Should an organisation pay a ransomware demand?¶
Payment is a legal, operational, ethical, financial and risk decision for authorised organisational decision-makers. It cannot be reduced to a technical recommendation, and it guarantees neither decryption nor deletion of data.
Support an informed decision¶
Provide the technical facts and uncertainty: impact, recovery options, evidence of possession, decryptor claims and continuing access. Appropriate legal, regulatory, insurance, financial and law-enforcement advice may be required, especially for current sanctions and anti-money-laundering risk.
The response team should not promise legality or effectiveness. Payment may yield a working, partial or malicious decryptor, further demands, publication or no response.
Preserve the decision and transaction¶
Retain the demand, negotiation, advice, approvals, wallet or payment-service details, transaction IDs and anything supplied afterwards. Record the stated purpose of any full, partial or test payment.
Payment can create intelligence and financial-tracing evidence while funding further offending. Those consequences belong in the documented decision, separate from the technical incident findings.
Key takeaway
Treat payment as a high-risk authorised decision with no guaranteed outcome, supported by current specialist advice and a complete negotiation, approval and transaction record.