Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    GM’s President Explains What’s New

    November 14, 2025

    Build Mode starts at the beginning: How Forethought AI found product-market fit

    November 14, 2025

    Vivo S50 Series Key Specifications Tipped: Expected to Launch in December

    November 14, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Build Mode starts at the beginning: How Forethought AI found product-market fit

      November 14, 2025

      VCs abandon old rules for a ‘funky time’ of investing in AI startups

      November 14, 2025

      Blue Origin sticks first New Glenn rocket landing and launches NASA spacecraft

      November 14, 2025

      Uber quietly pilots in-app video recording for drivers in India

      November 14, 2025

      Google’s NotebookLM adds ‘Deep Research’ tool, support for more file types

      November 13, 2025
    • Mobiles

      Vivo S50 Series Key Specifications Tipped: Expected to Launch in December

      November 14, 2025

      OPPO Introduces “LUMO Lab” Initiative to Elevate Mobile Photography in India

      November 14, 2025

      OnePlus 15 with Snapdragon 8 Elite Gen 5 SoC, 7300 mAh Battery, Android 16, 165Hz Display Launched in India

      November 14, 2025

      OPPO Reno15 Series India Launch Timeline and Price Range Leaked

      November 13, 2025

      Vivo X300 Series India Launch Confirmed

      November 13, 2025
    • Gaming

      Nintendo Switch 2 Update Has Bricked Some Docks

      November 14, 2025

      What Are T.E.D.D. Tasks in Black Ops 7 Zombies/

      November 14, 2025

      Best Manhwa With OP MCs

      November 13, 2025

      How to Start Kingdom Come Deliverance 2’s Mysteria Ecclesiae DLC

      November 13, 2025

      Horizon MMORPG Officially Revealed, And Fans Have Thoughts

      November 13, 2025
    • SEO Tips
    • PC/ Laptops

      Apple Reportedly Reserving OLED Displays for M6 Pro and M6 Max MacBook Pro Models

      November 10, 2025

      Apple Reportedly Working on a Budget MacBook Featuring iPhone Chip: Expected Launch and Price

      November 5, 2025

      Acer Predator Helios Neo 16 AI and 16S AI Gaming Laptops Launched in India: Check Pricing and Specifications

      November 4, 2025

      COLORFUL Launches Rimbook L1: Affordable Laptop For Everyday Use

      November 4, 2025

      Acer Expands Lite Series With New Nitro Lite 16 Laptop in India

      November 3, 2025
    • EV

      GM’s President Explains What’s New

      November 14, 2025

      Teslas May Get Apple CarPlay Soon: Report

      November 14, 2025

      China Is Cracking Down On Too-Quick EVs

      November 14, 2025

      The Ford F-150 Lightning’s Struggles Are A Terrifying Lesson For The EV World

      November 13, 2025

      Breakthrough Device Promises To Cut Charging Times And Boost EV Range

      November 13, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Experts’ Views on Refusing or Paying After a Ransomware Attack
    Featured

    Experts’ Views on Refusing or Paying After a Ransomware Attack

    KavishBy KavishAugust 16, 2024Updated:August 16, 2024No Comments6 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Experts’ Views on Refusing or Paying After a Ransomware Attack
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ransomware attacks have shown signs of decreasing in recent months. Yet they still pose enough threat for organizations to rethink whether a successful breach of their computers justifies paying a ransom demand in hopes attackers will not divulge their stolen content.

    According to the NCC Group Threat Pulse Report released in May, the ransomware landscape remains turbulent despite fewer reported incidents since April. Industrials (34%) and Consumer Cyclicals (18%) remained the first and second-most targeted sectors.

    There has been a significant shake-up among the top 10 ransomware actors since April. Hunters, one of the leading bad actors, moved from eighth to the second most active threat actor. It launched 61% more ransomware attacks in April than in March. RansomHub replaced RA Group in third place and saw a 42% increase in attacks over March.

    The policy of not paying ransom, often called a “no concessions” policy, is a widely debated strategy in counterterrorism and hostage situations. Its effectiveness continues to be argued from multiple perspectives. Cybersecurity experts apply the same reasoning when deciding whether to make or not make ransomware payments.

    Some argue that paying ransomware demands finances future criminal activity. Legal considerations are also part of the decision equation. In some countries, paying ransom to terrorists is illegal. Others say similar laws are needed to help curb ransomware crime.

    According to the U.S. Department of the Treasury, no federal law in the United States makes paying ransomware demands illegal. However, making such payments comes with significant legal and financial risks.

    The rationale behind a “no concessions” policy is that eliminating the financial incentive for cybercriminals could decrease the frequency and severity of ransomware attacks, according to Anne Cutler, cybersecurity evangelist at Keeper Security.

    “However, this approach, while commendable, presents real-world challenges for organizations,” she told TechNewsWorld.

    Table of Contents

    Toggle
    • No-Pay Ransomware Strategy is Gaining Support
    • Challenges Enforcing Ransomware Payment Bans
    • ‘No Concessions’ Ransomware Policy Risks and Realities
    • Strengthening Cybersecurity Through Employee Training
    • Tips to Avoid Ransomware Payment Dilemmas

    No-Pay Ransomware Strategy is Gaining Support

    Cybersecurity experts and government officials have long supported the policy of not paying ransoms due to its potential to curb criminal activity and reduce attacks, noted Cutler. Paying ransoms is risky and unreliable and does not guarantee that cybercriminals will restore access or decrypt files.

    “Cybersecurity insurance companies are increasingly excluding ransomware payments from coverage, enticing organizations to invest more heavily in proactive preventative measures,” she added.

    Cutler offered Japan’s strategy as a pertinent example. Nikkei Cross Tech and Japan Proofpoint report that Japanese organizations maintain a notably low rate of ransom payments compared to other countries. Despite a surge in ransomware incidents through 2023, the first half of 2024 has seen a slight decline, according to the Metropolitan Police Department’s Threats in Cyberspace Report.

    “While it is not clear if this decrease is directly related to Japan’s low payment rate, it suggests that minimizing ransom payments could influence overall ransomware activity,” she explained.

    Challenges Enforcing Ransomware Payment Bans

    Craig Jones, vice president of security operations at Ontinue, admitted that cyber experts discuss the pros and cons of banning ransom payments to combat ransomware. But that is a multifaceted proposition.

    “While it could dishearten attackers by cutting off their financial incentives, enforcing such a ban is difficult, especially with the anonymity provided by cryptocurrencies,” he told TechNewsWorld.

    In critical situations, organizations may still choose to pay ransoms covertly to recover vital data or restore operations, undermining the ban’s effectiveness, he added.

    Peer Lessons Learned for Contact Center as a Service Solutions Implementation

    Jones views a more well-rounded approach as potentially more effective. He favors enhancing cybersecurity defenses, promoting international cooperation to track and prosecute cybercriminals, and regulating the cyber insurance industry.

    “This multilayered strategy addresses the root causes and consequences of ransomware without the significant enforcement challenges and potential negative consequences of a ban,” he reasoned.

    “Such an approach acknowledges the complexities and the global nature of cyber threats, offering a balanced solution to mitigate ransomware risks.”

    ‘No Concessions’ Ransomware Policy Risks and Realities

    In theory, no payment clauses try to disrupt the profitability of cybercrime by denying attackers their desired outcome. However, applying this strategy universally can be challenging, warned Jason Soroko, senior vice president of product at Sectigo. His company offers comprehensive certificate lifecycle management (CLM) services.

    “While banning ransomware payments might deter attacks over time, it also puts victims, especially critical infrastructure, in a precarious position, potentially leading to severe disruptions,” he told TechNewsWorld.

    Legal frameworks prohibiting payments would need to be carefully crafted to avoid unintended consequences, he suggested. This includes forcing organizations to operate in secrecy or exacerbating the damage during an active attack.

    “The balance between disincentivizing crime and protecting essential services is delicate,” he observed.

    Strengthening Cybersecurity Through Employee Training

    Employee training and education on cybersecurity best practices are crucial for protecting an organization from evolving cyber threats, countered Patrick Tiquet, vice president for security and architecture at Keeper Security.

    “Employees are the first line of defense. Regular training sessions should emphasize the importance of vigilance when receiving unsolicited multi-factor authentication (MFA) prompts,” he asserted.

    Peer Lessons Learned for Contact Center as a Service Solutions Implementation

    This education process should focus on training employees to question unexpected notifications immediately and report any suspicious activity without delay. Simulated phishing attacks and push notification exercises can effectively help employees recognize and respond to threats, Tiquet noted.

    “Fostering a culture where employees feel comfortable reporting potential security issues without fear of reprimand is essential for timely threat detection and response,” he said.

    Tips to Avoid Ransomware Payment Dilemmas

    Ngoc Bui, a cybersecurity expert at Menlo Security, argues that paying ransoms should not be illegal anywhere. While it might incentivize threat actors, not paying could be more damaging, especially for organizations involved in critical infrastructure.

    “The disruption from ransomware can be catastrophic, and organizations must prioritize protecting operations and stakeholders. Organizations that suffer a ransomware attack should also use it as a learning opportunity to adjust their security measures and ensure they are using actionable intelligence to do so,” said Bui.

    A primary strategy for avoiding the pay-or-do-no-pay question is proactively preventing ransomware attacks. Tiquet recommends companies manage third-party contractor security. Start by conducting thorough background checks and security assessments to ensure contractors meet stringent standards before granting access to sensitive systems.

    “Once contractors are onboarded, applying the principle of least privilege is critical to an organization’s security,” he said.

    This approach means granting them only the minimum access necessary for their specific tasks and roles within the organization. Regular audits of third-party access are crucial to detect any unusual or unauthorized activities early on, enabling prompt action to mitigate potential risks and breaches.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    GM’s President Explains What’s New

    November 14, 2025

    Build Mode starts at the beginning: How Forethought AI found product-market fit

    November 14, 2025

    Vivo S50 Series Key Specifications Tipped: Expected to Launch in December

    November 14, 2025

    Nintendo Switch 2 Update Has Bricked Some Docks

    November 14, 2025

    VCs abandon old rules for a ‘funky time’ of investing in AI startups

    November 14, 2025

    Teslas May Get Apple CarPlay Soon: Report

    November 14, 2025

    Comments are closed.

    Top Reviews
    Editors Picks

    GM’s President Explains What’s New

    November 14, 2025

    Build Mode starts at the beginning: How Forethought AI found product-market fit

    November 14, 2025

    Vivo S50 Series Key Specifications Tipped: Expected to Launch in December

    November 14, 2025

    Nintendo Switch 2 Update Has Bricked Some Docks

    November 14, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.