Reporting shows companies are still paying ransomware demands despite official advice against it. Paying funds further crime, offers no guarantee of recovery, and marks you as a willing target — yet under pressure, many feel they have no other option.

What it means for you

That sense of having no choice usually traces back to one thing: no reliable, tested way to restore. When backups are missing, out of date or also encrypted, paying can feel like the only path back to operating.

The way to never face that decision is preparation: segregated, tested backups you know you can restore from, plus monitoring to catch ransomware before it spreads. We build that recoverability in so a ransom demand becomes a decision you don’t have to make.

Why organisations still pay

Almost nobody pays a ransom by choice. It happens under intense pressure, when systems are down, customers are waiting, and there appears to be no faster way back to operating. That sense of having no option nearly always traces to a single failure: no reliable, tested way to restore. When backups are missing, out of date, or encrypted along with everything else, paying can feel like the only route back — even though it funds further crime, offers no guarantee of recovery, marks you as a willing payer, and increasingly carries legal and sanctions risk.

Removing the need to pay

The way never to face that decision is to prepare before it arises. Keep segregated, immutable or offline backups and — the part organisations skip — test that they actually restore, so recoverability is a fact rather than a hope. Add monitoring to catch ransomware early, before it spreads, and a rehearsed plan so everyone knows their role. With the UK moving to ban ransom payments across parts of the public sector, being demonstrably recoverable matters more than ever. We build that recoverability in, so a ransom demand becomes a decision you simply do not have to make.

Source: ITPro, 23 July 2026.