Where the choice lies
Almost everyone has backups. The problem is that deploying them across the organization takes days or weeks, and sometimes it turns out that the backups were encrypted too because they were stored on the same network.
Attackers also added a second lever. They not only encrypt the data but also copy it in advance, then demand money to keep it from being published. Backups do not help at all here: the files are already in someone else's hands.
Why paying is still a bad idea
A key does not guarantee recovery. Decryption is slow and not always complete. Some data comes back damaged.
The promise comes with no guarantees. Copied files may surface later. It is impossible to verify that they were deleted.
The company gets put on a list. Those who pay are attacked again more often: it becomes known that they pay and have money.
The market grows. Every payment funds the next wave of attacks and makes this business profitable.
That is why the official recommendation in most countries is not to pay. But it is aimed at the industry as a whole, while the decision is made by a specific company that is losing money right now, and those two kinds of logic do not match.
Insurance also plays a separate role. An insurance policy makes paying a quick, predictable way out, and that is exactly what is often criticized: the convenience of paying reduces the motivation to prepare in advance.
Preparedness is what matters most. Backups stored separately from the network, along with a recovery plan practiced in advance, turn a catastrophe into an unpleasant day and make negotiations unnecessary.
Finish reading in the Miqo app
1 more minute, then a quiz at the end. Find it under “Crime → Cybercrime”
Point your phone camera here to open the App Store or Google Play.
Sources
- The decision to pay in data-encryption attacks is driven primarily by the cost of downtime and recovery timelines
- double-extortion attacks involving data theft make backups insufficient protection, while payment guarantees neither full recovery nor deletion of the stolen data