Over half of UK businesses now have a policy on whether to pay out on ransomware attacks
- Published: Wednesday, 07 July 2021 10:10
New research by Databarracks has found that 54 percent of UK businesses now have a defined policy in place to deal with ransomware attacks – whether this means paying a ransom, relying on insurance policies, or refusing to pay at all.
The findings are from Databarracks’ 2021 Data Health Check. Running since 2008, the annual report surveys over 400 IT decision-makers in the UK on critical issues relating to cyber security, IT resilience, cloud and remote working.
When asked if their organization had a policy for paying out on ransomware attacks:
- 21 percent have a policy to never pay a ransom
- 14 percent will pay a ransom if it is lower than the cost to recover systems
- 13 percent will pay if the ransom is covered by their cyber insurance policy
- 6 percent will pay only as a last resort if there is no other way to recover data.
Peter Groucutt, Managing Director of Databarracks, said: “Ransomware is the fastest growing threat we face. 29 percent or organizations were affected by ransomware in the last 12 months, up from just 9 percent in 2016.
“It’s encouraging to see organizations being proactive, setting policies and taking steps to better protect themselves against ransomware.
“However, the fact almost a third don’t have a policy of any kind is a significant gap. Of those that do, there’s still a strong tendency either to pay the ransom if it’s cost-effective to do so, or rely on cyber insurance policies to cover the financial hit.
“Neither of these approaches are sustainable in the long run. Paying a ransom, even if the demand is relatively small, emboldens criminals to hit harder and more frequently in future. There’s also always the possibility you won’t get your data back after paying up.
“Further, there’s no guarantee insurance policies will cover every claim: a Rusi think tank report has highlighted how the nascent cyber insurance industry has a lot to do to ensure policies are properly constructed and underwritten, and recommends insurers do more to incentivise good cyber practices among customers.”
Groucutt concluded: “Instead of choosing the path of least resistance, organizations should take proactive steps to make themselves more resilient. If your policy is not to pay, you must have alternatives you can rely on. That means not only having backups and disaster recovery processes in place, but that they are tested, and you are confident that you can recover quickly.
“It takes hard work in the short term, but it is the only viable long-term solution.”