More Than Half of CISOs Would Pay a Ransomware Demand. The Maths Are Not Flattering.
A survey of 750 CISOs in the US and UK finds 58% would hand over money to ransomware operators — despite law enforcement advice, incomplete decryption rates, and the lingering question of whether the data stays exclusive.

Fifty-eight percent of CISOs surveyed by Absolute Software say their organisation would pay a ransom demand if hit tomorrow. That figure, drawn from 750 CISOs across the US and UK, sits in direct contradiction to the official positions of both the FBI and the UK National Cyber Security Centre, neither of which endorses payment under any circumstances.
The NCSC's position is unambiguous. "It is the UK government's long-standing position, alongside law enforcement partners, that it does not encourage, endorse nor condone the payment of ransom demands," a spokeswoman for the NCSC said. The FBI's stance is similar: paying rewards criminal behaviour and funds further attacks on others.
But CISOs are not running law enforcement agencies. They are running businesses, and the calculus looks different from that angle.
"Attacks are increasing and continuing to increase," said Christy Wyatt, CEO of Absolute Software, which commissioned the survey. "Companies are better prepared to deal with them: some of the training is paying off and AI is helping. But remember that attackers have all the tools that defenders have."
Predictably, the proportion of organisations actually paying, as opposed to theoretically willing to pay, is difficult to pin down. Stigma suppresses disclosure. An IDC survey found that 37% of companies hit by ransomware paid the demand, though IDC research director for security services David Clemente believes the real figure is higher. "I'm sure that there are many more who have paid it but don't want to be open about it," he said.
And paying is no guarantee of anything. Around 5% of those who paid found decryption was incomplete, according to IDC. A late-2025 survey from insurer Hiscox found only 60% of SMEs that paid successfully recovered all or part of their data. "You may get your data back, you may not," said Wyatt. She also noted something more corrosive: "We have heard instances of companies paying up and finding that their credentials are being shared" — meaning the data never became exclusive again regardless of payment.
The alternative is not obviously better. IDC found that 29% of companies recovered encrypted files from backup without paying, but 33% of those who refused payment could not recover anything at all. So roughly one in three companies that held firm lost their data anyway (a detail that tends not to feature prominently in law enforcement briefings).
The most instructive recent case is Marks & Spencer, which declined to pay when ransomware disrupted its internal logistics and forced its online store offline in April 2025. M&S later estimated the cost of the incident at $400 million in lost operating profit. Whether payment would have been cheaper is unknowable, but the number is not small.
The survey does not resolve the dilemma. It just makes the dilemma visible, which is at least a start.



