Nobody plans to pay a ransom. Then the backups turn out to be encrypted too, the business has been down for four days, and the number on the screen starts to look like the cheaper option. This post is about making that decision with clear eyes, before you are in the room where it has to be made.
This is not legal advice. It is what an engineer who has sat through those conversations wants you to know before you have one.
The legal side: sanctions and reporting
In the United States, the Treasury Department's Office of Foreign Assets Control has issued guidance that paying a ransom to a sanctioned person or group can violate sanctions law, and that the payer can be liable even without knowing who was on the other end. Several ransomware groups and their affiliates have been sanctioned by name. This is why breach counsel and the negotiation firm check the group's identity against the sanctions list before any payment is discussed.
Payment also does not remove reporting obligations. If personal data was accessed, state breach notification laws, HIPAA, and contractual duties still apply. A ransom paid to keep data private does not make the breach legally disappear.
- Never negotiate or pay without counsel. The carrier's assigned law firm handles this for a reason.
- Use a specialist negotiation and payment firm. They perform the sanctions screening, handle the cryptocurrency, and document everything for the insurer and regulators.
- Expect the FBI to be involved. Reporting to law enforcement is usually a policy condition and can be a mitigating factor if sanctions questions arise.
The practical side: what paying actually buys
A payment buys a decryption tool and a promise. The tool is software written by criminals, and it is often slow, buggy, and fails on large files or on some file types. Recovery with a working decryptor is still a full rebuild project; you are decrypting data onto systems that must be rebuilt anyway because the attacker was inside them.
The promise is that stolen data will be deleted and not published. There is no way to verify deletion. Groups have been known to leak or resell data after payment, and to return for a second payment when the first was paid quickly. Paying also marks you as a payer.
- Decryptors typically need to be run per machine and may need the attacker's help to work at all. Budget time for it.
- Some files will not decrypt. Databases and large files are the usual casualties. You still need backups.
- Payment does not remove the attacker's access. Every account, every persistence mechanism, every backdoor still has to be found and removed.
- Check for a free decryptor first. The No More Ransom project maintains a list of tools for families whose keys have been recovered or whose encryption was flawed.
When people do pay
Companies pay when the alternative is going out of business, and that alternative is real when backups were destroyed or never existed, when the outage cost per day exceeds the demand, or when the exposed data would cause harm that outweighs the money. Those are legitimate business judgments, made with counsel, the insurer and the board.
The decision is easier to make well if it is made with information. Before anyone discusses paying, the response team should be able to answer three questions: what do we actually have in backups, how long will a rebuild take without a decryptor, and what data did they take.
- Confirm the state of every backup copy, including the offsite and immutable ones, and test-restore something from each.
- Get a realistic rebuild timeline from the people doing the work, not from the people hoping.
- Identify what was exfiltrated from the attacker's proof and from firewall and EDR logs. Volume and content change the calculus.
- Have counsel and the negotiation firm confirm the group's identity and sanctions status.
Make the question irrelevant
The only way to take the decision off the table is to make the ransom useless. That means backups the attacker cannot reach, a rebuild plan you have rehearsed, and enough segmentation and monitoring that the intrusion is caught before exfiltration.
Every control in this series exists so that the answer to 'should we pay' is 'we do not need to'. The companies that can say that are the ones with an immutable backup copy, a tested restore, and a written recovery order. Those are not expensive relative to the alternative.
- Immutable offsite backups with a retention longer than the attacker's likely dwell time.
- Quarterly restore tests, timed and written down.
- A tabletop exercise that walks leadership through this decision while nothing is on fire.
Frequently asked questions
Will our cyber insurance cover the ransom?
Many policies include extortion coverage, subject to sublimits, sanctions compliance and the carrier's approval process. Read your policy now rather than during the incident, and note that the insurer will require their own counsel and negotiators to be involved.
Can we negotiate the price down?
Professional negotiators routinely do, and they also buy time for the technical team to assess backups. That is one of the reasons to engage a specialist even if you do not intend to pay.
The attacker says they will delete the data if we pay. Can we trust that?
You cannot verify it, and there are documented cases where data was leaked anyway. Treat exfiltrated data as permanently compromised for planning and notification purposes regardless of payment. If you want help building the backup and recovery posture that makes this moot, RackLedge can start with a review of what you have today.
Takeaway
Paying is a legal and business decision that belongs to counsel, the insurer and the owners, not to IT. It buys an unreliable tool and an unverifiable promise. The best position is the one where you can say no because the backups are intact and the rebuild plan is rehearsed.