How is applying good security controls not in their best interest? Right now, companies are transferring the risk to insurance, instead of investing in good security.
Regardless, the problem gets worse over time as payments are made, making the RISKS greater for everyone! Paying ransoms is a short term fix that creates a long term cancer. Without change, more and more companies will go out of business because of ransomware (current stats show between 60%-90% of SMB are out of business within 2 years of a cybersecurity incident).
There are no silver-bullet technical solutions! There won't ever be anything that can block all the potential attack vectors. The way to stop these attacks is to target the motivation of the attackers themselves.
RE: Paying Ransomware Should be Illegal