The bottom line: Without isolated, immutable and strictly controlled backups, 84.5 percent of attacked companies do not pay ransom and still recover, while paying companies fail 8–33 percent of the time and face additional insurance and sanctions risks.
Although ransomware has long been a routine matter in boardrooms, the majority of companies lack the technical foundation to become operational after an attack without paying ransom. A study by HYCU and ActualTech Media shows: payments are not only expensive, but also unsafe.
Giving in to ransom demands does not reliably buy back normal operations. Of the companies that settle the first demand, 60 percent initially regain access to their data. However, one-third must pay a second time before recovery is even possible, and in 8 percent of cases access remains blocked despite payment. Even when a decryption key is provided, the technical rebuild of systems typically takes several weeks.
Beyond the pure ransom amount, substantial financial and legal risks emerge. Cyber insurance policies frequently exclude such payments from coverage, while premiums in the US have already risen on average by around 35 percent. The US Department of the Treasury warns that payments to sanctioned perpetrator groups can be penalized by the OFAC authority regardless of intent. Additionally, companies that have paid once are regarded in criminal circles as willing payers and are reportedly targeted again more frequently than average, sometimes by the same group.
The reassuring counterpoint: Globally, 84.5 percent of affected companies have recovered without any ransom payment whatsoever. The necessary prerequisite is a backup that meets three conditions. First, it must reside on immutable storage — specifically WORM storage (Write Once, Read Many) on S3-compatible object storage with Object Lock enabled. Delete commands cannot technically be executed there before a defined deadline, not even with stolen administrator credentials. Second, the backup environment must be isolated from the production environment: through network segmentation, without shared credentials, without shared services, and without trust relationships. Third, restricted access is required via role-based controls and separation of duties, so that even authorized superadministrators cannot manually delete backups.
Here the gap becomes apparent: 65 percent of IT decision-makers surveyed lack full confidence in their existing backup solutions. Of companies that have experienced an attack, 52 percent report measurable data loss and 63 percent report operational disruptions. Implementation of the three core principles is sparse: only 41 percent back up their backups in isolation, only 47 percent test them regularly, and only 35 percent consider their current tools adequately adapted to their own environment. While 77 percent of corporate boards actively participate in prevention discussions — technical implementation lags behind this level of attention.
Source: www.it-daily.net · Published 14 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.