The short answer
Law enforcement and security agencies — CISA, the FBI, Europol — generally discourage paying: payment funds criminal operations and guarantees neither a working decryptor, nor complete recovery, nor the deletion of stolen data. Paying is also not a purely private choice: legal, regulatory, sanctions and insurance issues may apply, and your reporting duties run either way. Yet it remains, in the end, a decision made under duress — so the honest framework is: establish the facts first, involve counsel and specialists, and never handle it alone. The organizations with the strongest position are the ones that could restore — that position is built before the attack.
What a payment actually buys — and what it does not
- A decryptor of unknown quality. Criminal decryptors are often slow, sometimes broken, and may recover only part of the data. A payment is not a recovery plan.
- A criminal's promise not to publish. If data was exfiltrated, payment buys an unverifiable claim of deletion from someone whose business is extortion. Copies may persist or resurface.
- No cleanup. Payment does not remove the attacker's access, the malware, or the vulnerability that let them in. You rebuild and harden either way — the payment changes none of that work.
- No protection against repeat extortion. Paying resolves neither the access nor the incentive; it may increase the risk of future targeting, and further demands remain possible.
The legal dimension — this is not only a business call
- Sanctions and criminal exposure. A payment or facilitated transaction may create sanctions, civil or criminal exposure depending on the jurisdiction, the recipient and the parties involved. Specialist legal and sanctions screening is required before any payment-related action.
- Reporting duties do not disappear. NIS2 (for in-scope entities) and GDPR (where personal data is affected) apply under their own tests whether you pay or not — a quiet payment does not buy a quiet incident. See the 24h/72h process.
- Insurance conditions. Many cyber policies require insurer consent before payment or negotiation, and use approved specialists. Acting first and telling the insurer later can cost you the coverage.
- Evolving national rules. Some jurisdictions are moving toward payment-reporting obligations or restrictions for parts of the economy. Counsel checks the current state — one more reason no payment decision should be made without them.
The facts to establish before any decision
There is no universal yes/no — the decision weighs, at minimum:
- Can we restore? Are there backups the attacker did not reach, and have restores been tested? This single fact dominates the whole decision.
- Is anyone at risk? Business continuity, human safety and critical services (patient care, utilities, safety systems) can change the weighting entirely — and bring their own legal duties.
- What exactly was taken? Encryption-only and encryption-plus-exfiltration are different problems, with different legal consequences.
- What does downtime actually cost per day? A real number, not a feeling — it frames every option.
- Who is the actor? Identification drives the sanctions screening, the credibility of their “promises”, and sometimes reveals that a free decryptor already exists.
- What do insurer, counsel and law enforcement say? All three, before any contact with the attackers — and the decision, either way, is one management will be accountable for, so it should be made and documented at that level.
If, after all that, payment is seriously on the table
Harm reduction, not endorsement:
- Specialists handle any contact — never principals, with legal counsel involved throughout and the insurer's conditions respected.
- Legal sign-off first, including documented sanctions screening.
- Law enforcement stays informed. It protects you later and occasionally changes the options available.
- Expect partial recovery and keep the restore-from-backup track running in parallel — whichever finishes first wins.
- Budget the rebuild anyway. The network was hostile territory; payment does not make it clean. Eradication, hardening and monitoring follow either path.
The uncomfortable conclusion
The strongest negotiating position is not needing to negotiate. That position is built before the attack, by making refusal affordable: protected and tested backups, a rehearsed first-hours response, and decision criteria agreed while nobody is under someone else's clock.
Sources
This article provides general incident-management information and is not legal advice. The lawfulness and consequences of a ransom payment depend on your jurisdiction, the identity of the threat actor, applicable sanctions regimes and your contracts — involve legal counsel before any decision or contact with attackers.