The Best Defense Against Ransomware Isn't Another Security Tool

CISO Circle James Hodgkinson Cybersecurity Researcher at Cisco Foundation AI

There was a brief period in the late 1960s and early 1970s when commercial airline hijackings were treated almost as a routine cost of doing business. Today, organizations budget for ransomware in much the same way, setting aside funds for incident response, cyber insurance, and even cryptocurrency reserves before an attack ever occurs.

Commercial aviation was porous. Cockpit doors were not reinforced. According to Brendan I. Koerner in The Skies Belong to Us, more than 130 U.S.-registered aircraft were hijacked between 1968 and 1972. Airlines responded pragmatically choosing to negotiate, pay the ransom, recover the plane, and move on. The result was predictable. If you make something easy enough, someone will eventually try it.

We are living through the ransomware equivalent. Critical services go dark. Hospitals revert to paper. Boards convene emergency calls. Lawyers weigh regulatory exposure. Insurers calculate coverage. Somewhere in the middle of it all, someone opens a spreadsheet and decides whether paying the ransom is cheaper than the alternative.

Why ransomware became another budget line

Here’s the uncomfortable parallel: Airlines didn’t solve hijacking by getting better at negotiating with hijackers. They solved it by redesigning the environment with hardened cockpit doors, universal screening, standardized security practices, and shared intelligence. Eventually, the problem stopped being a routine business event.

The same lesson applies to ransomware. We spend too much time dissecting attackers and not enough time redesigning the systems they exploit. If ransomware remains consistently profitable, it tells us something about the terrain, not just the attackers.

It's fashionable to talk about ransomware crews as criminal masterminds. Some are sophisticated. Others simply rent ransomware-as-a-service. At scale, ransomware succeeds because organizations continue to rely on flat networks, identity sprawl, backups reachable from production, logging that exists but isn't actively monitored, and privileged access that sprawls like ivy.

Stop relying on security theater

When aviation matured, the industry stopped thinking in terms of “How do we stop this hijacker?” and started asking, “What makes hijacking viable?” Cybersecurity needs the same shift.

Too many security investments create the illusion of protection rather than measurable resilience. It's the cyber equivalent of airport security theater: password rotation policies that encourage reuse, SMS-based MFA susceptible to phishing, and compliance exercises that satisfy auditors while leaving the blast radius unchanged.

We don’t need to take off our shoes to log in. We need to start eating our cyber vegetables.

The controls that actually change the economics of ransomware are far less exciting:

None are glamorous, but they all change the attacker's math.

Expected loss equals probability multiplied by impact. If ransomware is statistically likely in your industry, expected loss is actuarial. Organizations can either invest in resilience up front or pay for catastrophe repeatedly. Airlines eventually reached the same conclusion. They didn't wait for a moral awakening. They responded to incentives.

Change the economics of ransomware

Ransomware remains profitable because the incentives still work. Attackers count on victims lacking reliable recovery paths. They count on identity sprawl. They count on flat networks. They count on backups they can encrypt. When those assumptions hold, ransom payments often make financial sense.

Organizations should ask harder questions. Why was the entire domain reachable from a single compromised credential? Why were backups accessible through the same trust relationships? Why was privileged access so broad? Why was detection so delayed?

Those questions are less glamorous than dissecting the latest exploit chain. They are also more useful.

There is a risk of drifting into blame when discussing ransom payments. That is counterproductive. Airlines that negotiated were not weak; they were operating inside an ecosystem that had not yet matured. Organizations paying ransoms are often responding rationally to fragile architectures.

We should also be honest about trade-offs. Friction costs money. Segmentation complicates operations. Strong MFA increases support tickets. Immutable backups require budget. Aviation security did not come free. It changed passenger experience. It increased operational overhead. It required coordination between regulators and carriers.

Friction is inevitable. The question is whether it meaningfully reduces risk.

The airline industry didn't eliminate routine hijackings because criminals became ethical. It eliminated them because it made hijacking structurally impractical. Ransomware requires the same shift — not better negotiations, not more security theater, but better architecture.

Crime follows the path of least resistance. Change the terrain.

If you're interested in the architectural shifts reshaping cybersecurity, AI, and enterprise technology, subscribe to the monthly newsletter from Perspectives by Splunk.

No results