Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    A More Affordable Version Arrives Today. Here’s What We Know

    October 7, 2025

    Paytm launches Playback feature to make a rap out of your expenses – but is your data safe?

    October 7, 2025

    Age of Imprisonment Details More Playable Characters

    October 7, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Paytm launches Playback feature to make a rap out of your expenses – but is your data safe?

      October 7, 2025

      OnePlus 15T tipped to launch in early 2026 with Snapdragon 8 Elite Gen 5 chipset: Report

      October 7, 2025

      OpenAI launches AgentKit to make building AI agents faster and safer: How it works

      October 7, 2025

      OxygenOS 16 set to launch on Oct 16: Will OnePlus borrow Apple’s Dynamic Island? Here’s what to expect

      October 7, 2025

      Diwali deal: Samsung Galaxy S24 5G now ₹35,000 off on Flipkart – 3 reasons to buy

      October 7, 2025
    • Mobiles

      Realme P4 Series Key Specifications Confirmed Ahead of Launch in India on August 20

      August 12, 2025

      iQOO Z10 Lite 4G With Snapdragon 685 Chip, 50-Megapixel Camera Launched: Price, Specifications

      August 12, 2025

      Flipkart Independence Day Sale 2025 Begins Tomorrow: Deals on iPhone 16, Samsung Galaxy S24, and More

      August 12, 2025

      Vivo V60 Launching Today: Know Price, Features, Specifications and More

      August 12, 2025

      Oppo Find X9 Ultra to Feature Bigger Dual-Cell Battery Than Find X8 Ultra, Tipster Claims

      August 12, 2025
    • Gaming

      Age of Imprisonment Details More Playable Characters

      October 7, 2025

      Sonic Games With The Most Ridiculous Stories

      October 7, 2025

      Best Games That Make You Feel Like A Powerful Telekinetic

      October 7, 2025

      Mina the Hollower Hit With Release Date Delay

      October 7, 2025

      Luffy’s Final Gear Is Coming, And It’s Better Than Gear 5

      October 7, 2025
    • SEO Tips
    • PC/ Laptops

      Apple MacBook Model With A-Series Chip, Affordable Price Tag to Launch in Early 2026: Report

      August 12, 2025

      Flipkart Independence Day Sale 2025: Best Deals on Laptops Teased Before the Sale Begins

      August 12, 2025

      My Child Doesn’t Need a PC, Until They Really Do

      August 11, 2025

      Apple’s MacBook Pro With M6 Chip, OLED Display Could Launch by Early 2027: Mark Gurman

      August 11, 2025

      Google to Reportedly Shut Down Support for Steam for Chromebook in 2026

      August 9, 2025
    • EV

      A More Affordable Version Arrives Today. Here’s What We Know

      October 7, 2025

      Is The Model 3 Highland RWD The Cheapest Car You Can Get From Tesla?

      October 7, 2025

      Lucid Q4 Deliveries Hit Record Thanks To Gravity, EV Tax Credit

      October 7, 2025

      Over 40,000 Nissan Leaf EVs Could Catch Fire, And There’s No Fix Yet

      October 7, 2025

      2026 Cadillac Optiq Gets ‘Dramatic Increase’ In Performance—And A Tesla Plug

      October 7, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Experts’ Views on Refusing or Paying After a Ransomware Attack
    Featured

    Experts’ Views on Refusing or Paying After a Ransomware Attack

    KavishBy KavishAugust 16, 2024Updated:August 16, 2024No Comments6 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Experts’ Views on Refusing or Paying After a Ransomware Attack
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ransomware attacks have shown signs of decreasing in recent months. Yet they still pose enough threat for organizations to rethink whether a successful breach of their computers justifies paying a ransom demand in hopes attackers will not divulge their stolen content.

    According to the NCC Group Threat Pulse Report released in May, the ransomware landscape remains turbulent despite fewer reported incidents since April. Industrials (34%) and Consumer Cyclicals (18%) remained the first and second-most targeted sectors.

    There has been a significant shake-up among the top 10 ransomware actors since April. Hunters, one of the leading bad actors, moved from eighth to the second most active threat actor. It launched 61% more ransomware attacks in April than in March. RansomHub replaced RA Group in third place and saw a 42% increase in attacks over March.

    The policy of not paying ransom, often called a “no concessions” policy, is a widely debated strategy in counterterrorism and hostage situations. Its effectiveness continues to be argued from multiple perspectives. Cybersecurity experts apply the same reasoning when deciding whether to make or not make ransomware payments.

    Some argue that paying ransomware demands finances future criminal activity. Legal considerations are also part of the decision equation. In some countries, paying ransom to terrorists is illegal. Others say similar laws are needed to help curb ransomware crime.

    According to the U.S. Department of the Treasury, no federal law in the United States makes paying ransomware demands illegal. However, making such payments comes with significant legal and financial risks.

    The rationale behind a “no concessions” policy is that eliminating the financial incentive for cybercriminals could decrease the frequency and severity of ransomware attacks, according to Anne Cutler, cybersecurity evangelist at Keeper Security.

    “However, this approach, while commendable, presents real-world challenges for organizations,” she told TechNewsWorld.

    No-Pay Ransomware Strategy is Gaining Support

    Cybersecurity experts and government officials have long supported the policy of not paying ransoms due to its potential to curb criminal activity and reduce attacks, noted Cutler. Paying ransoms is risky and unreliable and does not guarantee that cybercriminals will restore access or decrypt files.

    “Cybersecurity insurance companies are increasingly excluding ransomware payments from coverage, enticing organizations to invest more heavily in proactive preventative measures,” she added.

    Cutler offered Japan’s strategy as a pertinent example. Nikkei Cross Tech and Japan Proofpoint report that Japanese organizations maintain a notably low rate of ransom payments compared to other countries. Despite a surge in ransomware incidents through 2023, the first half of 2024 has seen a slight decline, according to the Metropolitan Police Department’s Threats in Cyberspace Report.

    “While it is not clear if this decrease is directly related to Japan’s low payment rate, it suggests that minimizing ransom payments could influence overall ransomware activity,” she explained.

    Challenges Enforcing Ransomware Payment Bans

    Craig Jones, vice president of security operations at Ontinue, admitted that cyber experts discuss the pros and cons of banning ransom payments to combat ransomware. But that is a multifaceted proposition.

    “While it could dishearten attackers by cutting off their financial incentives, enforcing such a ban is difficult, especially with the anonymity provided by cryptocurrencies,” he told TechNewsWorld.

    In critical situations, organizations may still choose to pay ransoms covertly to recover vital data or restore operations, undermining the ban’s effectiveness, he added.

    Peer Lessons Learned for Contact Center as a Service Solutions Implementation

    Jones views a more well-rounded approach as potentially more effective. He favors enhancing cybersecurity defenses, promoting international cooperation to track and prosecute cybercriminals, and regulating the cyber insurance industry.

    “This multilayered strategy addresses the root causes and consequences of ransomware without the significant enforcement challenges and potential negative consequences of a ban,” he reasoned.

    “Such an approach acknowledges the complexities and the global nature of cyber threats, offering a balanced solution to mitigate ransomware risks.”

    ‘No Concessions’ Ransomware Policy Risks and Realities

    In theory, no payment clauses try to disrupt the profitability of cybercrime by denying attackers their desired outcome. However, applying this strategy universally can be challenging, warned Jason Soroko, senior vice president of product at Sectigo. His company offers comprehensive certificate lifecycle management (CLM) services.

    “While banning ransomware payments might deter attacks over time, it also puts victims, especially critical infrastructure, in a precarious position, potentially leading to severe disruptions,” he told TechNewsWorld.

    Legal frameworks prohibiting payments would need to be carefully crafted to avoid unintended consequences, he suggested. This includes forcing organizations to operate in secrecy or exacerbating the damage during an active attack.

    “The balance between disincentivizing crime and protecting essential services is delicate,” he observed.

    Strengthening Cybersecurity Through Employee Training

    Employee training and education on cybersecurity best practices are crucial for protecting an organization from evolving cyber threats, countered Patrick Tiquet, vice president for security and architecture at Keeper Security.

    “Employees are the first line of defense. Regular training sessions should emphasize the importance of vigilance when receiving unsolicited multi-factor authentication (MFA) prompts,” he asserted.

    Peer Lessons Learned for Contact Center as a Service Solutions Implementation

    This education process should focus on training employees to question unexpected notifications immediately and report any suspicious activity without delay. Simulated phishing attacks and push notification exercises can effectively help employees recognize and respond to threats, Tiquet noted.

    “Fostering a culture where employees feel comfortable reporting potential security issues without fear of reprimand is essential for timely threat detection and response,” he said.

    Tips to Avoid Ransomware Payment Dilemmas

    Ngoc Bui, a cybersecurity expert at Menlo Security, argues that paying ransoms should not be illegal anywhere. While it might incentivize threat actors, not paying could be more damaging, especially for organizations involved in critical infrastructure.

    “The disruption from ransomware can be catastrophic, and organizations must prioritize protecting operations and stakeholders. Organizations that suffer a ransomware attack should also use it as a learning opportunity to adjust their security measures and ensure they are using actionable intelligence to do so,” said Bui.

    A primary strategy for avoiding the pay-or-do-no-pay question is proactively preventing ransomware attacks. Tiquet recommends companies manage third-party contractor security. Start by conducting thorough background checks and security assessments to ensure contractors meet stringent standards before granting access to sensitive systems.

    “Once contractors are onboarded, applying the principle of least privilege is critical to an organization’s security,” he said.

    This approach means granting them only the minimum access necessary for their specific tasks and roles within the organization. Regular audits of third-party access are crucial to detect any unusual or unauthorized activities early on, enabling prompt action to mitigate potential risks and breaches.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    A More Affordable Version Arrives Today. Here’s What We Know

    October 7, 2025

    Paytm launches Playback feature to make a rap out of your expenses – but is your data safe?

    October 7, 2025

    Age of Imprisonment Details More Playable Characters

    October 7, 2025

    OnePlus 15T tipped to launch in early 2026 with Snapdragon 8 Elite Gen 5 chipset: Report

    October 7, 2025

    Is The Model 3 Highland RWD The Cheapest Car You Can Get From Tesla?

    October 7, 2025

    OpenAI launches AgentKit to make building AI agents faster and safer: How it works

    October 7, 2025
    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    A More Affordable Version Arrives Today. Here’s What We Know

    October 7, 2025

    Paytm launches Playback feature to make a rap out of your expenses – but is your data safe?

    October 7, 2025

    Age of Imprisonment Details More Playable Characters

    October 7, 2025

    OnePlus 15T tipped to launch in early 2026 with Snapdragon 8 Elite Gen 5 chipset: Report

    October 7, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.