Skip to content

8 August, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

      AI behaviour

      How do you measure AI adoption?

      It’s easy to produce metrics on AI software deployment, but these are pointless without tracking...

      prestigious board

      The hidden risk of prestigious boards

      High-profile directors bring experience, influence and credibility—but may lead to challenge being reduced and governance...

  • Comment
      • View all
    • leadership crisis

      How to fix the leadership crisis

      Unpopular opinion? It’s time for organisations to shift away from feelings to focus on competency...

      AI behaviour

      How do you measure AI adoption?

      It’s easy to produce metrics on AI software deployment, but these are pointless without tracking...

      risk management

      Why risk management requires good judgement

      Relying on probability models and mitigation plans is not enough—boards need to focus on making...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • governance

      How better governance helps private companies grow

      If governance is to become mature, management decision-making has no place on the board’s agenda,...

      future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

  • Board Careers
      • View All
    • female ceos

      FTSE 100 CEO appointments rise

      The number of CEO appointments has doubled in six months, although the global picture suggests...

      board role

      How to engage with outreach

      When board opportunities knock, should you answer the door? Here are tips from a new...

      growth

      Governance Guide: How boards drive growth

      The strategic role of the board is changing rapidly, in line with a shifting world....

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • FRC Annual Review of Audit Quality 2026

      This Financial Reporting Council report uses findings from its supervisory activities to assess audit quality...

      Governance Guide: How Boards Drive Growth

      This Board Agenda Governance Guide investigates how directors can evolve to drive performance and growth...

      Organizational Transformation in the Age of AI

      This World Economic Forum paper looks at how organisations must re-architect their workflows and operating...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

Ransomware warning as cybercriminals target large companies

by Gavin Hinks on July 9, 2019

Experts highlight ransomware risk as cybercriminals attack listed forensics company Eurofins Scientific, with reports that a ransom was paid.

cybersecurity, hacking, cybercrime, ransomware

Photo: Shutterstock

Favorite

While many commentators exuberantly laud current advances in technology, others are learning that the digital age comes with some serious downsides. Indeed, in the past week alone ransomware—a form of cyber extortion—has been described by experts as “commonplace”, with a major company alleged to have paid a ransom for the return of data.

The issue was brought into sharp relief this week with reports that Eurofins Scientific, a provider of forensics services to police forces across Europe, had suffered an attack that affected its ability to serve customers. Describing the attack as coming from “highly sophisticated and well-resourced perpetrators”, Eurofins said the ransomware appeared to be a new piece of malware—invasive software—that was “undetectable” to its security providers.

The attack began at the beginning of June but news emerged over the weekend that the incursion had been resolved by the payment of a ransom.

Eurofins has not commented on the ransom, though reports from other cybersecurity specialists suggest that the malware thought to be responsible, Ryuk, is believed to have earned its creators almost $4m in ransom payments so far from a raft of victims. Indeed, one payment traced by specialists ran to more than $700,000 in bitcoin transactions. Crowdstrike, a cybersecurity firm, says Ryuk is “specifically designed to target enterprise environments”.

Observers are surprised cybercriminals would target such a large company (Eurofins is listed on Euronext, Paris), but this is not the only case. US local authority Lake City, in Florida, recently paid half a million dollars to cybercriminals, as did another local government body, Riviera Beach.

Here in the UK, cybercrime made headlines last month when the band Radiohead was targeted. Extortionists threatened to post previously unpublished material online if the band refused to pay up. Members chose to release the music themselves instead, thus denying the criminals their leverage.

A growing threat

But ransomware is also in the news due to the sheer volume of criminal activity that appears to be under way. The global cost of ransomware attacks has been estimated to be $20bn by 2021 in ransom payments and lost business, making it the fastest growing form of cybercrime. Databarracks, a firm of IT disaster recovery experts, estimates 28% of companies will be hit by an attack in 2019, up from 16% three years ago.

What are the implications of such attacks and how should companies tackle ransom attempts?

According to Javvad Malik, security awareness advocate for KnowBe4, a security training provider, attacks are on the increase, though small and medium-sized companies are the main targets, along with underfunded sections of government, mostly because they lack sophisticated security measures. This week, Steve Wright, an adviser to the Bank of England, gave an interview in which he said small companies faced the same threat but with fewer defences.

He says that essential to any management of a ransomware attack is advance preparation, including having data backed up on a separate network.

Malik warns that demands for ransom will inevitably involve board members. “When it comes to the payment it’s not just an IT decision,” he says. This is because a decision to pay criminals will involve a strict process of documenting evidence to rule out the possibility of someone internal attempting to launder money or fund terrorists. “You need to exhaust every possibility,” says Malik.

With no data backed up or IT solution to break down the encryption used by ransomware, paying up may seem the only option for some companies. However, there are those who warn against it.

According to Peter Groucutt, managing director of Databarracks, paying ransom money is a mistake. He argues paying up could incite further attacks, or could be illegal in some cases. It’s not even certain payment will guarantee the return of data.
“At best paying the ransom means funding cybercriminals to carry out further attacks and, at worst, potentially funding terrorism, “ Groucutt says.

He echoes the advice that preparation is key; outright prevention is not viable so businesses should focus on having strategies in place to soften the blow of an attack, especially backup data.

Reflecting on the Radiohead incident, Groucutt adds: “Agreeing to pay a ransom demand isn’t conducive to long-term security and emboldens cybercriminals to continue to use this method.”

Whichever view you take, trends suggest many companies will soon face unsavoury demands from cybercriminals. Preparation looks like the only serious option.

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • FBI warns ransomware gangs are targeting M&A transactions
    November 18, 2021
    ransomware threat

    US crime agency says the hard deadlines involved in M&A transactions pressures victims to pay up for fear of affecting stock values.

  • Technology, cyber risk and ESG top list of business leaders' concerns
    June 8, 2022
    Digital code on skycrapers

    Mazars survey reveals 82% of executives plan to increase investment in IT systems, while 75% plan to boost spending on sustainability.

  • Are cyber disclosure demands too high?
    August 15, 2022
    cyber disclosure

    Organisations increasingly struggle with cybersecurity as they balance fear of reputational damage against cyber disclosure requirements.

  • Cyber criminals chase ransomware insurance money
    April 18, 2023
    ransomware insurance

    Specialist ransomware criminals are investigating victims’ insurance capacity—sometimes by blatantly asking companies outright.

Search


Follow Us

Most Popular

Featured Resources

The Future of FTSE 350 Chairs: Pathways, Pipelines & Barriers 2026

This report is a collaboration between the FTSE Women Leaders Review and Professor...

Agentic AI from principles to practice 

‘A C-suite guide to capturing value without losing control’, this Forvis Mazars...

Route to the Top: Europe 2026 

This survey report from Heidrick & Struggles finds that companies are tending...
board's role in a rewired world fgs 2026 cover

A hard job getting harder: The board's role in a rewired world

The role of a corporate director is demanding intellectually, ethically and strategically—and...

Boardroom resilience: Practical governance for risk, readiness and rapid response

Boards are operating in a world defined by uncertainty. Geopolitical tensions, climate...

Board Value Index Summer 2026

Board Intelligence found 86% of directors say rigid processes and inconsistent frameworks...

Governance Guide: Navigating Conflict in the Boardroom

The 'Governance Guide' on navigating conflict in the boardroom provides practical...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy