• Advertise
  • Contact Us
  • Supplier Directory
  • SCB YouTube
  • About Us
  • Login
  • Subscribe
  • Logout
  • My Profile
  • LOGISTICS
    • Air Cargo
    • All Logistics
    • Facility Location Planning
    • Freight Forwarding/Customs Brokerage
    • Global Gateways
    • Global Logistics
    • Last Mile Delivery
    • Logistics Outsourcing
    • LTL/Truckload Services
    • Ocean Transportation
    • Parcel & Express
    • Rail & Intermodal
    • Reverse Logistics
    • Service Parts Management
    • Transportation & Distribution
  • TECHNOLOGY
    • All Technology
    • Artificial Intelligence
    • Cloud & On-Demand Systems
    • Data Management (Big Data/IoT/Blockchain)
    • ERP & Enterprise Systems
    • Forecasting & Demand Planning
    • Global Trade Management
    • Inventory Planning/ Optimization
    • Product Lifecycle Management
    • Robotics
    • Sales & Operations Planning
    • SC Finance & Revenue Management
    • SC Planning & Optimization
    • Supply Chain Visibility
    • Transportation Management
  • GENERAL SCM
    • Business Strategy Alignment
    • Customer Relationship Management
    • Education & Professional Development
    • Global Supply Chain Management
    • Global Trade & Economics
    • Green Energy
    • HR & Labor Management
    • Quality & Metrics
    • Regulation & Compliance
    • Sourcing/Procurement/SRM
    • SC Security & Risk Mgmt
    • Supply Chains in Crisis
    • Sustainability & Corporate Social Responsibility
  • WAREHOUSING
    • All Warehouse Services
    • Conveyors & Sortation
    • Lift Trucks & AGVs
    • Order Management & Fulfillment
    • Packaging
    • RFID, Barcode, Mobility & Voice
    • Warehouse Automation
    • Warehouse Management Systems
  • INDUSTRIES
    • Aerospace & Defense
    • Apparel
    • Automotive
    • Chemicals & Energy
    • Consumer Packaged Goods
    • E-Commerce/Omni-Channel
    • Food & Beverage
    • Healthcare
    • High-Tech/Electronics
    • Industrial Manufacturing
    • Pharmaceutical/Biotech
    • Retail
  • THINK TANK
  • WEBINARS
    • On-Demand Webinars
    • Upcoming Webinars
    • Webinar Library
  • PODCASTS
  • WHITEPAPERS
  • VIDEOS
Home » Is a ‘No-Concessions’ Policy the Right Response to Ransomware Attacks?
SCB FEATURE

Is a ‘No-Concessions’ Policy the Right Response to Ransomware Attacks?

AN OFFICE WORKER HOLDS HER HEAD IN HER HANDS IN FRONT OF 3 SCREENS THAT ALL BEAR THE MESSAGE: YOUR PERSONA FILES ARE ENCRYPTED

Photo: iStock/AndreyPopov

August 19, 2024
Robert J. Bowman, SupplyChainBrain

Whether to pay ransom to kidnappers is a hotly contested question. Failure to do so endangers the lives of hostages. But it might also discourage future kidnappings. What to do?

A similar debate is raging around the subject of ransomware attacks on organizations. Should victims pay to recover their private data? Or does giving in to ransom demands encourage criminals to double down on the practice?

The FBI, for one, discourages payment. Doing so “may embolden adversaries to target additional organizations, encourage other criminal actors to engage in the distribution of ransomware and/or fund illicit activities,” the agency says. “Paying the ransom also does not guarantee that a victim’s files will be recovered.”

In addition, the payment of ransom might expose victims to sanctions. According to the U.S. Treasury Department, “In the U.S., while there is no outright law that makes paying ransomware demands illegal, there are in fact significant legal and financial risks associated with making such payments.”

So: Is a “no-concessions” policy a sensible response to a ransomware attack? Most victims don’t have the nerve to try it. But it’s an option in cases where the targeted person or organization has safely backed up their files, says Chris Denbigh-White, chief security officer with Next DLP, provider of a data-protection software platform. Then it’s more a matter of inconvenience than permanent and devastating loss of data. (There remains the possibility of damage to reputation, though, if the exposed information is especially sensitive or embarrassing.)

The nature and intent of ransom attacks is changing, Denbigh-White says. In their early form, they often involved blocking access to essential data, then offering a “key” to unlocking it upon receipt of payment. These days, however, attacks may also involve the outright theft of data, for purposes other than pure profit.

“The real threat,” says Denbigh-White, “is that I have all your sensitive data and I’m going to leak it over the internet.” Victims could then become subject to penalties for violating consumer data-privacy laws, such as the European Union’s General Data Protection Regulation (GDPR), as well as lawsuits by private individuals.

It's a high price to pay, no matter how the victim chooses to react. Denbigh-White acknowledges the logic of denying criminals a reward for their actions. But that’s “logical in a vacuum,” he says. “Anybody with a grasp of what the world is like isn’t being practical in the short run. When criminals’ revenue streams are threatened, they don’t simply pack up and get jobs at Walmart. What they tend to do is intensify their efforts and get more nasty.”

In theory, businesses and individuals at a higher risk of loss could ask regulators for a disclaimer that shields them from the punitive consequences of paying ransom. Again, says Denbigh-White, that might seem logical on the surface. “But all it does is paint a target on industries known to have the ability to pay ransom.”

The better approach lies in adopting effective measures that prevent bad actors from penetrating systems in the first place. “Rather than making ransom payments illegal,” Denbigh-White says, “we need to create a digital safe working environment for all companies to operate in.” And while that may be of little value to entities under attack, it’s a solid strategy for addressing the problem in the longer run.

“It starts with the basics,” he says. The means of repulsing most types of cyber-attack are generally available today. They include applying multi-factor authentication of systems and people, ensuring that employees remain vigilant about not clicking on suspicious messages or bringing to work unprotected personal devices, and undertaking regular updates and patching of security software. And, of course, there’s no lack of cybersecurity experts who stand ready to advise on the most effective measures for preventing all types of attacks.

Why, then, do so many organizations remain susceptible to cyberattack? Why won’t they take the necessary and obvious steps to shore up their systems? “These things are fundamental and basic,” explains Denbigh-White, “but they’re difficult and not interesting to do.” That’s especially the case with a multinational concern employing thousands around the globe and a host of legacy IT systems.

“People tend to conflate fundamental with easy,” Denbigh-White says, “and it’s certainly not easy.” He likens the problem to individuals who know that regular exercise and a good diet will help them to live longer, but fail to adopt those measures.

Denbigh-White nevertheless believes businesses are waking up to the need to embrace effective cybersecurity practices. They’re motivated in part by the adoption of strict consumer-privacy regulations such as GDPR. And, thanks to a raft of news stories, they’re fully aware of the nightmare that ensues when a business comes under attack from ransomware.

All of that “has brought the conversation to a head,” Denbigh-White says. “I’m quietly confident that we are slowly moving in the right direction.”

    RELATED CONTENT

    RELATED VIDEOS

    Regulation & Compliance Supply Chain Security & Risk Mgmt
    • Related Articles

      Cyber Insurance Is Back From the Brink After Onslaught of Ransomware Attacks

      RaaS: Ransomware Attacks on the Supply Chain Made Easy

      Ransomware Attacks on the Rise: How to Protect Your Company

    Robert J. Bowman, SupplyChainBrain

    Watch: A Roadmap for the AI Journey

    More from this author

    Subscribe to our Daily Newsletter!

    Timely, incisive articles delivered directly to your inbox.

    Featured Product

    Popular Stories

    • A GLEAMING TUNNEL OF LIGHTS CURVES AWAY INTO A HORN

      Gartner: Top 25 Supply Chain Organizations Are Embracing AI

      Global Logistics
    • HANDS TYPE ON A KEYBOARD UNDER A SUPER IMPOSED DIGITIZED MAP OF THE WORLD, ALONG WITH IMAGES OF A SHIP, A SHOPPING CART AND OTHER SYMBOLS OF INTERNATIONAL LOGISTICS

      Five Demand-Forecasting Mistakes Supply Chain Leaders Are Rethinking

      Technology
    • TWO WORKERS IN HI-VIS VESTS AND HARDHATS CONSULT A BANK OF COMPUTER SCREENS

      How a Poor Hiring Process Leads to High Turnover in Supply Chain

      HR & Labor Management
    • The outside of Oracle Corporation's corporate headquarters located in Silicon Valley. Photo: iStock.com/Sundry Photography

      Oracle Cuts 21,000 Jobs, More to Come From AI

      Technology
    • 037_a_roadmap_for_the_ai_journey_v1-(540p).png

      Watch: A Roadmap for the AI Journey

      Artificial Intelligence

    Digital Edition

    2026 esg cover main scb q2 2026 cover

    SupplyChainBrain 2026 ESG Guide: ESG — The Supply Chain’s Biggest Secret

    VIEW THE LATEST ISSUE

    Case Studies

    • Recycled Tagging Fasteners: Small Changes Make a Big Impact

    • A GRAPHIC SHOWING MULTIPLE FORMS OF SHIPPING, WITH A HUMAN STANDING AT THE CENTER, TOUCHING A SYMBOLIC MAP OF THE WORLD

      Enhancing High-Value Electronics Shipment Security with Tive's Real-Time Tracking

    • A GRAPHIC OF INTERLACING HONEYCOMBED ELEMENTS REPRESENTING GLOBAL BUSINESS TRANSACTIONS

      Moving Robots Site-to-Site

    • JLL Finds Perfect Warehouse Location, Leading to $15M Grant for Startup

    • Robots Speed Fulfillment to Help Apparel Company Scale for Growth

    Visit Our Sponsors

    4flow Arkieva Blue Yonder
    Carton Cloud CoEnterprise Dassault
    Duravant E2Open General Logistics Systems
    Hy-Tek iGPS Korber
    Lyngsoe Procurability Quinyx
    SAP Sikick Systech
    S&P Global Mobility TADA TransImpact
    US Bank Werner Enterprises WSI
    • More From SCB
      • Featured Content
      • Video Library
      • Think Tank Blog
      • SupplyChainBrain Podcast
      • Whitepapers
      • On-Demand Webinars
      • Upcoming Webinars
    • Digital Offerings
      • Digital Issue
      • Subscribe
      • Manage Email Preferences
      • Newsletters
    • Resources
      • Events Calendar
      • 2026 Event Coverage
      • SCB's Great Supply Chain Partners
      • Supplier Directory
      • Case Study Showcase
      • Supply Chain Innovation Awards
      • 100 Great Partners Form
    • SCB Corporate
      • Advertise on SCB.COM
      • About Us
      • Privacy Policy
      • Contact Us
      • Data Sharing Opt-Out

    All content copyright ©2026 Keller International Publishing Corp All rights reserved. No reproduction, transmission or display is permitted without the written permissions of Keller International Publishing Corp

    Design, CMS, Hosting & Web Development :: ePublishing