
Ransomware dominates headlines because it’s a concept that is easy to understand. Its impact is felt well beyond the initial victim, and its cost is easily demonstrable. It freezes operations. It halts revenue. It presents a neat number on a ransom note that board members and senior management can understand instantly.
But ransomware isn’t the whole attack. It’s the last step.
And that’s why the most unglamorous topic in cyber security – cyber hygiene – is still the best lever businesses have in reducing the impact of ransomware.
Why Ransomware Keeps Winning
If you’re a cyber attacker, there’s very little incentive to change your behaviour. The fundamentals that worked 10–15 years ago still work today. Find a way in, move around, escalate privileges, deploy the payload and get paid.
That “payload” is the key point. Ransomware is not how an attacker gains access. It’s what gets deployed once access has already been achieved and the attacker has positioned themselves for maximum disruption.
Buying more products is clearly not the primary solution to stopping attacks from reaching their final stage. If it were, the last decade of news headlines on cyber breaches – many involving organisations that should be among the best protected in the world – would look very different.
The uncomfortable truth is that ransomware thrives on basic failures. Attackers do not need zero-day exploits if patching is inconsistent, privileges are excessive or protective controls are mis-configured or poorly maintained. In those conditions, ransomware is not an intrusion problem. It is an inevitability.
In this scenario, it’s probable that many high-profile ransomware incidents weren’t enabled by genius-level exploitation, but by basic mistakes made along the way.
Cyber hygiene is simple – have a plan and execute it
Cyber hygiene sounds like “security 101” because it is. At its core, it’s businesses doing the boring work consistently:
- knowing what they have
- setting minimum standards
- reducing preventable exposure
- preparing for incidents on the assumption that they will happen
And yet, even in countries like the UK and the US, where you’d expect organisations to be leading the way, over 50% still don’t have a usable cyber security plan.
That’s not a tooling issue. That’s governance, discipline and accountability.
SME Cyber Hygiene Isn’t Just an SME Problem
As our CEO and founder, Simon Edwards, discussed on a recent CyberCube webinar, the issue is compounded for small and mid-sized businesses (SMEs) that often face a triple bind:
- They can’t afford “enterprise-grade” security products, and many vendors won’t even sell below minimum seat counts.
- They don’t adopt even lightweight standards because they don’t believe they have the budget.
- They can’t meaningfully insure themselves out of trouble, either due to cost, eligibility or the reality that insurers require telemetry and controls many SMEs don’t have.
So SMEs remain highly exposed, and that exposure becomes a supply-chain problem for larger organisations.
Why Boards Fund Ransomware (and ignore quieter breaches)
Ransomware is popular with attackers for a simple reason: instant monetisation.
In a strange way, it’s also popular with victims. It’s easy to understand. Boards can quantify the loss in hours of downtime versus the monetary value of the ransom demand.
Compare that to unseen IP theft, data exfiltration or long-term espionage. Those harms are real, but the financial figure is fuzzier, delayed and harder to defend in a budget conversation.
That’s one reason why we believe ransomware will stay in the spotlight for years: it creates an immediate, board-relatable crisis.
The risk is that organisations will optimise spending for the most visible outcome rather than the most probable path and subsequently under-fund the hygiene that prevents attackers getting to the payload stage.
Ransomware Resilience
Ransomware outcomes are shaped long before encryption begins, often by decisions made months or years earlier about patching discipline, privilege control and defensive coverage.
Where cyber hygiene is strong, ransomware struggles to gain a foothold. Not because attackers aren’t capable – but because the path to the payload usually depends on a chain of preventable weaknesses. Which is why when we test a cyber security product against ransomware, such as our most recent report on CrowdStrike Falcon, it’s not about ransomware as a payload alone.
It is about whether security products meaningfully support good cyber hygiene when it matters most, and whether that support holds up across both immediate and deeply embedded attack scenarios.