Ransomware groups have stopped locking your clients’ files. Now they just steal them

The old "restore from backup and move on" playbook doesn't work like it used to

Ransomware groups have stopped locking your clients’ files. Now they just steal them

Cyber

By Matthew Sellers

There was a time when a ransomware attack had a fairly predictable shape: a hacker locks your files, you either pay for the key or restore from backup, and life goes on. That shape has changed, according to a panel of UK cyber brokers who spoke to me on Insurance Business TV, in ways that are reshaping how programmes get built and how clients get told about their risk.

"The old adage, you're only as strong as your weakest link, has never been more relevant," said Ethan Godlieb, associate partner for cyber and fintech at Consilium Insurance Brokers, opening the discussion. His point wasn't really about ransomware itself but about what happens once encryption stops being the main event. The real work now, he suggested, is due diligence on the vendors a client relies on, because that's increasingly where the exposure sits.

Daniel Winn, a development broker at Jensten London Markets specialising in technology, media and cyber, put the shift in plainer terms. Threat actors are increasingly exfiltrating data from systems rather than simply locking them down and demanding a ransom for the key, which is why he thinks it matters so much to work with the best cyber insurers, some of whom may bring in experienced negotiators to recover that information and, in the process, help bring payments down.

Not every figure quoted on the panel is independently verifiable, but the broader trend holds up. Godlieb suggested average ransom payouts are falling even as attack frequency rises, putting the figure at "as much as 77%" by his own recollection rather than a cited study. Marsh's UK cyber team has reported something similar: ransom payment rates have fallen sharply, from 80% of victims paying in 2019 down to 32% by the third quarter of 2024. At the same time, extortion following ransomware attacks among Marsh's UK clients rose by more than 300% in 2023 alone. Fewer victims are paying, in other words, even as far more attacks now carry an extortion element in the first place.

Godlieb credits much of that gap to better negotiation and claims handling, and argues it's a genuine case for bringing in an expert rather than handling things in-house. "It really does pay to have an expert involved," he said. A skilled negotiator weighs more than just the ransom figure, he added, factoring in reputational risk, legal exposure and regulatory obligations too. This shift towards valuing claims support over price alone shows up in the wider data as well: Insurance Business's own 5-Star Cyber research found UK brokers moving away from ranking insurers primarily on pricing and underwriting technicalities, and placing more weight instead on whether a policy pays promptly and genuinely helps clients through a breach.

Winn flagged a less obvious wrinkle. Not all threat actors behave the same way once they've been paid, and some groups simply don't hold up their end of the bargain even after a ransom lands. That's part of why insurers now maintain their own intelligence on which groups can broadly be trusted to decrypt versus which ones just take the money and run. That intelligence, built up through years of claims handling and law enforcement liaison, is arguably one of the more underrated things a cyber policy actually buys a client.

The shift towards data theft over pure encryption has been building for a while. Allianz Commercial's cyber claims team has previously noted that the share of large cyber losses involving data exfiltration roughly doubled from 40% in 2019 to nearly 80% by 2022. That trend has only continued as privacy and breach-notification rules have tightened globally, giving stolen data genuine leverage value well beyond the simple threat of publication.

For brokers, Winn said, the practical upshot is that business interruption cover built around backup-and-restore timelines doesn't map cleanly onto an attack where the damage is a leak rather than a lockout. Clients need a clearer sense of where their exposure actually comes from, and both he and Godlieb pointed to the same answer: increasingly, that's a supplier or vendor relationship rather than a direct hit on the client's own systems. Building programmes around that reality, rather than around the client's own network alone, is becoming a bigger part of the broker's job.

Ransomware isn't going anywhere, either way. The International Underwriting Association has just launched a dedicated Cyber Claims Committee specifically to help the London Market keep pace with how fast claims patterns are evolving. What's changed, judging by this panel, is less the threat itself than what "resilience" actually needs to cover.

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!