New research from security vendor Proofpoint has put a hard number on a decision most businesses hope they never have to make: 58% of UK ransomware victims paid the ransom, despite consistent NCSC and government guidance not to. Worse, more than one in five of those who paid, 22% in the UK specifically, were then targeted for a second extortion demand from the same or a different criminal group. Two-thirds of UK victims also reported that data was stolen during the incident, not just systems locked, meaning paying to unlock files doesn’t address the exposure of whatever was taken.
The gap between official advice and what businesses actually do under pressure is the real story here. NCSC guidance not to pay exists because paying funds the next attack and offers no guarantee of full recovery, but when a business is staring at locked systems, an ultimatum, and possibly a legal or contractual deadline, “don’t pay” can feel like advice from people who aren’t the one making payroll that week.
Why the decision should be made before the crisis, not during it
The businesses making the worst version of this decision are the ones deciding for the first time under active pressure, with a countdown clock and an attacker in their inbox. The businesses making the best version already decided in advance: what their backup and recovery position actually is, whether it’s genuinely separate from systems an attacker could also encrypt, and who has authority to make the payment call if it ever comes to that. If you don’t currently know how long a full recovery from backup would take your business, that’s a gap worth closing this month, not after an incident forces the question.
Data theft changes the maths entirely
The finding that two-thirds of victims had data stolen, not just encrypted, matters because it changes what paying actually buys you. Restoring from a clean backup solves the “systems locked” problem without paying anyone. It does nothing for data already exfiltrated and sitting on a criminal server, which is exactly the leverage behind the repeat-extortion figure: pay once to get files back, then get a second demand threatening to publish or sell what was already taken. Recovery planning has to account for both problems separately, because one payment doesn’t buy immunity from the other.
This is precisely why more UK businesses are moving from occasional security reviews to continuous, ongoing monitoring; if data theft and encryption can now happen in the same incident, catching unusual access early is worth more than checking once a year. KeepSafe offers exactly that kind of continuous monitoring, built for businesses that would rather see a problem forming than find out about it from a ransom note.
What insurers and law enforcement are watching for
Cyber insurers are increasingly asking the same questions during renewal that this report highlights: can you demonstrate a tested backup and recovery process, and do you have an incident response plan that names who makes the payment decision. Businesses that can answer these clearly are starting to see it reflected in premiums, while those who can’t are finding cover harder to get or more expensive to keep. Law enforcement’s position hasn’t softened either; Action Fraud and the NCA continue to treat ransom payments as something to be reported, not hidden, partly because payment patterns help build a picture of which criminal groups are actually being funded by UK businesses.
The takeaway
Nearly six in ten UK ransomware victims are paying up despite advice not to, and paying still leaves a real chance of getting hit again. The single most useful thing an SME can do this week isn’t a bigger security budget, it’s a clear, written answer to two questions: how would we actually recover without paying, and who decides if we ever have to. Work that out now, while there’s no deadline attached to the answer.