I am also left to wonder if paying helps the investigation.
They stand to loose future premiums if paying ransoms is NOT broadly seen as a viable option.
Sure, in the short term, they hate customers that make a lot of claims. But those claims, in aggregate, are the fuel for their 20% skimming…
If nobody paid ransom, why would they want insurance coverage? And if no insurance covered it, they wouldn’t be able to skim off the corresponding premiums…
Yes I get that insurance paid the extortion, but besides just capitulating, why doesn't restoring from backup work, assuming you can spot the vulnerability that caused the ransomware attack?
We also have to consider the rebuild labor and if entire systems are corrupted then repurchasing new systems.