Ransomware and the Board’s Role: What You Need to Know

Ransomware attacks are increasingly making global headlines as the ransomware as a service ecosystem evolves, attack methods become more sophisticated and ransom demands escalate. Add to this environment the expanded use of AI to launch more sophisticated and frequent attacks, ongoing digitalization of companies, the prevalence of remote workforces, along with the increased number of […]

May 10, 2025 - 14:34
 0
Ransomware and the Board’s Role: What You Need to Know
Posted by Ray Garcia, Matt Gorham, and John Boles, PricewaterhouseCoopers, on Saturday, May 10, 2025
Editor's Note:

Ray Garcia is a Leader, Matt Gorham is a Global Cybersecurity and Privacy Leader, and John Boles is a Partner of Cyber, Privacy, & Forensics at PricewaterhouseCoopers LLP. This post is based on their PwC memorandum.

Ransomware attacks are increasingly making global headlines as the ransomware as a service ecosystem evolves, attack methods become more sophisticated and ransom demands escalate. Add to this environment the expanded use of AI to launch more sophisticated and frequent attacks, ongoing digitalization of companies, the prevalence of remote workforces, along with the increased number of companies doing business with third parties — these all may create greater vulnerability to ransomware attacks.

The proliferation of ransomware attacks has become a significant concern for companies, as threat actors continually refine their strategies to maximize impact and profit. These cybercriminals meticulously select their targets based on the presence of known vulnerabilities and the company’s ability to pay the ransom. Once successfully attacked, companies face the difficult decision of whether to pay the ransom, carefully weighing the associated risks and consequences.

Boards will want to engage with management to make sure they are strengthening their cybersecurity measures and resilience planning capabilities to defend against the threat landscape and adequately preparing for a potential ransomware attack.

(more…)