ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

The psychology of ransomware crisis response

psychology and ransomware
psychology and ransomware

Bec McKeown at Immersive Labs explains how an understanding of psychology is essential when preventing and responding to ransomware attacks

 

A ransomware attack is a trauma that shocks an entire organisation.

 

When an incident begins, normal operations cease as defenders mobilise and fight to save the company’s reputation, corporate value, and stakeholder relationships. It is a high stake, high-stress game that pushes the systems and processes inside an organisation - as well as its employees - to breaking point.

 

Understanding how an organisation is likely to respond to this trauma, and helping staff develop the capabilities to cope with threats, will limit the eventual damage. By optimising the capabilities of the entire workforce, every department can be mobilised to tackle such threats and non-technical employees can become cyber-security assets.

 

n March 2022, Immersive Labs released its Cyber Workforce Benchmark report, an in-depth analysis of the knowledge, skills, and judgement of more than 2,100 organisations.

 

Our platform tests, exercises and assesses the capabilities of people working at every level of an organisation. Over the past 18 months, our customers have carried out 500,000 exercises and simulations, enabling us to collect data which contains unique and valuable insights that reveal how security professionals respond to ransomware or other crises.

 

The psychology of solving cyber-security problems

We found that most employees do not want to pay attacker ransoms, with 83% of exercise participants choosing not to hand over money to criminals.

 

We found discrepancies between industries, with exactly one quarter of crisis teams in the education sector willing to pay a ransom - making it the sector most likely to pay. The sector that was least willing to pay a ransom was infrastructure, where not one single team agreed to give criminals the cash they are looking for.

 

Organisations must ask themselves the same question ahead of time – should a ransom be paid and how should crisis response teams react to a cyberattack?

 

Ransomware is a classic “wicked problem” - one that is difficult or impossible to resolve. During an incident, the people working to defend an organisation face severe psychological stress, data overload and decision fatigue.

 

The amount of information which must be considered can overwhelm people within an organisation, meaning that decisions are often rushed and based on fear, uncertainty, or even gut-feeling.

 

Pre-existing moral and ethical biases may also influence decisions made during the pressure of a ransomware incident. These decisions are likely to be sub-optimal.

 

To combat this, organisations must prioritise a cadence of exercising to build cognitive agility, enable better decision making and ensure effective cyber-crisis response. Despite its importance, our research exposed that no organisations exercised sufficiently.

 

Whilst technology and financial services companies prepare the most for cyber attacks, running nine and seven exercises per year respectively, it’s still not enough. Shockingly, critical national infrastructure exercised just once per year, when once per month should be a minimum.

 

A real crisis is not a time for learning. Only with regular exercising will crisis response teams be able to consciously develop the ability to make connections between previous decisions. What’s more, unless learned skills are regularly reinforced, they fade, and crisis response goes back to square one.

 

Cognitive agility

By carrying out simulations and test exercises, organisations can develop the human cyber capabilities necessary for a successful response as well as understand how and why their staff make certain decisions. The overall effect of repeated exercises is an improvement in cognitive agility, enabling employees to quickly adapt and cope with unexpected situations.

 

When a ransomware infection begins, for example, organisations typically base their response on a plan drawn up in advance based on previous threats and analysis of known risks. This approach cannot respond to dynamic or novel risks which come from left field. Such plans are too static responses to an ever-changing problem.

 

A better approach is building adaptable incident responders who can think on their feet and react to the situation in front of them. This is why continual exercising is important. You are not teaching people to respond to a specific crisis, but developing the skill of decision-making itself.

 

Exercise to win

The more an organisation exercises ransomware response, the more agile it becomes - allowing it to deal with known and unknown threats more effectively. Only once a team has learned the “what” of a capability can they progress to the “how” and the “why”; it is this deeper understanding that will make all the difference in a crisis.

 

Regularly exercising capabilities will keep skills fresh and boost resilience across an organisation. By carrying out exercises on a regular cadence, crisis-response teams will steadily develop the ability to make connections between previous decisions and decisions made more recently.

 

The time to learn about response capabilities is before a crisis. Starting now.

 


 

Bec McKeown is Director of Human Sciences at Immersive Labs

 

Main image courtesy of iStockPhoto.com

 


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543