The Official Position: Do Not Pay
The FBI, CISA, and international law enforcement agencies universally advise against paying ransomware demands. Their reasoning: payment funds criminal operations, incentivizes future attacks against your organization and others, and does not guarantee you will get working decryption tools. Data from multiple sources suggests that roughly 40% of victims who pay either receive non-functional decryption tools, experience the data released publicly anyway, or are attacked again within months by the same or affiliated groups.
The Reality: Many Organizations Pay
Despite official guidance, a significant percentage of organizations pay ransoms — particularly when they have no viable alternative and when their cyber insurance covers the payment. When your payroll system is encrypted, patient care is disrupted, or a manufacturing line is stopped, the calculus becomes different from a theoretical discussion about incentive structures. The decision is ultimately a business decision, not a purely ethical one, and it must be made quickly with imperfect information.
Legal Considerations: OFAC Compliance
Before authorizing any payment, your legal counsel must verify that the ransomware group is not on the Office of Foreign Assets Control (OFAC) sanctions list. Paying sanctioned entities — which include several major ransomware groups — is illegal regardless of whether you knew the group was sanctioned. Your cyber insurance carrier and legal counsel should be involved in this assessment before any payment is made.
Insurance Coverage
Cyber insurance policies typically cover ransom payments up to a defined limit, but carriers require prompt notification, OFAC compliance verification, and cooperation with their incident response requirements. Do not make any payment decisions without first consulting your insurance carrier — unauthorized payments can void coverage for the incident.
The Better Answer: Don't Be There
The only genuinely good answer to the ransom payment question is to never face it. Organizations that conduct annual penetration testing, maintain isolated backups, implement phishing-resistant MFA, and segment their networks are dramatically less likely to face this decision. Those that do face it are in a significantly better position because they have both better defenses to stop the attack mid-chain and better recovery options that reduce the leverage attackers have.
Prevention is better than negotiation.
Grid32 identifies the vulnerabilities ransomware operators would exploit in your environment — before they get the chance to use them.
Get a Quote →