Read these first
This article assumes the following earlier in its learning path.
The Economics of Ransomware: Why It Persists and How to Make It Unprofitable
Core premise: treating ransomware as a "technical attack" keeps you permanently behind. Treat it as a business, and the question becomes: how do we make this business unprofitable for the attacker? Angle: economics and risk. No operational detail.
Why it persists
One simple fact: as long as expected revenue exceeds expected cost, someone will keep doing it.
The attacker's cost structure is roughly:
| Cost item | Description |
|---|---|
| Tools and infrastructure | Off-the-shelf tooling can be bought or rented (even "ransomware as a service") |
| Labour | Parts of the chain are outsourced and specialised |
| Time | Intrusion to encryption can take only days |
| Risk | Being traced, prosecuted, or retaliated against |
On the revenue side: one successful extortion can cover the cost of hundreds of failures.
Three factors that make it "worth it"
Factor one: payment rates remain high
As long as some proportion of victims pay, expected revenue holds. More importantly: payment generates data — proof that the business works, attracting more entrants.
Factor two: defenders rarely rehearse
Many enterprises have backups but have never rehearsed "every system encrypted at once" recovery. When it happens, they discover the backups missed critical systems, recovery takes two weeks, and the business can only be down for three days.
Factor three: attackers have industrialised
Modern ransomware is not "one hacker": some specialise in initial access, others in negotiation, others in money laundering. Division of labour brings efficiency; efficiency brings scale.
The economics of defence: three levers
To make the business unprofitable, there are only three directions.
Lever one: raise the cost of attack
- Hardening and segmentation: prevent a single sweep across all systems;
- Credential isolation: the most critical link in the chain (see Credentials and AD Concepts);
- Multi-factor authentication: closes the "one password opens everything" path.
Lever two: reduce your loss (= reduce their bargaining power)
- Backups must be recoverable, not merely present: offline copies, regular verification, measured recovery time;
- Business continuity plan: which systems come back first, how long you can be down;
- Rehearsal: at least one full tabletop and one technical recovery drill per year.
Key insight: the attacker's bargaining power equals "your hourly downtime cost × expected downtime". The faster you recover, the weaker their hand.
Lever three: lower the attacker's expected return
- Do not encourage payment: clear policy, consistent public stance;
- Insurance and regulatory pressure: make "paying to make it go away" costly;
- Reporting and collaboration: share intelligence with law enforcement and peers to raise their risk.
Three common misconceptions
"We are too small to be targeted." Automated scanning does not care about size, only about opportunity. SMEs are often "low cost, certain return" targets.
"We have backups, so we are fine." Backups solve for data; ransomware targets business interruption. The goal is often not stealing data but stopping you operating.
"Paying ends it." Paying can mean being flagged as a payer and hit again, data still published, or no working decryptor at all.
A practical checklist
Recovery capability
- Are backups offline/immutable? When were they last verified?
- How long does recovering critical systems take? Have you measured it?
- If 80% of servers were lost simultaneously, how would the business run?
Cost of attack
- Are privileged credentials isolated? Is MFA enforced?
- Is the network segmented enough to prevent a single sweep?
Decision readiness
- Have you pre-decided when to pay and when not to?
- Who has authority? What are the disclosure obligations?
- Are lawyer, insurer, and law-enforcement contacts already established?
Three one-liners
- Ransomware is a business, not a technique. Only economic logic can defeat it.
- Recovery speed is bargaining power. The faster you recover, the weaker their hand.
- Rehearsal matters more than backups. An untested recovery plan is no plan.
Next steps
- For how attackers obtain credentials, read credentials and AD concepts
- For supply-chain risk, read supply chain and third-party risk
- For a red-team view of defence, read defense lessons from a red-team postmortem
Next on this path
More in Evidence
- Tunnel Techniques Explained: When an AI Agent Needs to Pave a Road into the Internal Network
- Agentic Attack Tooling Research Series: A Guide to All Fourteen Parts
- AI Supply Chain Poisoning: When the Risk Hides in Models, Data, and Tools
- When AI Learns to Pentest: The ARTEX Case and the Rise of Agentic Attack Tooling