- Upto €48000 per year + bonus + benefits
-
As a Senior Pre-Sales Solutions Architect, you will play a pivotal role in driving our sales success by translating complex technical solutions into compelling proposals that resonate with our clients. You will collaborate closely with our sales teams to understand customer needs, design tailored solutions, and negotiate successful deals. Responsibilities: Solution Design: Develop comprehensive technical solutions that align with customer business objectives and industry best practices. Proposal Development: Create compelling proposals, including requirements gathering questionnaires, presentation materials, and Statements of Work (SOWs). Customer Engagement: Build strong relationships with clients, understanding their technical, business, and commercial requirements. Collaboration: Work closely with sales teams, delivery teams, and third-party partners to ensure successful project execution. Pricing Strategy: Define and deliver pricing strategies that align with customer needs and company objectives. Requirements: Experience in technical pre-sales or sales support roles. Proven track record in designing and delivering successful customer solutions. Strong technical foundation in areas such as VMware, Azure, AWS, cloud computing, and data center technologies. Excellent understanding of sales principles, account management, and negotiation techniques. Ability to explain complex technical concepts clearly and concisely. Experience working in international teams and supporting clients across multiple regions. Fluency in German and English is essential. Benefits: Competitive salary and benefits package Opportunity to work on challenging and rewarding projects Collaborative and supportive work environment Potential for career growth and advancement Please note that this role is focused on supporting German clients, but will also involve global client support as needed.
-
- Director Cyber Security Consulting Medical / Biotech / Biopharma. United Kingdom
- United Kingdom
- Generous salary, uncapped bonus, travel and usual benefits.
-
CH8431 Director Cyber Security Consulting Medical / Biotech / Biopharma. United Kingdom Looking to make Security Partner within 2-3 years? Do you have current experience selling / delivering cyber consulting & advisory services into Medical / Biotech / Biopharma? If so, we would like to speak with you. Apply today for a discreet conversation. This is a UK based opportunity. Current Cyber security consulting experience is essential, as is a network into the Pharmaceutical / Healthcare industry. Package- Generous salary, uncapped bonus, travel and usual benefits. 07884666351 | chris.holt@dclsearch.com
-
- Director Cyber Security Consulting Pharmaceutical / Healthcare. United Kingdom
- United Kingdom
- Generous salary, uncapped bonus, travel and usual benefits.
-
CH8430 Director Cyber Security Consulting Pharmaceutical / Healthcare. United Kingdom Looking to make Security Partner within 2-3 years? Do you have current experience selling / delivering cyber consulting & advisory services into Pharmaceutical / Healthcare? If so, we would like to speak with you. Apply today for a discreet conversation. This is a UK based opportunity. Current Cyber security consulting experience is essential, as is a network into the Pharmaceutical / Healthcare industry. Package- Generous salary, uncapped bonus, travel and usual benefits. 07884666351 | chris.holt@dclsearch.com