It Doesn’t Pay to Pay
Ransomware victims in the study that opted to pay threat actors’ ransom demands saw only $610,000 less in average breach costs compared to those that chose not to pay, not including the cost of the ransom. Factoring in the high cost of ransom payments, the financial toll may rise even higher, suggesting that simply paying the ransom may not be an effective strategy.
“When you make the choice to pay a ransom, you are not only funding the next big problem, a future cyberattack, but you are also showing the cybercriminal ecosystem that you are willing to cooperate,” Kessem said. “That will immediately make a ransom-paying business an attractive target for a future attack. In fact, it’s not rare to see the same business hit twice/multiple times with ransomware due to this.”