What needs to happen is that they need to cop it on the chin and do better with their security.
These companies need to tell the scammers to bugger off. If they keep capitulating, the scammers will keep on doing it.
There have already been several cases of scammers continuing to threaten companies, even after the first ransom has been paid.