CYBERATTACKS - The Ransomware Dilemma
MIT Sloan Management Review|Summer 2022
The decision on whether to pay up when cybercriminals hold data hostage is shaped by choices leaders made long before an attack.
PHILIPP LEO, ÖYKÜ IŞIK, AND FABIAN MUHLY
CYBERATTACKS - The Ransomware Dilemma

The ransomware business is booming: In the United States alone, this form of cyberattack increased in frequency by 200% between 2019 and 2021. It’s an urgent threat, but too many leaders are caught flat-footed when it happens to them. Ransomware is malicious software that uses encryption to prevent access to data on the infected machine, effectively paralyzing the computer system. The culprits behind the attack then demand payment in exchange for decrypting the files and restoring access to the infected systems. The tactic dates to the 1980s, but it became a prominent threat to businesses after 2010 with the rise of cryptocurrency, criminals’ preferred mode of payment.

It’s a threat riddled with uncertainties, which makes planning a response difficult. Many organizations just want to find the quickest way out, and that often means paying the ransom, even though the financial burden may be considerable and the outcome far from certain. In a recent study of 300 companies, 64% revealed that they had experienced a ransomware attack within the previous 12 months, and a staggering 83% of those paid the ransom. On average, only 8% of organizations that paid up recovered all of their data, while 63% got about half of it back.

Some organizations receive a demand for a second (and perhaps even higher) ransom, despite having paid the first one on time, but the worst-case scenario is when the victim pays but either never receives the decryption key or it doesn’t work as intended.1

Organizations that decide not to pay also bear costs in terms of business downtime and lost revenues. And organizations that are caught unprepared, without a reliable backup system or an incident response plan, end up suffering the most — not only financially but also reputationally.

Esta historia es de la edición Summer 2022 de MIT Sloan Management Review.

Comience su prueba gratuita de Magzter GOLD de 7 días para acceder a miles de historias premium seleccionadas y a más de 9,000 revistas y periódicos.

Esta historia es de la edición Summer 2022 de MIT Sloan Management Review.

Comience su prueba gratuita de Magzter GOLD de 7 días para acceder a miles de historias premium seleccionadas y a más de 9,000 revistas y periódicos.

MÁS HISTORIAS DE MIT SLOAN MANAGEMENT REVIEWVer todo
Ask Sanyin: How Do You Build for an Unpredictable Future?
MIT Sloan Management Review

Ask Sanyin: How Do You Build for an Unpredictable Future?

While the pandemic was a wild ride of uncertainty for me and many of my peers in leadership, it feels like we never regained our footing.

time-read
2 minutos  |
Winter 2025
What You Still Can't Say at Work
MIT Sloan Management Review

What You Still Can't Say at Work

Most people know what can’t be said in their organization. But leaders can apply these techniques to break through the unwritten rules that make people self-censor.

time-read
7 minutos  |
Winter 2025
Make Character Count in Hiring and Promoting
MIT Sloan Management Review

Make Character Count in Hiring and Promoting

Most managers focus on competencies when evaluating candidates but it’s character that will transform the DNA of the organization. Here’s how to assess it.

time-read
10+ minutos  |
Winter 2025
Why Influence Is a Two-Way Street
MIT Sloan Management Review

Why Influence Is a Two-Way Street

Managers achieve better outcomes when they prioritize collaborative decision-making over powers of persuasion.

time-read
10 minutos  |
Winter 2025
Know Your Data to Harness Federated Machine Learning
MIT Sloan Management Review

Know Your Data to Harness Federated Machine Learning

A collaborative approach to training AI models can yield better results, but it requires finding partners with data that complements your own.

time-read
9 minutos  |
Winter 2025
How Integrating DEI Into Strategy Lifts Performance
MIT Sloan Management Review

How Integrating DEI Into Strategy Lifts Performance

Incorporating diversity, equity, and inclusion practices into core business planning can provide a competitive edge.

time-read
9 minutos  |
Winter 2025
The Myth of the Sustainable Consumer
MIT Sloan Management Review

The Myth of the Sustainable Consumer

Companies that understand the different kinds of consumers for sustainable products can market to them more effectively.

time-read
10+ minutos  |
Winter 2025
A Practical Guide to Gaining Value From LLMs
MIT Sloan Management Review

A Practical Guide to Gaining Value From LLMs

Getting a return from generative AI investments requires a systematic approach to analyzing appropriate use cases.

time-read
10+ minutos  |
Winter 2025
Improve Workflows by Managing Bottlenecks
MIT Sloan Management Review

Improve Workflows by Managing Bottlenecks

Understand whether process or resource constraints are stalling work.

time-read
10+ minutos  |
Winter 2025
Craft Schedules That Work for Everyone
MIT Sloan Management Review

Craft Schedules That Work for Everyone

Business leaders can improve retention and business performance with schedules that make sense for workers’ lives.

time-read
10+ minutos  |
Winter 2025