Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers

Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers

Ransomware: Over Half of CISOs Would Consider Paying Ransom to Hackers

https://www.infosecurity-magazine.com/news/ransomware-over-half-cisos-would/

Publish Date: 2026-05-24 01:55:38

Source Domain: www.infosecurity-magazine.com

Summary of the Article

According to a report published by Absolute Security, a majority of cybersecurity leaders—specifically 58% of Chief Information Security Officers (CISOs)—would consider paying cybercriminals’ demands in the event of a ransomware attack. The research revealed a distinction in attitudes towards ransom payment between US and UK CISOs, with 63% of the former being more open to the idea compared to just 47% of their UK counterparts. Factors influencing the UK’s reluctance include the lack of supportive legal frameworks, complexities introduced by GDPR regarding data theft, and doubts about data recovery even after paying the ransom. The survey indicated that operational downtime would have the greatest impact on an organization in a ransomware attack, with other significant concerns being data loss, reputation damage, financial losses, and regulatory penalties. Although 83% of CISOs expressed confidence in their ability to recover quickly from such incidents, many faced substantial delays in system restoration post-attack, with nearly a third taking a week or more. The disconnect between confidence and actual recovery time underscores the “defining ransomware challenge” of the era. Absolute Security emphasizes the need for organizations to build resilient systems to absorb disruption and recover swiftly, stressing that those lacking such infrastructure may fall prey to increasingly sophisticated attacks.

Key Points:

  • 58% of CISOs would consider paying a ransomware demand.
  • US CISOs are more likely to pay than UK CISOs (63% vs. 47%).
  • Legal and GDPR complexities reduce ransom payment willingness in the UK.
  • Operational downtime is the most significant concern in ransomware attacks.
  • Confidence in quick recovery (83%) doesn’t match actual restoration times, pointing to a critical gap.