A ransomware payment ban South Africa could adopt is now a live debate, and one of its loudest advocates is someone who has already paid. According to TechCentral, MIP Holdings CEO Richard Firth paid a ransom, saw what it bought, and now wants such payments outlawed. Orange Cyberdefense's Dominic White urges a different approach.

The disagreement matters beyond boardrooms. When criminals hold company data hostage, the information at risk usually belongs to ordinary customers and employees. How South Africa answers this question will shape how much say those people have in what happens next.

Why a ransom-paying CEO wants payments banned

Firth's position carries weight because it comes from direct experience. He is not arguing from theory; he has faced the decision, made the payment, and concluded that the country should take the option away from companies altogether.

The reporting summary does not spell out every part of his reasoning, so it would be wrong to put words in his mouth. But the logic of a ban is well understood. Ransomware groups keep attacking because it pays. If payment were illegal, the argument goes, the financial incentive to target South African organisations would shrink. A ban would also remove the pressure on an executive who is deciding, in the middle of a crisis, whether to pay. The law would make the decision for them.

There is also a fairness argument. A company that pays funds the next attack, and that cost is borne by every other organisation in the country.

Why security experts push back on a ban

Dominic White of Orange Cyberdefense argues for a different approach rather than an outright prohibition. The summary we have does not detail his specific proposals, so we will not guess at them. What we can say is that the wider policy debate gives critics several familiar concerns.

The first is that a ban can punish the victim. A company already dealing with locked systems and stolen data could also face legal exposure for trying to recover. The second is that a ban may drive payments underground: if paying is illegal, some victims may pay quietly and avoid reporting the attack, leaving authorities and other organisations with less information. The third is practical. Critics often argue that money is better spent on prevention, such as backups, network segmentation and incident response planning, so that companies are never forced to choose.

None of these points settles the question. They explain why sensible people, including those who have lived through an attack, land in different places.

Whether a ban would protect stolen personal data

This is the part that affects readers most directly. Paying a ransom does not guarantee anything. Criminals can keep copies of stolen data, sell it, or leak it later, whatever they promised. So a payment is a weak safeguard for your personal information even when it is made with the best intentions.

A ban would not undo that reality. If a company is breached, your data may already be in criminal hands. What a ban could change is the incentive structure for future attacks. What it cannot do on its own is make organisations store less data, encrypt it properly, or notify affected people quickly. Those duties sit in separate rules and practices.

Extortion groups also do not always rely on encryption. Some simply steal data and threaten to publish it, which means a company can have fully working systems and still face a demand. Our coverage of how ShinyHunters steals and leaks data from large organisations shows how this pressure model works in practice, and why a payment promise from criminals is not something to rely on.

What This Means For You

Most people will never be the one deciding whether to pay a ransom. You are far more likely to be a customer whose details sit inside a company that gets hit. That means the policy debate is less important to you day to day than your own preparation.

Whatever South Africa decides, assume that a breach at any organisation holding your data is possible. A ban may eventually reduce attacks, but it will not remove the risk of exposure overnight, and it will not tell you when your own information has leaked.

What to do if your data is held for ransom

If a company tells you your data was involved in a ransomware or extortion incident, act on your own behalf rather than waiting for the outcome of any negotiation.

  • Change passwords for the affected service and anywhere you reused them, and turn on multi-factor authentication.
  • Watch your accounts for unusual transactions, and contact your bank if anything looks wrong.
  • Be alert to phishing. Stolen contact details are often used for convincing follow-up scams that reference the breach.
  • Ask the company what was taken, whether it paid, and what it is doing to protect you.
  • Limit what you share. The less you hand over, the less there is to steal.

For a concrete example of these steps applied to a South African incident, see our guide on what Standard Bank clients should do now.

Key takeaways

The debate over a ransomware payment ban South Africa might introduce is really a debate about incentives, victims and trade-offs. Firth's call carries the credibility of someone who paid and regrets what it achieved. White's alternative reflects the concern that a ban alone may not fix the underlying weakness. Both positions accept that ransom payments are a poor way to protect people's data.

Do not wait for legislation. Secure your accounts, stay suspicious of messages that mention a breach, and follow the practical steps in our Standard Bank guide. To understand how extortion crews actually operate, read our ShinyHunters coverage linked above.