I don’t know much about this travel agency. They may or may not have had a security team. What they did have was mentioned in this article: liability. They took steps to reduce or eliminate this liability. I think we all know that there’s no proof these attackers acted in good faith past the actual decryption, but now CWT can at least say they attempted to recover lost data.
I think we can only realistically hold companies liable for transactions like this when we have better government resourcing and oversight. Getting the FBI involved in stuff like this is difficult, as they’re over loaded with such cases.
I also feel we should never hold individuals liable for stuff like this. It’s unreasonable to expect people who aren’t security professionals to know how to defend or respond to threats like this given how rapidly the landscape changes.
Figuring out a good way to holistically deal with cyber criminals will probably be a problem we struggle with for years, if not decades.