What this means for your decisions
1
Not paying is increasingly viable. Professional negotiation support pushes non-payment rates above 70%. Without support, victims pay at 2× the rate.
2
54% of victims had advance warning they didn't act on. Credential monitoring in dark web markets provides weeks of lead time before an attack is detected internally.
3
The 2–4 week dwell period is your detection window. Attackers are silent but active before encryption. Endpoint detection that catches lateral movement stops the attack entirely.
4
Brand takedowns don't stop the people. When a group is disrupted, affiliates migrate to a new brand within 60–90 days. The skills, relationships, and protection persist.