You cannot negotiate your way out of ransomware problems

Research into 461 ransomware incidents and 237 negotiations shows that technical resilience is more important than negotiation tactics.

Victims with fully recoverable backups negotiate and pay significantly less often. In only 18.3% of incidents without communication was a payment made, compared to 66.7% when victims actually started negotiating.

An offered discount increases the chance of payment, but the size of that discount does not appear to be decisive in itself. Longer negotiations more often lead to discounts, but at the same time appear to be associated with a lower chance of payment.

Professional incident response companies also increase the chance of a discount, but not demonstrably the chance that payment will ultimately be made.

Cyber insurance also does not appear to be a direct predictor of payment, contradicting a frequently heard assumption.

Moreover, paying offers no guarantee: 2.5% did not receive a decryption key, 6.7% experienced problems or delays, and in 7.6% of cases, new negotiations followed.

The most important defense strategy therefore lies before the attack. Therefore, invest primarily in reliable, genuinely recoverable backups and recovery processes.