Security experts say insurance companies cyber, which encourage victims to pay the ransom, are empowering criminals.
There has been a significant increase in ransomware attacks in the first half of 2019. In the US , many cities have been hit by attacks, causing many of their services to go offline.
These situations cause many victims to succumb. Many companies as well as entire cities have been forced to pay huge monetary amounts.
Many times, victims end up with this option, as restoring systems (in case there are backups) requires much more time, resources and money. When it comes to the services of a city, serving thousands of citizens, time is of the essence. The solution must be immediate. Thus, paying the hackers is an easier and faster process than restoring the systems.
Researchers have observed that most cyber insurance companies urge victims to pay the criminals because they consider it the most economical and easy way to deal with a ransomware attack .

Meanwhile, authorities are constantly emphasizing that victims should not pay the ransom, because in doing so they finance and strengthen criminal activities.
Theresa Payton, CEO of Fortalice Solutions, says she is disappointed with the insurance companies. In a speech at the CloudSec 2019 conference, she mentioned a case of a client who faced a ransomware attack.
“The insurance company told the client that it has experience negotiating with ransomware gangs and that it can lower the price. It said that paying the ransom is the cheapest «cheapest» solution».
Ms. Payton said that insurance companies are trying to solve the problem with as little cost as possible. This is done by paying the ransom.
This leads to a lot of problems. Hackers know that insurance companies give this advice, so they target businessesthat have an insurance company because they are more likely to get the money they are asking for.
Attackers calculate how much money a company needs to restore systems from backups and offer a lower price to increase their chances of payment.
However, victims should not give in. The attackers are not trustworthy. Even if victims pay the ransom, it is not guaranteed that they will get their data back. In this case, the victim will have paid the ransom and will also have to pay for the restoration of the systems. This means that the cost will be much higher.
Furthermore, when someone chooses to pay the ransom rather than secure their network, they may find themselves targeted by hackers again. There is no guarantee that they will not be attacked again.
Finally, as we said above, paying the ransom strengthens the hackers' attacks since they see that they are making a profit, while at the same time financing, helping them develop even more sophisticated and dangerous techniques.
Therefore, the best solution is prevention. Regularly update your systems , use reliable antivirus programs, train your staff and create backups. In case you fall victim to a ransomware attack, you will be able to restore your data without giving in to the criminals' demands.
