Funded startups have a lot of money. Milking money out of startups is a highly profitable market segment. Why would ransom gangs not want to get in on that? They don’t tend to ask for the ransom to be paid in ISOs…
A bit off your "real" point: No company should ever spend more mitigating a risk than the potential cost they could incur from the risk. That is just good business, but the reality is that companies generally won't spend more on cybersecurity than their peers (either as a percentage of revenue or percentage of IT spend). Whether that is the proper balance for a risk/spend calculation is the real topic.
The problem is that we can't accurately calculate the probability of a cyber event and the cost impact of that event. So the company is stuck waiting for an attack on themselves or one of their cohorts so they can adjust.
Funny, after the fact they are usually out a lot of money and they decide that they now do want to mitigate that risk.
I've heard hospital administrators make this argument after I've warned them about their security infrastructure being vulnerable to ransomware. I'm not convinced.
basically you summed up the opening scene from the FightClub. The human life cost H millions, so until it is going to kill N such that N * H >= cost of the fix ...
Given the time cost of retrofitting effective security, waiting until you become a worthwhile target doesn't work. But hiring secops and spending time on security engineering instead of your product is also deadly to startups. It is another knife-edge for startups to walk.