Key Takeaways
- Ransomware attacks have surged 650 % since 2019, moving from a latent risk to an active, financially motivated threat across Asia and Vietnam.
- Technical defenses alone cannot prevent incidents stemming from human error or third‑party vulnerabilities; a robust, executive‑led incident response (IR) plan is essential.
- Effective response requires clear coordination among IT, finance, legal, and senior leadership, with defined roles and decision‑making authority.
- Cyber insurance provides more than payouts—it grants immediate access to forensic, legal, communications, and recovery specialists that accelerate containment and remediation.
- IR plans must be reviewed, updated, and tested regularly to keep pace with evolving threats such as AI‑enabled attacks, state‑linked campaigns, and new data‑protection regulations.
- Investing in comprehensive cyber resilience reduces disruption, protects reputation, and creates a competitive advantage for long‑term growth.
Overview of the Rising Ransomware Threat
According to Aon’s Risk Based Security analysis, the frequency of ransomware attacks climbed 650 % by Q4 2025 compared with 2019 levels. This sharp increase illustrates that ransomware is no longer a distant possibility but a prevalent, financially driven menace. Across Asia, roughly 660 organisations have appeared on ransomware leak sites, underscoring an organized trend of extortion‑focused campaigns. In Vietnam alone, ten ransomware incidents targeting large enterprises have been officially recorded in the past two years, with many additional attacks likely unreported. The data make clear that every organization, regardless of size or sector, faces a heightened probability of encountering a ransomware event.
Geographic and Sector‑Specific Implications
The concentration of reported attacks in Asia reflects both the region’s rapid digitalisation and the growing sophistication of criminal groups that target valuable data for monetary gain. Vietnamese firms, in particular, have experienced a noticeable uptick in ransomware attempts, often exploiting gaps in employee awareness or weak links in third‑party technology providers. Even companies that have invested heavily in endpoint protection, network segmentation, and intrusion detection remain vulnerable to social engineering, compromised credentials, or supply‑chain weaknesses. Consequently, reliance on preventive controls alone is insufficient; a holistic approach that includes preparedness for inevitable breaches is required.
Why Technical Controls Are Not Enough
Investments in firewalls, anti‑malware tools, and vulnerability management are vital, yet they cannot eradicate risk arising from human error or third‑party exposures. Employees may inadvertently click malicious links, use weak passwords, or mishandle privileged credentials, providing attackers with a foothold. Likewise, reliance on external platforms—cloud services, SaaS applications, or outsourced IT—introduces vectors that lie outside the direct control of an organization’s security team. Recognizing these limitations, experts stress that a well‑defined incident response plan, which outlines actions before, during, and after an attack, is critical to limiting damage and restoring operations swiftly.
The Cost of Poor Cross‑Functional Coordination
When a ransomware incident unfolds, delays or inconsistencies in response often stem from gaps in communication and decision‑making among IT, finance, legal, and executive leadership. Without pre‑established processes, teams may duplicate efforts, miss critical notification deadlines, or struggle to allocate resources effectively. Such fragmentation can extend downtime, increase financial losses, amplify regulatory penalties, and erode stakeholder trust. Therefore, building a coordinated crisis response framework—where each function knows its responsibilities and authority—is as important as the technical safeguards themselves.
Insights from Aon’s Ransomware Tabletop Exercise for Executives
Aon conducted a Ransomware Tabletop Exercise for Executives in Ho Chi Minh City (May 26) and Hanoi (May 28), placing senior leaders in a simulated attack scenario. Participants assumed the roles of CEO, CISO, CFO, CRO, or Legal Counsel and were tasked with discussing response options in real time. The exercise highlighted that while the IT function supplies essential technical details—such as the scope of encryption, expected downtime, and recovery costs—strategic decisions cannot be made in isolation. Leadership must weigh operational continuity, financial implications, legal obligations, and reputational risks, necessitating input from multiple disciplines.
Decision‑Making Beyond the IT Function
Key decisions during a ransomware event extend far beyond technical remediation. Whether to pay a ransom, how to negotiate with threat actors, and what payment methods to use require financial and legal expertise to assess potential liabilities and regulatory compliance. Determining which parties—customers, regulators, partners, or law‑enforcement—must be notified hinges on legal counsel’s interpretation of breach‑notification laws. Crafting an appropriate communication strategy demands input from public relations and corporate affairs to preserve brand integrity. Engaging external specialists, such as forensic investigators or crisis‑management consultants, also benefits from procurement and risk‑management oversight. Thus, a cross‑functional leadership team is indispensable for balanced, informed choices.
The Role of Senior Leadership in Balancing Priorities
Senior executives must serve as the ultimate arbitrators, balancing the need to maintain business operations against financial pressures and reputational concerns. A hasty decision to pay a ransom might restore systems quickly but could fund further criminal activity and invite future attacks. Conversely, refusing to pay may prolong recovery, increase losses, and trigger customer dissatisfaction. Leaders must also consider the long‑term impact on brand perception, investor confidence, and regulatory standing. By establishing clear escalation paths and empowering designated decision‑makers, organizations can reduce ambiguity and act decisively when minutes count.
Cyber Insurance as a Force Multiplier
Beyond its traditional role of indemnifying financial losses, modern cyber insurance policies provide immediate access to a suite of specialist services during an incident. These include forensic analysis to identify the attack vector, legal advisory to navigate regulatory obligations, communications support to manage stakeholder messaging, and system recovery specialists to rebuild compromised environments. Leveraging these resources can dramatically shorten containment time, improve the accuracy of impact assessments, and facilitate a smoother return to normal operations. Consequently, cyber insurance should be viewed as an integral component of an organization’s incident response readiness rather than a mere back‑stop financial tool.
Maturity of the Cyber Insurance Market and Integration Practices
The cyber insurance market has entered a more mature phase, marked by an influx of new insurers, expanded underwriting capacity, and increasingly competitive terms that favor buyers. This environment enables organizations to tailor coverage to their specific risk profiles, adding endorsements for ransomware extortion, business interruption, and third‑party liability. To maximize value, firms should proactively review policy details, understand the exact resources and services included, and embed those provisions into their IR plans. Regular liaison with brokers and carriers ensures that coverage evolves alongside emerging threats and that claims processes are well understood before an incident occurs.
Keeping Incident Response Plans Current Amid Evolving Threats
The cyber risk landscape is dynamic; new attack vectors emerge from advances in artificial intelligence, the proliferation of state‑linked or geopolitical campaigns targeting critical infrastructure, and shifting regulatory landscapes concerning data protection, privacy, and AI use. Consequently, incident response plans must be reviewed, updated, and exercised at least annually—or more frequently when significant changes occur. Tabletop exercises, red‑team/blue‑team simulations, and after‑action reviews help identify gaps, refine roles, and validate communication channels. Continuous improvement ensures that plans remain effective against both known threats and novel, unexpected scenarios.
Strategic Benefits of Investing in Cyber Resilience
Organizations that treat cyber resilience as a strategic priority—combining robust technical defenses, well‑tested IR plans, cross‑functional governance, and appropriate cyber‑insurance coverage—are better positioned to minimize disruption, contain costs, and protect reputation. Such preparedness not only reduces the likelihood of severe losses but also enhances competitiveness by demonstrating reliability to customers, partners, and investors. Over the long term, a strong cyber‑resilience posture supports sustainable growth, enables confident digital transformation, and reinforces brand trust in an increasingly threat‑laden environment.
Aon’s Local Presence and Collaborative Initiatives in Vietnam
Aon has operated in Vietnam since 1993, maintaining over 150 professionals across its Hanoi and Ho Chi Minh City offices. As a leading provider of insurance and reinsurance brokerage, corporate risk consulting, and employee benefits solutions, Aon Vietnam leverages the global reach and analytical capabilities of the Aon Group. Recent initiatives underscore the firm’s commitment to strengthening regional cyber defenses: a partnership with FPT to help enterprises build a “digital shield,” the appointment of Winnie Loh to lead Aon’s Southeast Asia real‑estate and data‑centre practice, and ongoing advocacy for improved data‑protection measures amid Vietnam’s rapid digital boom. These efforts reflect a broader industry push to elevate cyber risk management from a technical concern to a board‑level imperative.

