To pay or not to pay: build the ransom decision framework before you need it
Key takeaways
- Decide who's in the room and what they need before an incident — the middle of one is the worst time to invent the process.
- Recoverability from backups is the biggest lever; sanctions exposure can make payment unlawful regardless of the business case.
- Payment guarantees nothing — decryptors are often slow or incomplete, and 'we'll delete the data' is a criminal's unverifiable promise.
Decide the framework, not the answer, in advance
The worst possible time to first debate whether to pay a ransom is at 2am in the middle of an active incident. The organizations that navigate this well have decided the framework in advance: who is in the room when the question comes up, what information they need in front of them, and what legal and regulatory constraints bound the choice before business judgment even enters. You can't pre-decide the answer — but you can pre-decide the process, and that's most of the battle.
The inputs you can know beforehand
The core inputs are knowable ahead of time. How recoverable are you from backups — the single biggest lever on whether payment is even relevant? What is the scope and sensitivity of any data already stolen? What does a day of business interruption actually cost? And critically, is payment lawful at all: if the actor is tied to a sanctioned entity, paying can carry sanctions exposure regardless of the business case, which is a question for counsel, not the incident bridge.
Payment is not recovery
It is worth being clear-eyed that payment does not guarantee recovery. Attacker-supplied decryptors are frequently slow, incomplete, or buggy, and paying for a promise to delete stolen data is buying a criminal's word with no way to verify it. These outcomes should be modeled honestly, not assumed favorable. Payment buys a chance at a faster recovery and a chance the data stays private — chances, not certainties.
Write the one-page memo now
The practical step is to write a one-page decision memo template today — naming the decision-makers, the legal, incident response, and insurer contacts, and the specific questions each must answer — so that a live incident fills in a known form rather than inventing the process under pressure. Loop in legal counsel and your insurer's breach panel before an incident, not during one. When the note appears, you want to be executing a plan, not writing one.