That means less potential profit for ransomware makers, less incentive to make ransomware, and less money to fund ransomware development.
The gunpoint analogy is a poor one; being coerced by physical violence is one thing, being coerced because you lost your files (and don’t have backups) is another. It’s a horse of a different color.
The companies getting their customers data encrypted are NOT victims. At best they are incompetent and should never have been in business to begin with and most certainly should never have been anywhere near any of their customers data.
Companies have a fiduciary responsibility to protect their customers and investors. If a company is letting phishers trounce all over my data then in a way I am glad that my data became encrypted so that the company can no longer hide the fact they were negligent not only to keep the thugs out but also neglected to properly back up my data. I am more concerned about all the companies that were popped and were able to hide it because they only lost my data to the phishers. Ransomware is exposing the incompetent businesses and embarrassing their leadership as it should. Securing data in an ever growing and large company can be challenging due to internal politics especially if being security focused from day one was not their priority. Backing up data is easy.