Most businesses now have a ransomware payout policy

Lock on Laptop Screen
(Image credit: Future)

Many modern businesses know what to do in case of a ransomware attack, a new report is claiming.

The Databarracks’ 2021 Data Health Check paper, based on a poll of 400 IT decision-makers in the UK, found over half (54%) of organizations now have a defined policy set up that dictates their response to a ransomware attack.

Sometimes it means paying the ransom, sometimes it means reaching for the backup, and sometimes it means persisting, no matter what. Of the 400 ITDMs polled for the paper, a fifth (21%) have a policy never to pay ransom, no matter what. Further 14% will pay, if it’s cheaper compared to rebooting the system, and 13% will pay if their cyber insurance policy can cover the expenses. Another 6% will only pay if there is absolutely no other alternative. 

Discussing the findings, Databarracks’ Managing Director Peter Groucutt said ransomware is the fastest-growing threat today, with almost a third (29%) of organizations falling victim in the last year, compared to just 9% five years ago.

And while he believes it’s “encouraging” seeing businesses being proactive, it’s still worrisome that a third don’t have any kind of policies set up, and that some expect to pay up if needed.

“Neither of these approaches are sustainable in the long run. Paying a ransom, even if the demand is relatively small, emboldens criminals to hit harder and more frequently in future. There’s also always the possibility you won’t get your data back after paying up,” he says

“Further, there’s no guarantee insurance policies will cover every claim.”

“Instead of choosing the path of least resistance, organizations should take proactive steps to make themselves more resilient. It takes hard work in the short term, but it is the only viable long-term solution.”

While ransomware attacks against large enterprises often make headlines, SMBs are also a frequent target. Ransomware operators are no longer casting a wide net, but instead focus on specific organizations and slowly move their way into the premises, regardless of the victim’s size.

A ransomware attack will usually start with a phishing email or a fraudulent SMS/call, which is why it’s essential for SMBs to train and educate their employees on the dangers of downloading email attachments and clicking on links from unconfirmed sources.

An SMB suffering a ransomware attack may lose customer trust, end up with a destroyed brand image, on top of mounting remedy costs and potential fines. 

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
A computer being guarded by cybersecurity.
The impact of the cyber insurance industry in resilience against ransomware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
Representational image of a cybercriminal
Should ransomware payments be illegal?
Hack The Box crisis simulation event
“Everyone will experience a hack” - how incident response can protect your organization
UK Government launches ransomware protection proposals
Latest in Security
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Latest in News
Xbox Series X and Xbox wireless controller set to a green background
Xbox Insiders are currently testing a new Game Hub feature that looks useful, but I've got mixed feelings about it
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI