Why So Many Must Pay the Ransom

By Ray Birch

BALTIMORE—The lack of resources to properly defend against and then recover from ransomware attacks is leading to three-quarters of targeted institutions and companies being forced to pay the ransom, according to one expert.

It's a classic case of pay now or pay (much more) later, according to Think/Stack VP of Security and Risk Jennifer Anthony, who stressed the fact that 78% of those being targeted feel they have no choice but to pay up is something that must change.

And that begins with boosting the budget for cybersecurity to not only to defend against attacks, but to have foolproof backup systems in place for getting back online without paying a cent to crooks.

Feature Final Final Ransomware

“What is happening is that many companies are not well prepared to get back online with their data via backup systems, et cetera,”  she said. “So, they tend to pay the ransom. And by doing so not only are they encouraging more ransomware attacks globally, they’re funding those criminals’ efforts.”

Anthony’s insights were shared during a recent webinar hosted by cybersecurity firm Think/Stack, which was held to provide CUs with insights and answers regarding ransomware in light of the recent ransomware attack that affected five-dozen CUs due to a strike on a common vendor.

Third in Series

This is the third in a series featuring Anthony’s advice for credit unions when it comes to ransomware and cyber-attacks.

The first in the series examined the anatomy of a cyberattack, while the second in the series outlined the questions every credit union should be asking itself ahead of such a security breach.

The ’Big Folks’

Anthony sized up the threat credit unions are facing.

“It's the big folks—China, Russia, Iran, North Korea. They are certainly well-funded…These are not young kids in hoodies in their basement hacking credit unions,” she said. “These are very sophisticated and well-funded adversaries and they have a lot of resources at their fingertips.”

There’s a reason for credit unions to be prepared beyond just the critical need for protecting member and CU records, she explained.

anthony

“Every time we pay we are putting money back into the circle, and criminals are using those funds to continue to fund attacks,” Anthony said. “I'm super-passionate about this—don't give them one dime.”

‘Got Hit Big Time’

Anthony described an experience she had while working in cybersecurity at a previous employer where her company was hit by ransomware, but was also ready to restore operations on its own.

“We got hit big time. No one across 10 buildings could log in,” she recalled. “But we were prepared and had operations restored within the business day—and we didn't give that ransomware attacker one dollar because we had done the things that we needed to do. We’re not going to keep funding their capabilities.”

The Case for Investment

So, how does a credit union IT leader convince management, or, how does management convince a CU’s board, that cybersecurity—including better defenses—needs a bigger slice of the budget?

“My executive team reports to the board, and annually we have cybersecurity conversations,” said Anthony, who emphasized the discussions on related funding need to happen more frequently than that. “Is the annual conversation about cyber security a strong enough cadence? How often should credit unions be talking about it? Who should be having these conversations? Cybersecurity conversations should be embedded in the culture of credit unions, yet they are not.”

Building a Case

Anthony said she recognizes every credit union department is requesting additional budget dollars.

“I acknowledge that credit unions are dealing with a lot of issues, such as how do I manage my decreasing membership? How do I stay relevant. I mean, cybersecurity is not the only thing barking at the door of the leaders of a credit union,” she said.

One thing a technology leader should not do in building a case for more cybersecurity funding is to use “scare tactics,” according to Anthony.

“I don't think that right is now a good time to run into your CEO’s office and say, ‘See I told you we need $5 million more to do this’,” Anthony advised, referring to the recent ransomware attack that hit 60 CUs. “Your point must be made via continuous conversations that are happening at the leadership level. If board members and leaders of credit unions don't have regular conversations with their technology teams, I would say that's one thing that needs fixing.”

A Need to Talk

Anthony further recommended credit union CEOs be talking as often with the CTO as he or she does wotj the CFO.

“I suggest you take a look at your entire threat landscape and do some prioritization of things that need to be funded,” she said. “And then say to your boss these are the top seven things we need to do next year. You have to realize you are not going to be able to close all the security gaps at once.”

The credit union CTO also needs to be talking a great deal with its vendors and asking some detailed questions, Anthony said.

“Ask them what they are doing for incident response. What are they doing for intrusion prevention. Are they testing their backups. If you're depending on vendors those questions are incredibly important,” she said.

Section: Standard
Word Count: 1129
Copyright Holder: CUToday.info
Copyright Year: 2026
Is Based On:
URL: https://cuto-admin.flux5.ccplatform.net/THE-feature/Why-So-Many-Must-Pay-the-Ransom