Key Takeaways

  • Businesses are urged to combine employee education with layered technical controls as AI makes ransomware campaigns more convincing.
  • Phishing and vulnerability exploitation remain leading entry points, while downtime and recovery costs can exceed the ransom itself.
  • Multi-factor authentication, restricted access, segmented networks and tested offline backups can reduce operational exposure.

The Hartford is calling on corporate leaders to treat ransomware as an operational and financial risk, not simply an IT problem, as artificial intelligence helps attackers create more persuasive phishing messages, voice impersonations and malicious content.

“A solid cybersecurity strategy with the ability to pivot to changing threats is essential for any business,” said the global head of professional liability and cyber at The Hartford. “We’re seeing corporate leaders continue to note their concern for how the use of AI may enhance ransomware capabilities and increase risk.”

That warning arrives against a difficult threat backdrop. Ransomware attacks surged 25% in 2025 according to recent estimates. The European Union Agency for Cybersecurity, or ENISA, identified ransomware as the most impactful cyber threat in the EU in its 2025 threat landscape and observed 82 ransomware variants during the reporting period.

AI does not fundamentally change what ransomware does. The malware can still encrypt files, disrupt systems and support data theft or extortion. It can, however, improve the social engineering surrounding an attack. A message written in a familiar style, a convincing executive voice recording or a tailored request based on public information may be harder for an employee to dismiss.

Paying a ransom does not ensure recovery. Attackers may fail to provide a working decryption key, demand additional money or retain stolen information for later extortion. Before considering payment, businesses typically need to determine whether data can be restored from backups, whether an incident response provider can recover affected systems and what legal or regulatory issues apply. Those decisions tend to be far easier when an incident plan has already assigned authority to security, legal, finance and executive teams.

The ransom itself may not even be the largest expense, as operational downtime can inflict severe financial damage. Industry research indicates the average business interruption following a ransomware attack can stretch to 24 days.

Could a smaller company absorb more than three weeks of disrupted billing, customer service or production? For many, the answer depends on cash reserves, contractual obligations and whether essential work can continue manually. Reputational damage can linger too, particularly when customers question how their information was protected.

Prevention still starts with fairly unglamorous controls. ENISA found that phishing accounted for 60% of initial access methods, while vulnerability exploitation represented 21.3%. Regular phishing exercises can help employees recognize unusual attachments, urgent payment requests and attempts to capture credentials. Training once a year is unlikely to reflect the speed at which lures and impersonation tactics change.

Technical guardrails provide another layer. The principle of least privilege limits employees to the systems and information needed for their roles, reducing the territory available to an intruder using a compromised account. Multi-factor authentication can make stolen passwords less useful, although organizations should favor stronger methods where practical and monitor suspicious authentication prompts.

The Cybersecurity and Infrastructure Security Agency also emphasizes rapid patching, network segmentation and offline or immutable backups. Backups should be isolated from production credentials and tested through restoration exercises. A backup that exists but cannot be restored under pressure offers limited resilience.

For management teams looking to organize the work, the National Institute of Standards and Technology Cybersecurity Framework 2.0 groups security activity into govern, identify, protect, detect, respond and recover. That structure can help connect board oversight, asset inventories, employee controls, monitoring and recovery planning. Tools matter, of course. But this guidance points to a wider reality: resilience depends on people knowing what to do before one convincing click becomes a companywide shutdown.