It is great that your company is investing more in security, but that it is not the overall industry trend of investment necessary to mitigate ransomware. We are seeing a repeat of what companies did during the early years of data breaches. Ignore the risks, transfer the risk to insurance, but not actually improve the security. It was not until regulations required them to notify customers of a data breach (then they had to pay for credit monitoring, etc.) did things change. They went kicking and screaming, saying such a privacy regulation would bankrupt them. It did not. It was just them fighting against spending to keep their customers data secure. Same is true now. Most companies want to secure a ransomware insurance policy versus spend on security and IT backups.
The financial incentives, which should align to the benefit of the consumer, were upside down. It took regulation to change things. Same is true now. I see it every day.
RE: Paying Ransomware Should be Illegal