Ransomware: pay or don’t pay is the wrong question
The decision is prepared months earlier, while you are not yet on fire.

When your files are encrypted and a timer on the screen counts down the hours, the question everyone asks is: do we pay? It is the wrong question, or at least it has arrived too late to be the right one. The moment to decide how you will handle ransomware is not while you are on fire: it is now, with a clear head.
The decision to pay, when it comes, is the product of what you did — or did not — build beforehand: backups that hold, a plan you know how to run, and legal clarity on what you can actually do. The right question is not pay or don’t pay, but how prepared you are to have a choice at all.
The ransom is not a restore function
Paying is not a restore button. The decryptor supplied by attackers is often slow, unstable and fails to recover all the data; on large volumes recovery can take days or weeks, much like restoring from backup. Then there is double extortion: most groups steal the data before encrypting it, so paying for the key does not remove the exfiltrated copy. The threat to publish it remains, with or without payment.
Defensible backups, not just backups
Almost everyone has backups. Few have backups that survive an attacker who already holds domain administrator privileges. The first thing a capable ransomware group does is hunt down and destroy the backup copies. A defensible backup is isolated from the credentials it protects, is immutable or offline so it cannot be deleted, and — above all — has been tested by actually restoring it. A backup never tested is a hypothesis, not a guarantee.
The informed decision
If you do weigh payment, make it an informed decision and not a surrender. You need to understand restore time from backup versus time with the decryptor, the precise scope of exfiltrated data, the reliability of the group whose message you are reading, and who in the company has the authority to decide. You also need an honest estimate of the real business impact hour by hour, because that is what gives the alternatives their weight. None of those answers can be improvised in the middle of the crisis: either you prepared them, or you are guessing while the clock runs and judgement is at its lowest.
The legal and notification layer
Paying is not only an economic choice. Where personal data is breached, the GDPR requires notification to the supervisory authority within 72 hours of becoming aware of it, and in some cases communication to the affected individuals. The NIS2 directive adds reporting obligations for entities in its scope. And the payment itself may be unlawful if the funds reach parties subject to sanctions regimes: before transferring any sum, this has to be checked. These are legal judgements, not technical ones, which is why the lawyer joins the room early.
What no one guarantees you
Paying does not guarantee recovery, does not guarantee the destruction of the stolen data, and marks you as a company willing to pay — information that circulates among criminal groups. This is not a moral argument: it is an operational fact to weigh in the calculation. Preparation does not remove ransomware, but it moves the decision from panic to reason.
Preparing the decision, not just the technical side
The quality of the choice depends on work done while the systems were running. Who has the authority to decide, and within what spending limits? Is there insurance cover, and what does it require to engage? Who do you coordinate with — legal, response specialists, negotiators if needed — and is that contract already signed? A prepared company has answered these questions in peacetime, ideally rehearsing them in an exercise. An unprepared one discovers them while the timer runs, and it is at the worst moment that it makes the most expensive decisions.
The takeaway
Stop treating payment as the central question. Build backups an attacker cannot delete and that you have genuinely tested, decide in advance who makes the call and under which legal constraints, and bring in legal and specialists from the first minute. If you reach the crisis with these things in order, the choice — whatever it turns out to be — is yours, not the attacker’s.



