Skip to content
Stop Ransomware

Resource Center · Ransomware response

Should You Pay the Ransom? A Decision Framework

Published 3 July 2026 · Updated 3 July 2026 · 8 min read

The short answer

Law enforcement and security agencies — CISA, the FBI, Europol — generally discourage paying: payment funds criminal operations and guarantees neither a working decryptor, nor complete recovery, nor the deletion of stolen data. Paying is also not a purely private choice: legal, regulatory, sanctions and insurance issues may apply, and your reporting duties run either way. Yet it remains, in the end, a decision made under duress — so the honest framework is: establish the facts first, involve counsel and specialists, and never handle it alone. The organizations with the strongest position are the ones that could restore — that position is built before the attack.

What a payment actually buys — and what it does not

The legal dimension — this is not only a business call

The facts to establish before any decision

There is no universal yes/no — the decision weighs, at minimum:

  1. Can we restore? Are there backups the attacker did not reach, and have restores been tested? This single fact dominates the whole decision.
  2. Is anyone at risk? Business continuity, human safety and critical services (patient care, utilities, safety systems) can change the weighting entirely — and bring their own legal duties.
  3. What exactly was taken? Encryption-only and encryption-plus-exfiltration are different problems, with different legal consequences.
  4. What does downtime actually cost per day? A real number, not a feeling — it frames every option.
  5. Who is the actor? Identification drives the sanctions screening, the credibility of their “promises”, and sometimes reveals that a free decryptor already exists.
  6. What do insurer, counsel and law enforcement say? All three, before any contact with the attackers — and the decision, either way, is one management will be accountable for, so it should be made and documented at that level.

If, after all that, payment is seriously on the table

Harm reduction, not endorsement:

The uncomfortable conclusion

The strongest negotiating position is not needing to negotiate. That position is built before the attack, by making refusal affordable: protected and tested backups, a rehearsed first-hours response, and decision criteria agreed while nobody is under someone else's clock.

This article provides general incident-management information and is not legal advice. The lawfulness and consequences of a ransom payment depend on your jurisdiction, the identity of the threat actor, applicable sanctions regimes and your contracts — involve legal counsel before any decision or contact with attackers.

Facing this decision right now?

Do not make it alone, under the attacker’s clock. Our 24/7 response line is free — we help you establish the facts that make this decision rational instead of desperate.

Get confidential incident support