Join the next in-person event in London - spaces limited:

register now
Close Notice

We Should All Be a Lot Angrier About Ransomware

Posted : 10 August 2026

Posted In : Blogs

Businessman working on laptop in night office.
Matt Smith

Written by:

Matt Smith, Chief Technical Officer

Cynthia Kaiser, formerly of the FBI, on why ransomware is hitting mid-sized businesses harder than ever, and what that means for the next Board conversation.

“I’m a recovering government official in industry now.”

That’s how Cynthia Kaiser opened when we sat down with her to talk about ransomware. Twenty years inside the FBI, the back half of it running cyber threat intelligence and policy, briefing the White House daily during some of the country’s worst cyber incidents, before she moved into industry to lead threat research at Halcyon. I’ve sat through a lot of cybersecurity interviews, and most of the time you can predict the next sentence before it lands. I couldn’t predict a single one of hers.

As always, what I want to pull from a conversation like this isn’t just what she said, it’s what it means for the mid-sized UK businesses we work with every day, the ones without a large security team, who might already be feeling some of this without quite having the words for it yet.

The Wednesday night problem

Here’s the line that’s stayed with me since. Cynthia was talking about how fast ransomware moves now compared to a few years ago, and she put it like this: “When you put your phone down for dinner on Wednesday night with your family, by the time you pick it back up, a ransomware attack has occurred.”

Wednesday evening, she said, is the single most common time for it to start, with first access to full encryption averaging four hours for one of the groups her team tracks, sometimes under one. Sit with that for a second if you’re the person responsible for a mid-sized business’s systems: there is no window where you notice something’s wrong and step in, the window has already closed by the time most people would think to look.

Why the big gangs breaking up made things worse, not better

What’s changed most in the last year isn’t a new strain of malware or a fresh exploit, which is what I’d have guessed before watching this. She went somewhere more interesting. When Lockbit and AlphV came apart in 2024, taken down by law enforcement action, she watched the threat landscape splinter rather than shrink.

“The threat actors went and created their own smaller groups,” she said, tighter and harder to infiltrate, but also cut off from the shared expertise that used to move between the bigger operations. So, they’ve compensated by casting wider, with attacks on small and mid-sized businesses happening at roughly four times the rate they are on large enterprises. For this, they will aim for smaller individual payouts, but far more often. Nobody decided mid-market businesses weren’t worth targeting, there are simply more people running these operations now and they need more victims to make the maths work, which means you were never off the radar, you’re the volume.

The number nobody prices in

This is the part I think most Boards get wrong, and Cynthia’s been watching people get it wrong for years. Everyone prices the ransom based on affordability or insurance coverage, but almost nobody prices the operational downtime.

“That time period is over twenty days of downtime on average,” she said. “There are entities that are down for weeks and weeks.” And paying doesn’t make the problem disappear, it tells the people who attacked you that you’re worth attacking again: “The threat actors know that you paid. They’re going to come back again and again.” I don’t think I’ve sat in a single Board conversation where that number, twenty days, came up before the ransom figure did, and it should.

A phone call beats a zero day

Everyone in this industry currently has an opinion on AI and ransomware, and most of it is the same opinion stated slightly differently, but Cynthia’s version cut through, mostly because it wasn’t really about the technology. “It’s easier to lie with AI,” she said, pointing to better phishing emails, deepfake videos are convincing enough to fool a help desk and voice cloning that’s good enough to authorise a password reset over the phone, all of it real and all of it already happening.

But then there’s a case she described that needed none of it. A ransomware group that specifically targets law firms simply sent someone into the building, and staff let them in, sat them down and gave them hands on a keyboard. “I was like, are you kidding me?” she said, and she wasn’t performing surprise for the camera, you could tell it had got to her even after everything she’s seen: “It takes a lot for me to be shocked.” That’s the detail I keep coming back to: we spend so much energy worrying about how sophisticated attackers have become, and sometimes the whole operation still comes down to one person holding a door open.

The fence with the doors left open

On investing in detection and response, she had a line I’ve already used twice since in client conversations, without quite meaning to steal it: “You can’t build a great electric fence and then just leave the doors open on the inside. You have to do both.” She also had no patience for the amount of hype on the expo floor, vendors promising sophisticated AI capability that, when she looked underneath it, was often just a basic prompt to an off the shelf model dressed up as a proper product: “I don’t understand how this isn’t just a prompt,” she said, and it was refreshing to hear someone put it that plainly.

The conversation that moves a board

Years ago, trying to get cyber defence funding out of Congress, she learned that talking about cyber threats got her nowhere: “I had to talk to them in terms of what they cared about. For them, it was their constituents. It was the human factor. Ransomware is targeting hospitals, and when a hospital is down, people die.”

That’s the same translation I have to make constantly. Nobody on a Board wants to hear about detection coverage or mean time to respond. They want to know what happens to the business if the systems are down for three weeks (the twenty days Cynthia mentioned earlier), and whether people still get paid at the end of the month. Say it that way and the room changes.

Angrier, not calmer

Her closing thought is the one I’d want you to leave with, more than any of the detail above: “We should all be a lot angrier about cybercrime than we are. They happen so often that it’s not even in the press any longer. It is stealing a generation of wealth from our society. It is causing people to lose businesses, to lose lives.”

And the second half of that thought matters just as much: even if your business did everything right two years ago, that doesn’t mean it’s right now. “Ransomware is a lot different than it was just two years ago, and even if you did everything right back then, you have to relook, you have to change and you have to think about what the threats are today and how you can mitigate them moving forward.”

If there’s one thing worth checking this week, off the back of everything above, it’s whether a voice on the phone can still move money, reset a password or grant access in your business without a second person confirming it first. Almost everything in this conversation traces back to that one gap somewhere.

Watch the whole interview for the full picture: Cynthia Kaiser, Senior Vice President at Halcyon’s Ransomware Research Center, on ransomware, mid-market risk and what a thirty-day plan looks like. Watch it here.

Share

Related insights

Getting started with us couldn’t be easier.

Just use the form or call us on +44 (0) 1223 834 333 to set up a call.

Sign up for our monthly Security Decoded newsletter
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

3rd Party Cookies

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.