Companies are still paying ransomware demands despite official advice – Report

SECURUS Communications Ltd

Securus is a managed communications Operator, providing next-generation network infrastructure and value added services to Managed Hosting providers and the ‘cloud generation’​ of enterprises. Securus priority is to offer communication services that represent excellent value for money and are backed by exceptional levels of support.

Contact Securus
Securus Communications Ltd
Station Road, Landmark house, Hook, England RG27 9HA, GB
T: Enquiries:  | Service Desk: 03451 283458
Securus on LinkedIn | Securus on “X” | https://securuscomms.com

Why companies still pay ransomware demands despite official advice and what SMEs should learn - Report
Image Credit: Magnific

Gibraltar:  Monday, 24 August 2026 – 07:00 CET

Why companies still pay ransomware demands despite official advice and what SMEs should learn – Report
By: Iain Fraser – Cybersecurity Journalist
Published in Collaboration with:
Securus Communications Ltd
SMECyberInsights.co.uk – First for SME Cybersecurity
Google Indexed on: 240826 at 09:05 CET | SERPS: LLM(AI) Google
#CyberJourno #CyberEssentials #CyberResilience #CyberSafe #CyberSecurity #Cybersecurity #NCSC #SME #SMECyberInsights #SMECybersecurity #SMECyberInsights #ThreatIntelligence #Securus #Ransomware

Why companies still pay ransomware demands despite official advice

Organisations are still paying ransoms to cyber criminals, even though governments and security authorities have repeatedly advised against it. That uncomfortable gap between official guidance and real-world behaviour is one of the most revealing parts of the latest ransomware picture. According to Proofpoint, a significant share of organisations affected by ransomware have chosen to pay, underlining a simple reality: when disruption becomes severe enough, many businesses prioritise immediate operational survival over ideal security doctrine.

For SMEs, that finding matters because it strips away the fantasy that good intentions are a ransomware strategy. Most organisations do not pay because they approve of criminal extortion. They pay because they feel cornered: systems are down, backups may be weak, customers are waiting, staff cannot work, and leaders are making decisions with incomplete information under extreme pressure. In that environment, “never pay” can collapse from principle into aspiration.

The more useful question for smaller businesses is not whether paying is morally tidy or strategically sound in the abstract. The real question is why so many organisations still end up in a position where payment feels like one of the few remaining options. That is where the SME lesson begins.

What the Proofpoint findings show

Proofpoint’s research highlights the stubborn reality of ransomware’s continued effectiveness. It also suggests that the problem is not confined to technical compromise alone. It is operational, financial, and increasingly shaped by attacker adaptation.

Ransomware continues to create real leverage

The reason ransomware still works is not mysterious:

* it interrupts operations
* it creates uncertainty
* it threatens data loss or exposure
* it compresses decision-making time
* it exploits weak recovery readiness

When attackers achieve that level of leverage, organisations can end up weighing:

* downtime costs
* contractual exposure
* customer disruption
* reputational damage
* legal uncertainty
* recovery timelines

That is a brutal decision matrix, especially for smaller firms without large internal security, legal, and crisis-management teams.

Official advice and operational reality diverge

Authorities generally advise against paying ransoms because payment:

* funds criminal activity
* does not guarantee full recovery
* may invite repeat targeting
* can create legal or regulatory complications
* may still leave stolen data exposed

All of that is true. The difficulty is that in a live incident, those strategic warnings compete with immediate operational pain.

For SMEs, this divergence matters because it shows that ransomware resilience cannot depend on a promise made in calm conditions. It depends on whether the business can survive without paying when the pressure arrives.

AI is also influencing the threat landscape

The Proofpoint source also points to the role of AI in making ransomware attacks more effective or scalable. That is important because it suggests attackers may be getting better at:

* crafting phishing lures
* personalising social engineering
* accelerating reconnaissance
* improving deception
* increasing the speed of attack preparation

For SMEs, that means the ransomware problem is not standing still. Attackers are evolving while many smaller organisations are still trying to fix last year’s basics.

Why SMEs remain especially vulnerable

Ransomware remains one of the clearest examples of how cyber incidents become business crises.

1. Smaller firms often have less recovery depth

Many SMEs still struggle with:

* incomplete backup coverage
* untested recovery plans
* limited incident response resources
* over-reliance on key individuals
* unclear decision-making structures
* weak asset visibility

That means a ransomware incident can escalate quickly from a technical problem into a full operational standstill.

2. Downtime hits smaller firms harder

Large organisations may have more room to absorb disruption. Smaller firms often do not.

A few days of serious outage can affect:

* cash flow
* payroll
* customer trust
* supplier commitments
* service delivery
* contractual performance

In that context, paying a ransom can start to look less like a security decision and more like a desperate continuity decision.

That does not make it wise. It makes it understandable.

3. SMEs may overestimate their preparedness

A common problem is the assumption that having backups means being ransomware-ready.

But resilience depends on more than backups alone:

* are backups isolated
* are they tested
* how quickly can systems be restored
* who leads recovery
* what happens if data is stolen as well as encrypted
* how will customers and regulators be informed

Without clear answers, the business may discover too late that its “recovery strategy” was mostly optimism with a storage subscription.

Why companies still pay ransomware demands despite official advice and what SMEs should learn - Report

What SMEs should do instead of relying on hope

The best lesson from the Proofpoint findings is not simply “do not pay.” It is “build conditions in which payment is less likely to feel necessary.”

Practical priorities for SME resilience

1. Strengthen backup and recovery capability
Focus on:

* offline or isolated backups
* regular restore testing
* clear recovery priorities
* recovery time expectations

2. Prepare an incident response process before you need it
Define:

* who makes decisions
* who contacts external support
* who handles legal and reporting issues
* how communications are managed
* when critical systems are isolated

3. Reduce initial compromise opportunities
Prioritise:

* MFA
* patching
* email protection
* endpoint detection
* least-privilege access
* admin account control

4. Plan for data theft as well as encryption
Modern ransomware is often also an extortion and disclosure problem, not just a downtime problem.

5. Run tabletop exercises
Leaders should rehearse what happens if:

* core systems go offline
* customer data is threatened
* backups are delayed
* attackers demand payment fast

Quick resilience table

Below is a practical way to frame the issue for SMEs.

Ransomware pressure point Why it pushes firms toward payment Best SME response
Operational downtime Staff and services cannot function Tested recovery plans and backup restoration
Data encryption Critical files become inaccessible Segmented systems and resilient backups
Data theft Fear of exposure and reputational harm Data minimisation, response planning, legal readiness
Decision pressure Leaders must act quickly with limited clarity Predefined incident roles and escalation paths
Weak controls Initial compromise happens too easily MFA, patching, endpoint protection, email security

The key point is that payment often becomes tempting where resilience is weakest.

The wider lesson from the survey

Proofpoint’s findings should be read as a warning about preparedness, not just attacker behaviour. If large numbers of organisations still pay, that suggests ransomware defence is too often focused on prevention alone.

That is not enough.

Businesses also need:

* continuity planning
* recovery discipline
* leadership readiness
* realistic incident playbooks
* confidence in operating under disruption

For SMEs, this is especially important because ransomware is often sold as a technical problem with technical solutions. In reality, it is a business resilience problem with technical entry points.

The bigger takeaway

According to Proofpoint, many organisations affected by ransomware still end up paying cyber criminals despite clear official advice not to do so. For SMEs, the most important lesson is not to judge that decision too quickly from a safe distance. It is to understand why the pressure becomes so severe that payment feels viable at all.

The practical response is clear:

* improve recovery capability
* test backups properly
* define incident roles in advance
* reduce easy attack paths
* rehearse business disruption scenarios

The goal is not just to block ransomware. It is to ensure that if an attack succeeds, the business still has credible options other than funding the people who caused the problem in the first place.

FAQs

1. Why do companies still pay ransomware demands?

Because severe disruption, weak recovery capability, data exposure threats, and time pressure can make payment seem like the fastest route to business continuity.

2. Does official advice still say not to pay?

Yes. Authorities generally advise against paying because it funds criminal activity, offers no guarantee of recovery, and can create further risks.

3. What is the most important step for SMEs?

Build strong recovery readiness. Tested backups, clear incident roles, and rehearsed response plans can make a major difference when ransomware hits.

 

Lost your data? Don’t panic. R3 can help! Real data recovery services from a real UK lab!
Data loss can happen at any time and can happen in the most unexpected ways. As long as your device hasn’t been stolen R3 can recover your data from the most unlikely disasters. From their wholly secure state of the art Recovery Lab they can deploy the very best data recovery service as quickly as possible.

Contact R3 Data Recovery

Security House, Windsor St, Sheffield S4 7WB,
T: Enquires 800 999 3282 | Emergency: 07511 051360
R3 On LinkedIn | https://www.r3datarecovery.com/

What is a VPN & Does my SME Need one? A VPN is a Virtual Private Network a method of securing your communications credentials. When it comes to SMEs, the choice of VPNs can significantly impact the security and efficiency of their operations. NordVPN secures your Internet data with military-grade encryption, ensures your activity remains private and helps bypass geographic content restrictions online.   Join NordVPN Today and Save up to 73% and Get 3 months Extra Free – Rude Not to …!

CYBERInsights | Practical Small Business Cybersecurity
Image Credit: IfOnlyCommunications

SMECYBER Insights – Helping Keep Small Business CYBERSafe! 

Launched in 2020 by Cybersecurity Journalist Iain Fraser and his team at IfOnly… SMECYBERInsights was developed to be the go-to platform providing definitive, reliable & actionable Cybersecurity News, Intel,  Awareness & Training specifically written and curated for Small Business & Enterprise Owners, Partners and Directors throughout the UK. #SMECyberInsights #SMECyberSecurity #CyberAttack #CyberAwareness  #Compliance #DDoS #Fraud #Ransomware #ScamAlert #SME #SmallBusiness #SmallBusinessOwner #ThreatIntel