Nearly half of ransomware victims pay, as UK moves to block public payouts
A Sophos study finds ransom payments are common and demands are rising, while governments tighten the no-pay policy.

Sophos research in 2025 says nearly half of companies hit by ransomware ultimately pay to regain data or systems, as the median ransom demand increases. The UK is advancing plans to prohibit public sector bodies and critical infrastructure groups, including the NHS, local councils, and schools, from making ransom payouts.
Nearly half of companies targeted by ransomware pay up to regain access to their data or systems, according to 2025 research from cyber security group Sophos. The same work flags two more realities boardrooms cannot ignore: the median amount demanded is rising, and attackers are getting more sophisticated and methodical about who they hit.
That pressure is colliding with policy. In the UK, the government is advancing plans to prohibit public sector bodies and critical national infrastructure groups from making ransom payments. The list is specific enough to feel real in operations, naming the National Health Service, local councils, and schools, among the organizations that could face a “veto” against paying.
So what is the hard choice? It is not whether ransomware is bad. Everyone knows it is bad. The choice is whether a business, agency, or institution should treat ransom payments as a last-ditch lever for continuity or as a dangerous precedent that encourages more attacks. Sophos’s numbers suggest that, in the real world, many decision-makers end up paying anyway, likely because ransomware incidents can immediately disrupt services, halt production, lock up critical systems, and force leaders to triage the unthinkable: downtime versus data loss, and both versus escalating harm to staff, customers, or patients.
Add another wrinkle: Sophos notes that ransomware attackers have become more advanced and meticulous over time, particularly targeting vulnerable small and medium-sized businesses. That matters for boards because it changes the risk profile from “rare event” to “repeatable business disruption.” If attackers are picking targets with weaker recovery options, then the perceived odds of getting your systems back quickly after an attack may feel better than the long-term odds of staying resilient. Even when leaders prefer not to pay, the incident may present itself as a clock, not a philosophy.
Meanwhile, global governments are increasingly trying to remove the incentive structure. The UK plan described in the source is part of that broader wave, where jurisdictions move toward banning ransom payments by certain categories of organizations. The underlying logic is straightforward: if payments become harder, attackers have less reliable revenue, and attacks should become less profitable. But the operational consequence is more complicated. For organizations that are singled out in such rules, ransomware response planning has to shift from “pay or not pay” to “what else can we do, fast, when systems are locked and data is threatened.” In practice, that usually means pre-arranged incident response, stronger backup and recovery strategies, and more rehearsed decision-making processes.
This is where second-order effects get spicy. First, if public bodies and critical infrastructure are constrained from paying, the market for defenses, preparedness, and response capabilities can intensify. Vendors in incident response, backup modernization, security operations, and disaster recovery can gain more attention from boards that need to prove they can withstand a “no-pay” environment. Second, boards at private companies may face a parallel pressure even without a legal ban. Investors, insurers, and counterparties could start asking harder questions about how leadership will respond under a potential public sector restriction mindset. If the public sector is being told “do not pay,” private operators may get judged by the same standard: resilience over ransom.
Sophos also highlights that demands are rising. That detail interacts with board dynamics in a blunt way: a higher median demand changes the internal debate about affordability, but also changes the timing of negotiations if attackers are methodical. When demand escalates, the window for executive consensus shrinks. That is why policies like the UK’s matter beyond compliance. They force governance to define decision rules before an incident turns the organization into a hostage negotiation.
Strategically, executives and boards looking at peers with similar exposure should treat this moment as a governance upgrade, not just a cybersecurity headline. The combination of common payments in practice, rising median demands, and tightening government restrictions means the center of gravity is shifting. Organizations need to be able to survive the incident without relying on ransom as a routine exit ramp, because both regulation and reality are moving the target.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Science
Illinois tests 64 one-acre plots to map crop research for the next 150 years
A massive, tile-drained field experiment is underway at UIUC, and farmers are helping set the research targets.
Anaerobic digestion turns animal waste into energy and income for farmers
A centuries-old ingredient, a modern process: livestock waste becomes renewable gas while cutting emissions and diversifying revenue.
Magnetic orientation turns into a three-way handshake inside a single-celled organism
A new study explains how a ciliate-like eukaryote uses Earth’s magnetism, solving a long-standing biological puzzle.
