Agentic Research

Read these first

This article assumes the following earlier in its learning path.

The Economics of Ransomware: Why It Persists and How to Make It Unprofitable

2026/10/1114 min readBryan Chan閱讀中文原文
TopicsRansomwareRisk ManagementBusiness ContinuityDefense StrategyEconomics

Core premise: treating ransomware as a "technical attack" keeps you permanently behind. Treat it as a business, and the question becomes: how do we make this business unprofitable for the attacker? Angle: economics and risk. No operational detail.

The economic structure of ransomware

Why it persists

One simple fact: as long as expected revenue exceeds expected cost, someone will keep doing it.

The attacker's cost structure is roughly:

Cost itemDescription
Tools and infrastructureOff-the-shelf tooling can be bought or rented (even "ransomware as a service")
LabourParts of the chain are outsourced and specialised
TimeIntrusion to encryption can take only days
RiskBeing traced, prosecuted, or retaliated against

On the revenue side: one successful extortion can cover the cost of hundreds of failures.

Three factors that make it "worth it"

Factor one: payment rates remain high

As long as some proportion of victims pay, expected revenue holds. More importantly: payment generates data — proof that the business works, attracting more entrants.

Factor two: defenders rarely rehearse

Many enterprises have backups but have never rehearsed "every system encrypted at once" recovery. When it happens, they discover the backups missed critical systems, recovery takes two weeks, and the business can only be down for three days.

Factor three: attackers have industrialised

Modern ransomware is not "one hacker": some specialise in initial access, others in negotiation, others in money laundering. Division of labour brings efficiency; efficiency brings scale.

The economics of defence: three levers

To make the business unprofitable, there are only three directions.

Lever one: raise the cost of attack

  • Hardening and segmentation: prevent a single sweep across all systems;
  • Credential isolation: the most critical link in the chain (see Credentials and AD Concepts);
  • Multi-factor authentication: closes the "one password opens everything" path.

Lever two: reduce your loss (= reduce their bargaining power)

  • Backups must be recoverable, not merely present: offline copies, regular verification, measured recovery time;
  • Business continuity plan: which systems come back first, how long you can be down;
  • Rehearsal: at least one full tabletop and one technical recovery drill per year.

Key insight: the attacker's bargaining power equals "your hourly downtime cost × expected downtime". The faster you recover, the weaker their hand.

Lever three: lower the attacker's expected return

  • Do not encourage payment: clear policy, consistent public stance;
  • Insurance and regulatory pressure: make "paying to make it go away" costly;
  • Reporting and collaboration: share intelligence with law enforcement and peers to raise their risk.

Three common misconceptions

"We are too small to be targeted." Automated scanning does not care about size, only about opportunity. SMEs are often "low cost, certain return" targets.

"We have backups, so we are fine." Backups solve for data; ransomware targets business interruption. The goal is often not stealing data but stopping you operating.

"Paying ends it." Paying can mean being flagged as a payer and hit again, data still published, or no working decryptor at all.

A practical checklist

Recovery capability

  • Are backups offline/immutable? When were they last verified?
  • How long does recovering critical systems take? Have you measured it?
  • If 80% of servers were lost simultaneously, how would the business run?

Cost of attack

  • Are privileged credentials isolated? Is MFA enforced?
  • Is the network segmented enough to prevent a single sweep?

Decision readiness

  • Have you pre-decided when to pay and when not to?
  • Who has authority? What are the disclosure obligations?
  • Are lawyer, insurer, and law-enforcement contacts already established?

Three one-liners

  1. Ransomware is a business, not a technique. Only economic logic can defeat it.
  2. Recovery speed is bargaining power. The faster you recover, the weaker their hand.
  3. Rehearsal matters more than backups. An untested recovery plan is no plan.

Next steps

  • For how attackers obtain credentials, read credentials and AD concepts
  • For supply-chain risk, read supply chain and third-party risk
  • For a red-team view of defence, read defense lessons from a red-team postmortem

Next on this path