Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

Should an organisation pay a ransomware demand?

Payment is a legal, operational, ethical, financial and risk decision for authorised organisational decision-makers. It cannot be reduced to a technical recommendation, and it guarantees neither decryption nor deletion of data.

Support an informed decision

Provide the technical facts and uncertainty: impact, recovery options, evidence of possession, decryptor claims and continuing access. Appropriate legal, regulatory, insurance, financial and law-enforcement advice may be required, especially for current sanctions and anti-money-laundering risk.

The response team should not promise legality or effectiveness. Payment may yield a working, partial or malicious decryptor, further demands, publication or no response.

Preserve the decision and transaction

Retain the demand, negotiation, advice, approvals, wallet or payment-service details, transaction IDs and anything supplied afterwards. Record the stated purpose of any full, partial or test payment.

Payment can create intelligence and financial-tracing evidence while funding further offending. Those consequences belong in the documented decision, separate from the technical incident findings.

Key takeaway

Treat payment as a high-risk authorised decision with no guaranteed outcome, supported by current specialist advice and a complete negotiation, approval and transaction record.

Reference: CIM-187Cyber Incidents & Offender Methods