Practitioner Guide
Most organizations facing ransomware have never been in this situation before. The threat actor has. Here is what to expect, and what the decisions actually look like in practice.
When It Happens
The first thing most organizations want to do when ransomware hits is open a negotiation channel. That is almost always the wrong first move.
The first 24 hours are about understanding what happened, stopping what is still happening, and preserving the evidence you will need to make every subsequent decision. Negotiation is a parallel track — not the primary one.
Opening negotiation before you know what you're dealing with is a mistake. Threat actors track response timing. Moving too fast signals panic. Moving too slow signals disorganization. Neither is advantageous.
It depends on four things.
There is no universal answer to whether an organization should pay a ransomware demand. Anyone who tells you there is — in either direction — is not being straight with you. The decision depends on four factors, evaluated together.
If you have clean, tested, offline backups that can restore your systems to a workable state within an acceptable timeframe, you have significant leverage. You can rebuild without paying. If your backups are also encrypted, or if restoring from backup would take longer than the business can sustain, the calculus changes.
Modern ransomware groups almost always exfiltrate data before encrypting. Even if you can restore from backup, paying may be the only way to prevent publication of sensitive data — customer records, M&A documents, health information, employee data. This is "double extortion," and it is now the norm, not the exception.
The US Treasury's Office of Foreign Assets Control maintains a list of sanctioned threat actors. Paying a sanctioned group — knowingly or unknowingly — carries legal exposure. Threat actor identification must happen before any payment is made. This is not optional.
Not all decryptors work. Some ransomware groups provide decryptors that are slow, incomplete, or corrupt data during decryption. Knowing the threat actor's reputation for decryptor reliability — which varies significantly by group — is an input into the decision to pay and into what you're willing to pay for.
The decision to pay is a business decision, not a technical one. It should involve legal counsel, the CEO or board, and your IR team — all of whom should be in the same room, with the same information, at the same time.
Ransomware negotiation is not a hostage negotiation in the Hollywood sense. It is a structured commercial transaction between a threat actor running an extortion business and an organization that is their customer — involuntarily. Understanding this changes how you approach it.
Most ransomware groups are profit-motivated. They want to close the transaction, collect payment, and move on. A decryptor that doesn't work produces disputes, damages reputation on the criminal forums where they recruit affiliates, and slows their operation. A negotiation that drags indefinitely costs them time. They have incentives to reach agreement.
This does not mean they are reasonable. It means they are predictable. Experienced negotiators use that predictability.
The negotiator should be someone experienced in this specific type of negotiation — not your general counsel, not your CISO, and not an executive who is emotionally invested in the outcome. Inexperienced negotiators make commitments they can't walk back, reveal information that hurts their position, or escalate when de-escalation serves them better.
Negotiation also runs alongside — not instead of — technical remediation. Organizations that treat negotiation as an alternative to rebuilding end up in a worse position than those that treat it as one track in a parallel effort.
The board will have three questions. They will not always ask them directly, but they are always the underlying questions.
The board is not a technical audience. The briefing should be in business language — operational impact, financial exposure, timeline to recovery. Avoid technical detail unless a board member specifically requests it. Lead with what you know, acknowledge clearly what you don't, and tell them what the decision points are and who has authority to make each one.
The worst briefing is one that leaves the board feeling like they're being managed rather than informed. They will find out eventually. Being the source of accurate information — even when that information is bad — is the right posture.
In an Active Incident?
If you are in an active ransomware incident, the best time to call was before this happened. The second best time is now. We provide emergency incident response and run negotiation in parallel with technical remediation — not as a substitute for it.
If you want to be in a better position before it happens, that's what our IR retainer is for.
Tell Us About Your Situation →Or email directly: hello@unknown2.com