• Cybercriminals only ever act in their own interest — even when one ransomware group turns on another, the goal is still leverage, control and profit.
  • An attacker’s offer to “help” is not a recovery option — there is no proof they can restore your data and no obligation for a criminal organisation to keep any promise.
  • For regulated firms, engaging with an attacker is a governance and compliance risk — it exposes client confidentiality, audit trails and professional standing to further harm.
  • The only reliable route through an incident is proper protection and trusted support — tested backups, early monitoring and a rehearsed response plan.
  • Decisions made under pressure define the outcome — a governed, pre-agreed plan limits damage; improvising can make things far worse.

Every so often, a story emerges from the cybercrime world that almost sounds like good news. One ransomware group starts threatening another. They promise to expose identities, leak stolen data, and, most tellingly, offer to “help” the victims caught in the crossfire. For a moment, it can feel like a kind of rough justice, the criminals finally getting a taste of their own medicine.

For a regulated firm, though, that feeling is precisely where the danger begins. When you are responsible for client money, sensitive personal data, and a professional reputation built over years, the temptation to grasp at any lifeline during an incident is understandable. But the moment that lifeline is offered by a criminal, it stops being a rescue and becomes a fresh liability. This post looks at why, and what a governed, board-ready response should look like instead.

There is only one thing you can rely on cybercriminals for

It is worth stating the uncomfortable truth plainly: the only thing you can reliably depend on a cybercriminal to do is act in their own interest. When one ransomware operation recently began threatening a rival, claiming it would unmask them, leak their data, and even assist their victims in unlocking files, the motivation had not changed at all. It was still about leverage, pressure and profit. Turning on a competitor is simply another way of gaining an advantage in a marketplace built on extortion.

That distinction matters enormously for a professional firm. In your world, promises are backed by regulation, contracts, professional indemnity and a duty of care. In theirs, there is no such framework. An offer to “help” is not a service-level agreement. It is bait, designed to extract something further, whether that is money, access, or simply information about how you respond under stress.

Why the “helpful” attacker is a trap, not a lifeline

Imagine your firm has been hit. Files are encrypted, staff are locked out, and clients are starting to ask questions. Then a message arrives from a second group claiming they can undo the damage the first group caused. In that moment, exhausted and under pressure, it is genuinely tempting to consider it.

Here is the reality. There is no proof that such a group can recover your data, and even if they could, you would still be dealing with a criminal organisation that has no obligation whatsoever to follow through on anything it promises. It is like being caught between two con artists and betting your firm’s future on one of them turning out to be honest. That is not a position any board would knowingly choose. The very same social-engineering instincts that criminals exploit through fake alerts and bogus verification pages are at work here, dressed up as generosity rather than urgency. If you want a clear illustration of how convincing these manipulations have become, our recent piece on how criminals weaponise everyday trust is a sobering read: the fake CAPTCHA trap that turns “prove you’re human” into a costly scam.

The compliance dimension most firms overlook

For an unregulated business, engaging with an attacker is reckless. For a regulated firm, it can be a reportable failure. The moment you enter into any dialogue with a criminal group, you introduce questions that your regulator, your insurer and your clients are entitled to ask. Did you knowingly transact with a sanctioned entity? Did you expose client data to an additional party? Can you evidence that every decision was made in the client’s best interest?

These are not hypothetical concerns. In sectors such as legal services, financial advice, accountancy and insurance broking, the expectation is that incidents are handled through documented, defensible processes, not improvised deals struck in a panic. A single poorly judged decision can transform a contained technical incident into a governance crisis, complete with regulatory scrutiny and lasting damage to client confidence. This is exactly why routine-looking risks now demand board-level attention, a theme we explored in detail in our analysis of why a seemingly routine software update has become a board-level risk.

What a reliable response actually looks like

If the answer is never “trust another attacker”, then what is the answer? It is unglamorous but dependable: proper protection put in place before anything happens, and trusted support to call on if it does. For a regulated firm, that framework rests on three pillars.

  1. Backups that are tested and accessible. Backups only count if you have proven you can restore from them. A backup you have never tested is a hope, not a control. Regular, documented restore tests give you a genuine alternative to any attacker’s “offer”, because you already hold the keys to your own recovery.
  2. Monitoring that spots trouble early. Many serious incidents begin quietly, with unusual logins, unexpected data transfers or privilege changes that go unnoticed for days. Proactive monitoring shortens that window dramatically, giving you the chance to contain an incident before it becomes a crisis, and before anyone is tempted to consider a criminal’s help.
  3. A clear, rehearsed response plan. When an incident hits, you will be making decisions under intense pressure, and those decisions will either limit the damage or make it far worse. A response plan that names who does what, who is notified, and how evidence is preserved removes guesswork at the worst possible moment. Increasingly, that plan also needs to account for automated tools acting inside your systems, a governance challenge we unpacked in our guide to how AI agents can create governance blind spots in regulated firms.

Decisions under pressure define the outcome

The uncomfortable heart of any cyber incident is that it forces significant decisions in a compressed, stressful timeframe. That is by design; attackers rely on pressure to push otherwise sensible people into poor choices. The firms that come through well are not the ones that improvise brilliantly on the day. They are the ones that decided, calmly and in advance, what they would do, so that on the day they are simply executing a plan rather than inventing one.

This is where a trusted IT partner earns their place. Working with people whose job is to defend your business, not exploit it, means that when the worst happens you have expert support acting in your interest, with a documented, defensible approach that stands up to regulatory and client scrutiny.

The bottom line for regulated firms

When cybercriminals turn on each other, treat it as a reminder, not an opportunity. The infighting changes nothing about their nature or their reliability. Your firm’s options during an incident should never include trusting another attacker, no matter how convincing the offer or how desperate the moment.

The reliable path is the one you build in advance: tested backups, early monitoring, a rehearsed plan, and trusted support. If you are not completely confident in how your firm would respond to an attack today, that gap is itself a governance risk worth closing. We would be glad to help you build a strategy that protects your clients, your compliance position and your reputation, so that whatever the criminals do next, your response is entirely your own.

What next?

One of my passions is helping businesses to succeed and if I can help you save some money as well – even better. You can fill out our contact form, phone us or click on the appointment button below and let’s start a conversation to see if I can help your business. Our guarantee:

  • There are no hidden charges – this is a 100% free 15 minute consultation with no hidden charges.
  • We will never spam you or sell on your contact details.
  • We will treat your information with absolute confidentiality.
AI
Illustration representing Microsoft 365 Copilot Wave 3 AI agents working within a business environment, symbolising automated workflows under governance oversight.

Copilot Wave 3, What It Means for Governance

Copilot Wave 3 has landed, and this release feels different. AI is moving from helping your team to acting on its behalf, through custom agents and a smarter, context-aware Copilot. For regulated firms, that shift is an opportunity, but only if governance keeps pace. Here's what's changing and how to stay in control.

Cyber Security
A close-up of a CAPTCHA-style "prove you're not a robot" verification prompt on a computer screen, illustrating the fake CAPTCHA scam targeting professional firms.

The Fake CAPTCHA Trap: “Prove You’re Human” With Fresh Suspicion

CAPTCHAs are so familiar that we barely register them, and that trust is exactly what criminals are now exploiting. A new breed of fake verification page asks you to "prove you're human" by sending a text, quietly racking up premium-rate charges that only surface later. For regulated firms, the stakes reach further than the bill. Here's how the trap works, and how to protect your team.

AI
Rows of identical humanoid robots beside a December wall calendar with a Friday date pinned, illustrating the question of whether regulated firms should pause AI use on Fridays.

Should Your Firm Hit Pause on AI Every Friday Afternoon?

By the close of the working week, even careful professional teams are stretched thin, and that is exactly when AI-generated work slips through unchecked. The output looks board-ready, so a tired reviewer approves it without a second read. For regulated firms, that quiet moment of over-trust is a genuine compliance risk. So should you pause AI on Friday afternoons?

Cyber Security
A laptop screen displaying a Windows 11 update prompt, illustrating the risk of a convincing fake update targeting regulated professional firms.

Why a Routine Update Has Become a Board-Level Risk

For regulated firms, a routine software update should never become a compliance incident. Yet a highly convincing fake Windows 11 update is now fooling even experienced professionals, and a single click can expose client data. This post explains how the scam works, why it slips past security tools, and the governance-led steps every professional firm should take to stay protected and audit-ready.