Should a company pay a ransom in a cyberattack?
CIOREVIEW >> Security >> NEWS

This article is part of CIOReview's Innovation Insights series featuring expert contributions nominated by our subscribers and reviewed by our editorial team.

Should a company pay a ransom in a cyberattack?

Rodrigo Herrera, CTO at TrustDimension

With the increase in news about ransomware affecting different types of organizations every day, CIOs of companies that have not yet been victims face the challenge of knowing if the organization is prepared and most importantly, they don’t know if have effective plans to prevent, mitigate and recover from an event like this.

49% of organizations have a formal ransomware response plan, compared to 48% in 2022.

Source: Thales

Although, in recent years there has been more awareness about the preparation that must be taken, there is still a great gap to ensure that the critical assets of companies are free from falling into the hands of cybercriminals.

During last weeks, some of our customers who were victims of ransomware trusted us to support them in mitigating and recovering from these attacks, and for this reason we want to share some recommendations on how to deal with the issue of ransomware and what strategies can be used to recover.

By getting involved and executing our incident response process, we identified some recurring doubts and failures in the decisions that had been made. With a couple of customers, the executives were tempted to pay the "ransom" of the information, this is a very common issue, in another case the executives left the IT manager without support despite the existence of legal implications due to the nature of the business; and in another case, an external consultant wanted to take control of the attacker, which resulted in the reboot of the machines and the loss of the possibility to obtain the encryption key; finally in another case, the recovery had to be started again because the data was encrypted again.

 Companies must have an ally, a cybersecurity specialist with experience in handling ransomware incidents, who support them in preventing and constantly evaluating their security posture to reduce the attack surface. 

A company does not experience situations of this nature every day so, when suffering an attack, the probability of making an error to normalize the operation is highly possible, either due to omission or ignorance, which will directly impact the time to achieve the recovery, with the immediate monetary cost that this represents without forgetting secondary impacts such as the reputation of the brand or legal implications.

Regarding these facts, I would like to emphasize the first big question for companies: Should they agree to pay a ransom?  The answer is NO, and these are the reasons:

● Today these attacks have a double extortion, the first is to provide us with a decryption key and the second to not disclose the data they obtained, without a guarantee in both cases.

● Paying the ransom helps criminal organizations finance their operations, so by paying, we are encouraging such attacks to continue happening.

Therefore, it is very important that companies have an ally, a cybersecurity specialist with experience in handling ransomware incidents, who supports them in the prevention and constant evaluation of their security posture to reduce the attack surface. But also, to prepare an action plan with the processes, policies and procedures to execute before, during and after an event, in a coordinated manner.

Contact us, we have supported different organizations and I am sure that we can accompany you in any critical security situation.

MORE FROM INNOVATION INSIGHTS

AI as a Catalyst for Better Project Leadership
Think Big Technology
Omar Hafez, Founder
Connecting Data, Context, and Trust in the Age of Semantic AI
Zenia Graph
Aurelije Zovko, Co-founder and CTO, Zenia Graph, and Nina Mladenovski, Co-founder and COO
Stop Automating Broken Processes: The Next Era of Business Workflow Automation
Herbert Insights & Innovations
Martin J. Herbert IV, President/CEO

EXPLORE OUR KNOWLEDGE NETWORK



The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.