Ransomware economics and response decisions
By the end of this module you will be able to:
- Describe how the ransomware extortion model changed between 2024 and 2026, and why the asset at risk moved from availability to confidentiality
- Read the payment statistics correctly, including what a falling payment rate does and does not tell you
- Walk a ransom payment decision through its legal, sanctions, insurance and evidence dimensions as a pre-agreed procedure
- State the UK policy direction precisely, including the 22 July 2025 Government response
- Brief an executive on why backups no longer end the ransomware conversation
22 July 2025: the UK commits to banning ransom payments across the public sector and critical infrastructure
On 22 July 2025 the UK Government published its response to a consultation that ran from January to April 2025. It committed to three measures: a targeted ban on ransom payments by public sector bodies and operators of critical national infrastructure, a payment prevention regime requiring any other organisation to engage the authorities before paying, and mandatory incident reporting. It is the first national payment ban commitment of its kind.
Read it through the eyes of an NHS trust. Until 2025 a trust hit by ransomware could, in extremis, treat payment as a last resort while it rebuilt. Under the announced regime that door is closing: a public body may not pay at all. The incident playbook can no longer contain a page headed “if all else fails, negotiate”. The plan has to be that the trust restores itself, because the option of buying its way out is being removed by law rather than by choice.
That single policy shift is why this module treats ransomware as an economics and decision problem, not a malware problem. The encryption is the easy part to understand. The hard part is the sequence of decisions a board faces when its data is already gone and paying is either unlawful, uninsured, or simply no guarantee of getting anything back.
1. From encrypting data to exposing it
For most of its history, ransomware was an availability attack. The criminals encrypted your files and sold you the key. An organisation with good backups could refuse to pay, restore, and move on. That world is gone. Attackers watched victims recover from backups and changed the model so that recovery no longer buys silence.
The first change was : steal a copy of the data before encrypting it, then threaten to publish it unless paid. A restored backup does nothing about the stolen copy, so the threat survives your recovery. Groups then added a third and a fourth form of pressure: denial-of-service attacks to knock you offline during negotiations, and direct harassment of your customers, patients or staff whose records were taken. The newest variant drops encryption entirely. An attack never locks a single file. The criminals quietly exfiltrate the data and go straight to the threat to leak, because that is the part that actually pays.
The evidence backs the shift. ENISA’s Threat Landscape 2025 records that around 77 per cent of 2025 ransomware attacks involved data exfiltration. The asset genuinely at risk moved from availability, which backups protect, to confidentiality, which they do not. The control set has to move with it: data minimisation so there is less to steal, encryption at rest so a stolen copy is harder to read, and detection tuned to catch data leaving the building rather than only catching files being locked. The figure below traces the five stages and, at each one, the answer that actually addresses the pressure being applied.
Common misconception
“Ransomware is an encryption problem, and good backups solve it.”
Backups defeat the encryption, but they do nothing about the stolen copy. With exfiltration now present in roughly three-quarters of attacks, and extortion-only attacks that never encrypt anything, a perfect restore still leaves the criminals holding your data and their threat to publish it. Backups remain essential for recovery, but they are one control among several, not the answer to the modern extortion model.
2. The payment market is collapsing while payouts grow
The headline statistic is that far fewer victims pay. The incident response firm Coveware reports that about 23 per cent of victims paid in the third quarter of 2025, down from around 85 per cent in 2019. Refusing to pay is now the statistical norm, which changes the negotiation itself: the criminals know most targets will walk away, so their opening demands and their willingness to bluff both shift.
Two numbers have to be read together, or you will draw the wrong conclusion. Chainalysis, which traces payments across the public blockchain, found that total ransom payments fell by about 35 per cent to roughly 813 million US dollars in 2024. Fewer victims paying pushed the total down. Yet the payments that still happen are concentrating into larger sums aimed at organisations that cannot tolerate downtime and have the means to pay. A falling payment rate does not mean ransomware is becoming less profitable per successful extortion; it means the criminals are being more selective about whom they squeeze.
The supplier side fragmented too. After the international takedowns of LockBit in early 2024 and ALPHV, the market did not shrink so much as splinter, with around 85 active groups counted by the third quarter of 2025. Enforcement disrupts brands and reputations, which matters, but it does not remove the underlying economics. As long as stolen data has value and some victims can be pressured into paying, new affiliates assemble around whatever tooling is available.
3. The decision nobody wants
When an extortion demand lands, an organisation faces a decision it never wanted, under time pressure, with incomplete information. The single worst way to take it is to open the debate on the night of the incident. The decision should already exist as a written procedure, agreed in calm conditions, that a named authority walks through. Treat it as a sequence of gates, each of which can stop a payment on its own.
The first gate is legality. Paying a group that is a designated entity can itself be a criminal offence. In the UK the Office of Financial Sanctions Implementation enforces financial sanctions, so exposure, alongside the United States Office of Foreign Assets Control for any dollar-denominated payment, has to be checked before anything moves. This is the module’s core idea of : the risk that the recipient of a ransom is a sanctioned party, which turns a commercial decision into a legal one. The second gate is insurer consent. A policy that would fund a payment almost always requires the insurer to approve it first; paying without that written approval can void the cover you were relying on. The remaining gates test the value of paying at all: will a decryptor actually restore service at production scale, what evidence exists that stolen data will genuinely be deleted rather than resold, and has the one named board authority signed the decision off. Payment guarantees neither recovery nor deletion, so both must be argued on evidence, not hope.
Every gate also names who must be told when it fails, because the failure is itself information that other people need: legal, the insurer, the recovery lead, the data protection officer, the board. Drawing the decision this way turns a panicked argument into a checklist that can be rehearsed in a tabletop exercise long before it is needed.
Common misconception
“If we pay, we get our data back and the stolen copy is deleted.”
Payment buys a promise from a criminal, nothing more. Some decryptors work poorly or corrupt data at scale, so a purchased key is not a tested restore. Deletion is unverifiable: there is no way to confirm that every copy of exfiltrated data has been destroyed, and stolen datasets have been re-extorted or resold after payment. Both the recovery-evidence gate and the deletion-evidence gate exist because the promise on offer cannot be trusted.
4. The UK is legislating, so resilience becomes the plan
The 22 July 2025 Government response set a direction that changes the whole calculation for regulated bodies. The targeted ban removes payment as an option for the public sector and critical national infrastructure operators. The payment prevention regime requires other organisations to notify and engage the authorities before any payment, so even where paying remains lawful it is no longer a private commercial choice made quietly. Mandatory incident reporting means the state gains visibility of attacks that were previously settled in silence.
For a critical infrastructure operator the practical effect is stark. The question at the board table moves from “would we pay?” to “we may not pay”. Once payment is off the table, the only plan that survives contact with a serious attack is the ability to restore and keep operating without the criminals’ cooperation. That is why the next module treats resilience and recovery as a first-class capability rather than a storage-administration afterthought: the law is making resilience the whole answer, not the fallback.
None of this ends the exfiltration threat. Even a body that restores perfectly still has to manage the leak of whatever was stolen, with its data protection, regulatory notification and communications duties intact. The policy shift does not make ransomware easier. It removes the escape hatch that let organisations avoid building the resilience they needed all along.
A mid-sized UK water utility is hit by extortion-only ransomware: no files are encrypted, but the attackers have exfiltrated operational and customer data and are demanding payment to prevent publication. The incident lead asks whether the organisation should pay. Which single fact most decisively changes the decision, and which gate does it fail?
A board is told that the industry-wide ransom payment rate has fallen to roughly 23 per cent while the total value of payments dropped about 35 per cent in a year. A director concludes that ransomware is becoming a smaller commercial risk to the company. Why is that conclusion unsafe?
Core distinctions
- Ransomware has shifted from an availability attack to a confidentiality attack. Double, triple and extortion-only models mean a clean restore no longer defuses the threat, because the stolen copy survives your recovery.
- Around 77 per cent of 2025 attacks involved data exfiltration (ENISA). The controls that answer this are data minimisation, encryption at rest, and detection tuned to catch data leaving, not only files being locked.
- Payment statistics must be read together: roughly 23 per cent of victims paid in Q3 2025 (Coveware, down from about 85 per cent in 2019) and total payments fell about 35 per cent to around 813 million dollars in 2024 (Chainalysis), yet the payments that remain are concentrating into larger, more targeted sums.
- The ransom payment decision is five gates decided in advance: legality and sanctions (OFSI and OFAC), insurer consent, recovery evidence, deletion evidence, and board authority. Any gate can stop the payment, and each failure names who must be told.
- The UK Government response of 22 July 2025 commits to a targeted payment ban for the public sector and critical national infrastructure, a payment prevention regime, and mandatory reporting. Where payment is barred, resilience and recovery become the entire plan.
Standards and sources cited in this module
UK Government response to the ransomware legislative proposals (22 July 2025)
The primary source for the targeted payment ban, the payment prevention regime and mandatory incident reporting. Read the scope carefully: the ban is targeted at the public sector and CNI operators, not universal.
EU incident-population evidence base, including the finding that around 77 per cent of 2025 ransomware attacks involved data exfiltration. Note it counts incidents, not breaches, so the denominator differs from DBIR.
Coveware quarterly ransomware payment reporting (Q3 2025)
Source for the roughly 23 per cent payment rate in Q3 2025, down from about 85 per cent in 2019, and for the count of active groups after the LockBit and ALPHV takedowns.
The evolving economics of ransomware (Morphisec analysis of Chainalysis data)
Explains the fewer-payments-bigger-payouts pattern behind the Chainalysis finding that total payments fell about 35 per cent to roughly 813 million dollars in 2024.