Practitioner Guide

What ransomware negotiation actually looks like.

Most organizations facing ransomware have never been in this situation before. The threat actor has. Here is what to expect, and what the decisions actually look like in practice.

When It Happens

The first 24 hours are not about negotiation.

The first thing most organizations want to do when ransomware hits is open a negotiation channel. That is almost always the wrong first move.

The first 24 hours are about understanding what happened, stopping what is still happening, and preserving the evidence you will need to make every subsequent decision. Negotiation is a parallel track — not the primary one.

The immediate priorities

  • Identify the blast radius. What systems are encrypted? What systems are not? What backups exist, and are they also compromised?
  • Stop ongoing encryption. In most ransomware incidents, detonation is a separate event from initial access. The attacker may still be active. Isolate, don't just shut down.
  • Identify the threat actor. The ransom note, the file extension, the negotiation portal URL — these are attribution signals. Knowing who you're dealing with changes the negotiation strategy significantly.
  • Preserve forensic evidence. Do not wipe systems before imaging them. The forensic trail is how you establish the root cause, scope the breach, and meet notification obligations.
  • Engage legal counsel. Ransomware incidents frequently trigger notification obligations. Attorney-client privilege applies to the investigation if structured correctly. Do this early.

Opening negotiation before you know what you're dealing with is a mistake. Threat actors track response timing. Moving too fast signals panic. Moving too slow signals disorganization. Neither is advantageous.

Should you pay?

It depends on four things.

There is no universal answer to whether an organization should pay a ransomware demand. Anyone who tells you there is — in either direction — is not being straight with you. The decision depends on four factors, evaluated together.

1. Backup viability

If you have clean, tested, offline backups that can restore your systems to a workable state within an acceptable timeframe, you have significant leverage. You can rebuild without paying. If your backups are also encrypted, or if restoring from backup would take longer than the business can sustain, the calculus changes.

2. Data exfiltration

Modern ransomware groups almost always exfiltrate data before encrypting. Even if you can restore from backup, paying may be the only way to prevent publication of sensitive data — customer records, M&A documents, health information, employee data. This is "double extortion," and it is now the norm, not the exception.

3. OFAC compliance

The US Treasury's Office of Foreign Assets Control maintains a list of sanctioned threat actors. Paying a sanctioned group — knowingly or unknowingly — carries legal exposure. Threat actor identification must happen before any payment is made. This is not optional.

4. Decryptor reliability

Not all decryptors work. Some ransomware groups provide decryptors that are slow, incomplete, or corrupt data during decryption. Knowing the threat actor's reputation for decryptor reliability — which varies significantly by group — is an input into the decision to pay and into what you're willing to pay for.

The decision to pay is a business decision, not a technical one. It should involve legal counsel, the CEO or board, and your IR team — all of whom should be in the same room, with the same information, at the same time.

How negotiation actually works.

Ransomware negotiation is not a hostage negotiation in the Hollywood sense. It is a structured commercial transaction between a threat actor running an extortion business and an organization that is their customer — involuntarily. Understanding this changes how you approach it.

The threat actor's incentives

Most ransomware groups are profit-motivated. They want to close the transaction, collect payment, and move on. A decryptor that doesn't work produces disputes, damages reputation on the criminal forums where they recruit affiliates, and slows their operation. A negotiation that drags indefinitely costs them time. They have incentives to reach agreement.

This does not mean they are reasonable. It means they are predictable. Experienced negotiators use that predictability.

What moves the number

  • Demonstrating financial constraint. Threat actors research targets before attacking. They have a number in mind. The negotiation is partly about convincing them that number is wrong for your specific situation.
  • Technical progress on restoration. If you are actively restoring from backup, the threat actor's leverage decreases over time. Communicating this — carefully — can accelerate negotiation.
  • Timeline pressure from both sides. Threat actors have operational timelines too. Long negotiations are expensive for them. Patience is a negotiating tool.
  • Proof of life for the data. Before any payment, request a proof-of-life sample — a small set of files decrypted to demonstrate the decryptor works. This is standard practice. Any group that refuses is a signal.

Who does the talking

The negotiator should be someone experienced in this specific type of negotiation — not your general counsel, not your CISO, and not an executive who is emotionally invested in the outcome. Inexperienced negotiators make commitments they can't walk back, reveal information that hurts their position, or escalate when de-escalation serves them better.

Negotiation also runs alongside — not instead of — technical remediation. Organizations that treat negotiation as an alternative to rebuilding end up in a worse position than those that treat it as one track in a parallel effort.

What to tell the board.

The board will have three questions. They will not always ask them directly, but they are always the underlying questions.

  • How did this happen? They want to know if this was foreseeable and preventable — not to assign blame immediately, but because it informs the decision about leadership accountability and future investment.
  • What are we doing about it right now? They want to know that someone credible is in charge, that the situation is being actively managed, and that there is a plan they can hold the management team accountable to.
  • What does this mean for the business? Revenue impact, customer notification obligations, regulatory exposure, reputational risk. They need numbers, or honest ranges, not reassurance.

The board is not a technical audience. The briefing should be in business language — operational impact, financial exposure, timeline to recovery. Avoid technical detail unless a board member specifically requests it. Lead with what you know, acknowledge clearly what you don't, and tell them what the decision points are and who has authority to make each one.

The worst briefing is one that leaves the board feeling like they're being managed rather than informed. They will find out eventually. Being the source of accurate information — even when that information is bad — is the right posture.

In an Active Incident?

We work active incidents. Including right now.

If you are in an active ransomware incident, the best time to call was before this happened. The second best time is now. We provide emergency incident response and run negotiation in parallel with technical remediation — not as a substitute for it.

If you want to be in a better position before it happens, that's what our IR retainer is for.

Tell Us About Your Situation →

Or email directly: hello@unknown2.com