Dispute Resolution Managing Partner TL Lim recently spoke with the Hong Kong Economic Journal on the evolving ransomware landscape, which is becoming increasingly acute across Asia.
What we are seeing is a shift: ransomware is no longer just an IT issue – it is a business-critical event. Attacks are more targeted, more organised, and increasingly enabled by AI – whether in identifying vulnerabilities or even in how threat actors communicate and negotiate. One point worth emphasising: paying a ransom does not guarantee that stolen data will be deleted.
Organisations may find themselves exposed not only to repeat attacks, but also to legal, financial and regulatory consequences. At the same time, many incidents still come back to familiar ground – the human factor. Technology has advanced, but non‑technical gaps (awareness, decision-making, coordination) remain where things often break down.
If there is one takeaway, it is this: resilience needs to be proactive, not reactive. That means thinking beyond systems — to preparedness, governance, and how organisations will respond under pressure.


