Key Takeaways

  • No More Ransom helps ransomware victims identify infections and recover encrypted data without paying attackers
  • ENISA ranks ransomware as the most impactful cyber threat across the EU, despite criminal groups fragmenting under law-enforcement pressure
  • Enterprises can improve resilience through tested backups, network segmentation, Zero Trust controls, and prepared incident-response procedures

No More Ransom is giving ransomware victims an alternative to a decision that can otherwise feel brutally simple: pay criminals or lose access to critical data. The public-private partnership provides access to decryption tools and guidance designed to help organizations and individuals recover encrypted information without funding their attackers.

The initiative matters because ransomware is no longer confined to opportunistic file encryption. Modern campaigns frequently combine encryption with data theft, leak threats, operational disruption, and pressure directed at customers or employees. Even when backups allow an organization to restore systems, stolen information can give attackers another route to extortion.

That changes the business calculation. A ransom payment may not secure complete data recovery, prevent publication, or bring operations back online quickly. It can also encourage repeat targeting by signaling that an organization is willing to negotiate. Free decryptors will not resolve every incident, since tools generally apply only to particular ransomware families and variants, but they can remove payment from the equation in cases where researchers have identified a workable recovery method.

The scale of the threat remains substantial. The ENISA Threat Landscape 2025 examined 4,875 cybersecurity incidents across the EU from July 2024 to June 2025 and identified ransomware as the most impactful cyber threat. Within cybercrime-related incidents, ransomware represented more than 80% of attacks during that period. Akira, Qilin, and SafePay were among the strains dominating the European landscape.

Public administration illustrates why raw incident counts tell only part of the story. Ransomware accounted for around 10% of all reported cyber incidents in that sector during 2024, but those attacks were among the most disruptive to services. A successful compromise can interrupt citizen portals, payment systems, licensing operations, healthcare administration, and internal communications at the same time. The visible cases may be only the tip of the iceberg, given uneven reporting and the reluctance of some victims to disclose attacks.

Taking down one major ransomware operation rarely dismantles the wider market. Law-enforcement pressure on LockBit contributed to fragmentation, but affiliates, developers, access brokers, and negotiators can migrate to other brands. Dozens of variants and affiliate programs can emerge from the same criminal talent pool. The name on the ransom note changes. The commercial machinery behind it often survives.

Where does that leave enterprise security leaders? Decryption resources should sit inside a wider response plan, not serve as the plan itself. Organizations need a reliable way to identify the ransomware strain, isolate affected assets, preserve forensic evidence, notify appropriate authorities, and assess whether information was exfiltrated. Restoring files is important. Understanding how the attacker entered, and whether access remains, is just as important.

Preventive architecture also has a role. NIST SP 800-207 Zero Trust Architecture describes an approach in which access decisions are based on explicit verification rather than assumed trust tied to network location. Applied pragmatically, that can mean stronger identity controls, limited privileges, segmented environments, device checks, and closer scrutiny of unusual access. The EU’s NIS2 enforcement regime adds regulatory pressure around risk management and incident reporting.

Enterprises increasingly use CrowdStrike, Palo Alto Networks, and SentinelOne for endpoint detection, threat intelligence, and incident response. Technology helps, but configuration and operational discipline still shape the outcome. An alert that nobody investigates at 2 a.m. offers limited protection.

Tested offline or immutable backups remain especially valuable. So do rehearsed recovery procedures, because an untested backup can fail at precisely the wrong moment. Organizations should also establish in advance who can authorize system isolation, engage external responders, communicate with regulators, and evaluate tools available through No More Ransom.

Can ransomware be eliminated outright? Probably not in the near term. Its affiliate model is too adaptable, and vulnerable targets remain plentiful. But these free decryption initiatives can reduce criminal leverage one recoverable infection at a time. Combined with segmentation, Zero Trust practices, prepared response teams, and dependable backups, free decryption gives victims something attackers would rather they did not have: another option.