Cyber extortion (commonly referred to as ransomware) has been around for a while now. However, lately it is received a lot more attention, primarily due to the fact that this time it is much more successful.
Recently, ThreatTrack had a blind survey conducted of 250 U.S. mid-market (500 to 2,500 employees) security professionals. The survey revealed that 70 percent of those surveyed stated they would refuse to negotiate; and a surprising 30 percent acknowledged that they would be willing to negotiate with cyber extortionists. Critical infrastructure organizations in healthcare and financial services are among the top targets.
I asked one CISO at a critical infrastructure provider about his thoughts on these stats. He said, “Look, it is just business.” If the cost to recover the stolen/encrypted data is more than the cost to pay the demanded ransom, it makes business sense to pay the ransom, he explained.
Last week an article was passed out at a briefing I attended about this cyber extortion. In that article it revealed that one law enforcement organization had been targeted and actually paid the ransom! This sparked a very intense conversation about those being compliant with the cyber extortionists demands will or is promoting an increase in these events.
What was truly shocking is that in this conversation and as part of the study identified above, the majority of individuals asked felt the government should set policies that cover this growing criminal issue. It is not often that the private sector and cyber security professionals are in favor of more regulations.
Cyber extortion is often ranked in the top 5 types of cyber crimes. Clearly, this is a matter that every organization should investigate and like most risks, answer on a case by case basis.




