Skip to content

To Pay or Not to Pay: DriveSavers Weighs In After Being Quoted in the Financial Times

To Pay or Not to Pay: DriveSavers Weighs In After Being Quoted in the Financial Times

Confirmed ransomware victims rose 389% year over year in 2025, climbing from roughly 1,600 in 2024 to 7,831 globally. Nearly half of the companies targeted end up paying. Those are the ransomware statistics behind a debate the Financial Times recently asked DriveSavers to weigh in on: should ransom payments just be banned?

Our answer was that it’s complicated. We want to explain why here in more detail than a news article allows, and to show what that complication actually looks like from inside a ransomware data recovery case.

The Case For, and Against, a Blanket Ban

The UK government is advancing plans to ban ransom payments outright for public sector bodies and critical national infrastructure providers, including the NHS, local councils, and schools. It’s a serious response to a serious problem. Most ransomware victims are small and midsize businesses, not critical infrastructure operators. A ban aimed at critical infrastructure providers targets a small share of overall attacks, so on its own it may do little to reduce the total volume of ransomware crime.

Jim Walter, a senior threat researcher at SentinelOne, takes a harder line on payment generally. “Paying extortive threat actors only strengthens the ecosystem and the entities that enable it,” he told the Financial Times. Attackers can’t be trusted to delete stolen data, and re-extortion happens often enough that he considers payment a net loss even when it works.

DriveSavers doesn’t disagree with any of that, in principle. Our concern is what happens when a payment ban is in place, but recovering critical data required to restore operations  isn’t feasible. “Situations are almost always more nuanced than a ban accounts for,” Maus told the Financial Times. Take a water utility or a regional power provider. If an attack takes their systems offline, a ransom payment is barred, and there’s no technical path to restoring operations, the people who lose water or power aren’t the hackers or the policymakers who wrote the ban; they’re customers. Payment bans make sense when the impacted organization has a viable alternative to ensure their critical systems can be secured, and operational data can be recovered. As Maus said, “Blanket prohibition, without that alternative in place, can cause more harm than it prevents.

There’s already a test case for this. North Carolina banned ransomware payments for government entities in 2021, and Florida followed in 2022. Neither ban appears to have materially deterred criminal activity in either state. Haydn Brooks, CEO of Risk Ledger, raised a related point in the same piece: if public bodies can’t pay, criminal groups will likely pivot toward less-regulated private-sector targets, and insurers may respond by excluding ransomware payouts entirely and driving premiums up as a result.

What the Law Says

One misconception needs correcting here, at least under U.S. law. Paying a ransom is not, by itself, illegal under U.S. federal law. In the United States, the only federal legal barrier to payment is the OFAC sanctions list. If the attacker is a sanctioned group, individual, or nation-state, payment is illegal. Outside of that, there’s no nationwide ban on private organizations paying, though North Carolina and Florida have banned their own public agencies from doing so. This has not deterred attacks on municipalities. Every state and U.S. territory has its own data breach reporting requirements, and those apply regardless of whether a ransom gets paid.

That distinction changes the real question most businesses are facing. It’s rarely a question of legality. It’s a question of whether payment is the right call given the data involved, the customers affected, and the actual odds of recovering from the attack.

The legal picture looks different elsewhere. The UK, Australia, and other jurisdictions where DriveSavers operates are weighing or enforcing their own restrictions, so organizations outside the U.S. shouldn’t assume U.S. rules apply to them.

What Ransomware Data Recovery Actually Looks Like

The cases DriveSavers works on share a structure that wasn’t as consistent a few years ago. Before encrypting systems, attackers are corrupting or deleting backup infrastructure: Veeam backup repositories, Hyper-V hosts and VMware ESXi hosts to offer prime examples. Roughly half of the ransomware data recovery cases DriveSavers has handled over the past two years involved attackers targeting Veeam backups specifically before touching the primary servers. Veeam is the dominant backup platform for virtualized environments, with roughly 550,000 customers worldwide, and a lot of IT teams don’t realize that deleted or corrupted Veeam backup files can often still be recovered with the proprietary recovery tools and techniques developed at DriveSavers.

Decryptors provided by threat actors are also unreliable, especially with large files and databases. Organizations that pay the ransom to acquire a decryptor frequently still need professional data recovery afterward to recover a complete set of usable files, because the decryption process itself leaves data corrupted. And immutable backups, while genuinely worth investing in, aren’t foolproof. DriveSavers has recovered critical data from cases where a backup server marketed as immutable was deleted outright, because the software managing that immutability had itself been compromised.

In one recent engagement, DriveSavers helped an insurance carrier avoid a ransom demand described as being in the millions of dollars by recovering all of the necessary operational data from deleted backups. The data recovery services required cost a fraction of that. It’s part of a broader shift: insurance carriers are now routinely asking whether data recovery is feasible before authorizing a ransom payment, which wasn’t a standard question a few years ago.

Recovery Is Sometimes Possible Without Paying. Not Always.

Paying a ransom doesn’t guarantee attackers hand over a working decryption key, that your data comes back intact, or that stolen data won’t surface somewhere later anyway.

The opposite assertion requires equal prudence, and it is beneficial to distinguish between two concepts:

Definition

Ransomware Data Recovery Services

Actually restoring or repairing the original files from what survived the attack, whether that’s production systems, damaged backups, or partial copies, is what DriveSavers does. It’s sometimes possible and sometimes not, depending on the ransomware strain involved, how much of the backup infrastructure survived, whether a decryption tool has already been published for that malware variant, and how the attack itself was executed.

Definition

Ransomware Recovery

In the broader sense, is better defined as restoration. Meaning the organization itself has restored business operations. In cases where the original data genuinely can’t be recovered, some organizations have to go through the tedious process of data recreation: rebuilding records from connected systems that weren’t touched, third-party or client-side copies, paper records, or manual reconstruction from transaction logs held elsewhere. That’s a legal and operational exercise more than a technical one, and it’s outside DriveSavers Data Recovery’s specialty, but it’s a real path, and a failed data recovery attempt shouldn’t be treated as the end of the road.

Before any payment decision, DriveSavers recommends bringing in a digital forensics and incident response team and a breach coach to properly assess the overall risk to the organization, determine what data was actually taken, whether it involves personal or health information, identify which threat actor group is responsible, and explore whether ransomware data recovery is realistically on the table. None of that supports a fixed rule in either direction, and that conversation should happen before a ransom deadline forces a decision, not after.

What Would Actually Reduce the Problem

A few of the other people quoted alongside Maus made a point that deserves more attention than the ban debate itself gets. Gavin Millard, VP of product at Tenable, put it plainly: the more useful question is how to make ransomware less profitable to begin with. Most attacks still exploit known vulnerabilities and exposed systems, so exposure management does more long-term good than any payment policy. Spencer Young at Delinea made a related point about access controls: limiting standing permissions so a single stolen credential can’t move freely through a network shrinks the damage even when an attack succeeds.

Maus raised a related point on the policy side. “Rather than prohibiting payment for an attack that has already happened,” he told the Financial Times, investing in subsidized backup infrastructure or tax incentives for cybersecurity spending “would do more to reduce the underlying exposure.” Preventing the crisis is cheaper than legislating around it after the fact.

On the preparedness side, the organizations that recover fastest tend to have already documented where their backups are stored, which systems are critical, and who to call, before an attack happens. That contact list should live somewhere separate from the primary servers so it isn’t encrypted along with everything else, and it should include legal counsel, the cyber insurance carrier, and a data recovery service.

Where This Leaves You

Resolving the dilemma of paying a ransomware demand is never straightforward. Treat it as a decision with several inputs, not a single moral choice: how sensitive the data is, whether backups survived, who the specific attacker is, what the legal exposure looks like, and how realistic data recovery actually is. Bring in outside help early, before a ransom deadline forces your hand, so you have more of those inputs to work with instead of fewer.

If you’ve been hit with a ransomware attack, reach out to DriveSavers for a complimentary consultation before you make any decisions: +1 (888) 282-2227

Read the full Financial Times report: Surge in ransomware hacks deepens divide over whether to pay (subscription may be required).

Andy Maus is Head of Cyber Recovery Services at DriveSavers, leading initiatives that help organisations recover critical data following cyber incidents, ransomware attacks, and other security breaches. He joined DriveSavers in 2023 after more than two years at Arete Incident Response, where he introduced Data Recovery Services to the firm’s restoration portfolio, expanded the technical operations team from 10 to over 70 specialists, and built strategic alliances with SentinelOne, Dell, and Presidio. Earlier, at Ontrack Data Recovery, he oversaw global sales, supporting complex data restorations for clients across 22 countries. With more than three decades in the technology industry—including leadership roles at Dell, Mitel, and Level 3 Communications—Andy brings deep experience in cyber incident response, data recovery methodologies, and large-scale technical operations.

Back To Top
Search