Pay up or not? Ransomware surge has victims facing tough choices.
Source Entity
Hannah Murphy, Financial Times

Rising ransomware sophistication is forcing governments to consider banning ransom payments. New research indicates nearly half of victims pay, leading to legislative efforts to protect critical infrastructure from extortion.
The Escalating Ransomware Crisis: A Global Dilemma
The digital landscape is currently facing a perilous inflection point as ransomware attacks grow in frequency and complexity. According to 2025 research from Sophos, nearly 50% of targeted organizations choose to pay the ransom to recover their data. This reliance on payment has inadvertently fueled a cycle of criminal profitability, emboldening threat actors to increase their demands and refine their methodologies.
The Shift Toward Legislative Intervention
Governments worldwide are beginning to recognize that voluntary compliance is insufficient to stem the tide of cyber extortion. In the United Kingdom, for instance, authorities are actively advancing legislation to prohibit public sector entities, including the National Health Service, local councils, and schools, from making payments. By cutting off the financial incentive, policymakers hope to dismantle the business model that sustains these criminal syndicates, effectively starving them of the capital needed for further research and development of malware.
Targeting the Vulnerable
Modern ransomware campaigns have moved beyond indiscriminate "spray and pray" tactics. Hackers are increasingly meticulous, focusing their efforts on small and medium-sized enterprises (SMEs) that often lack the robust cybersecurity infrastructure of larger corporations. These entities are viewed as "low-hanging fruit" because they often lack the resources to withstand prolonged downtime, making them more likely to acquiesce to ransom demands to ensure business continuity.
The Evolution of Cyber Threats
As we move into 2026, the ransomware ecosystem has transformed into a highly sophisticated industry. Attackers are now employing advanced encryption techniques and data exfiltration strategies that force organizations to deal with both operational paralysis and the threat of public data leakage. This dual-extortion method makes the decision to pay increasingly complex, as a payment no longer guarantees that sensitive information will not be sold or published on the dark web.
Broader Economic and Security Implications
Banning payments is not without controversy. Critics argue that such prohibitions might leave organizations with no recourse if backups are compromised, potentially leading to the permanent loss of critical data or the collapse of essential services. However, proponents suggest that such bans are the only way to break the "ransomware feedback loop." The goal is to force a systemic shift where organizations prioritize proactive defense and data resilience over reactive, high-risk financial settlements.
Future Trends and Resilience
Looking forward, the success of these legislative bans will depend on how effectively governments can support the private sector in improving their security posture. Without government grants, technical assistance, or improved insurance policies, businesses may find themselves in a precarious position. The future of cybersecurity will likely hinge on whether nations can successfully transition from a culture of paying for recovery to one of investing in absolute systemic resilience.