Menu
Two laptops in a dark room

Why ransomware resilience is replacing negotiation

Posted on 19 August 2026

Reading time 5 minutes

The ransomware landscape continues to evolve, with a growing disconnect between attack volumes and criminal revenues - incidents, victim disclosures, and extortion attempts continue to rise, while payment rates are declining across multiple sources. Overall, threat actors appear to be conducting more attacks for diminishing returns, while organisations are becoming more resilient and more capable of recovery without payment. Organisations that do pay still, however, face significant financial impact, suggesting that threat actors are responding by pursuing larger payments from fewer victims and applying greater pressure during negotiations.

What does this mean?

Historically, ransomware was primarily an encryption problem. Today, it is increasingly a data extortion problem. Threat actors routinely steal information before deploying ransomware, allowing them to threaten publication even when systems can be restored from backups.

The Sophos State of Ransomware 2026 report found that 67% of victims identified the event as their most significant identity-related attack and that 79% of attacks originated through identity-based methods such as phishing, malicious email, or credential compromise.

Paying a ransom is also becoming less reliable. Proofpoint's recent AI-Era Ransomware Report found that among organisations that paid a ransom, 37% subsequently faced a second extortion demand, while only 56% paid a single ransom and successfully regained access to their data. Approximately 2% paid but never regained access to their data.

The Sophos report also shows how resilience is affecting payment outcomes; among organisations whose data was encrypted, 66% recovered using backups, while only 48% paid a ransom to recover data. Sophos also reported that 51% of organisations that paid successfully negotiated a lower settlement than the original demand, indicating that opening demands are often negotiating positions rather than fixed amounts.

As ransomware becomes more dependent on stolen data than encrypted systems, there is often no reliable way to confirm deletion.

This raises an important question: is payment still delivering the outcome organisations expect?

Increasingly, the evidence suggests the answer is no.

Payment may address an immediate operational issue, but it offers little assurance that stolen data will remain private, that further demands will not follow, or that the organisation will not be targeted again.

As organisations become less willing to pay, threat actors appear to be increasing pressure during negotiations. Chainalysis highlights in its 2026 Crypto Crime Report that incident response providers observed ransomware groups contacting employees, customers, and business partners directly. Other groups reportedly analyse stolen datasets to identify sensitive information and tailor threats around legal, commercial, or reputational consequences.

The ransomware ecosystem is fragmenting, with revenues increasingly distributed across smaller operators rather than a handful of dominant Ransomware-as-a-Service (RaaS) brands, reducing confidence that negotiated agreements will be honoured, as smaller or transient actors may have fewer reputational incentives to provide working decryption tools or uphold data deletion promises.

As with many modern-day cyber security challenges, artificial intelligence is also playing an enabling role; current evidence suggests that AI is not fundamentally changing the ransomware business model, but it is making precursor activity more effective.

Proofpoint's research found that 65% of surveyed organisations believed AI increased ransomware effectiveness, primarily through phishing, credential theft, impersonation, and reconnaissance, with Sophos similarly reporting that phishing and malicious email have overtaken exploited vulnerabilities as the most common root causes.

As organisations depend more heavily on cloud providers, managed service providers, SaaS platforms, and software supply chains, ransomware operators can increasingly gain access indirectly through trusted external relationships; according to the Verizon 2026 Data Breach Investigations Report, breaches involving third parties increased significantly year-on-year and now account for almost half of all breaches, which makes third-party risk another important consideration.

How could this affect me?

The shift towards data-centric extortion is particularly notable for law firms and legal service providers, as these organisations typically hold large volumes of sensitive information, privileged communications, transaction data, litigation material, intellectual property, and personal information. The legal and regulatory implications are significant, as in many cases the threat of disclosure may create greater pressure than encryption-related disruption.

This risk is not exclusive to the legal sector, however, as all organisations that control personal data will need to manage incident response, regulatory scrutiny, reputational harm, and legal claims simultaneously. A serious data breach may trigger UK GDPR reporting, client notification, contractual disclosure requirements, professional regulatory expectations, and potential litigation.

Identity-led attacks also present a challenge for organisations that rely heavily on email, outsourced providers, cloud collaboration platforms, and hybrid working. As attackers increasingly exploit trust rather than technical vulnerabilities, identity security, phishing-resistant authentication, and user awareness become critical controls.

What does this mean for the future of negotiations?

Modern ransomware negotiations increasingly resemble crisis and hostage negotiations rather than conventional commercial discussions; threat actors frequently create urgency, apply psychological pressure, and contact stakeholders to influence decision-making. Negotiation should therefore be treated as a way to gather intelligence, validate claims, preserve options, and create time for technical recovery and legal assessment, rather than as a guaranteed path to resolution. Clear objectives should be set before engagement, including whether the aim is to obtain proof of possession, delay disclosure, understand attacker motivations, or support wider incident response.

The same applies to payment decisions. The evidence suggests that payment should not be viewed as a risk-elimination measure - any decision to pay should be supported by documented legal, regulatory, operational and financial assessment, including sanctions screening, anti-money laundering considerations, insurance requirements, and reporting obligations. Payment provides no guaranteed protection against future disclosure, repeat extortion, or subsequent attacks; organisations should therefore preserve strategic flexibility for as long as possible and avoid decisions that unnecessarily constrain recovery options.

Overall, ransomware remains highly disruptive, with attacks continuing to increase, recovery costs remaining substantial, and threat actors adopting more coercive methods.

The key takeaway is not simply that fewer organisations are paying. It is that payment is no longer a reliable route to lasting resolution. For organisations in highly regulated sectors, resilience, recovery capability, governance, and preparedness are becoming more important than negotiation itself.

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else