Brought to you by:

More ransomware victims refuse payment demands

Most Australian organisations hit by ransomware attacks have refused to meet extortion payment demands, according to a Howden report.

Only 4% of cases over the past two and a half years involved ransoms being paid, down from about 15% in 2023, the broker’s Pacific half-year cyber report says, citing analysis from law firm Wotton Kearney.

“While ransom payments attract most of the headlines, the reality on the ground in Australia is that most organisations are choosing not to pay … as organisations get better at preparing for and responding to incidents,” the report said.

A couple of factors are driving down such payments, according to the paper.

Firstly, paying a ransom is not a mitigating factor in Australia. Organisations must still meet their legal, regulatory and notification obligations.

Related article: Cyber ‘at crossroads’ as demand climbs, prices fall

Secondly, specialist negotiators report that paying does not reliably prevent data being sold or published, making “data-suppression” payments an unattractive proposition.

“The focus has shifted decisively toward preparation: containing the incident with the right specialist vendors, recovering from safe and reliable back-ups, and having business continuity plans that keep the organisation running until normal operations resume.”

Howden says that despite a drop in cyber insurance premium rates for a fourth straight year, “the market is not oversupplied for the risks that exist.

“It is oversupplied for the risks it has learnt to price, and chronically undersupplied for the ones it has not – autonomous AI-enabled attacks, systemic single vendor concentration, and long-tail data theft liability among them.”

See the report here.