CyberISolve

Incident Response

Ransomware: Should You Ever Pay? What We Tell Clients Facing That Decision

July 30, 2025 · 6 min read

This is one of the hardest decisions a business can face, usually made under enormous time pressure, and we’ve sat with clients through it more than once. There’s no single right answer that applies to every situation, but there are facts worth knowing before the decision has to be made.

Paying doesn’t guarantee recovery

A meaningful share of businesses that pay still don’t get fully functional decryption, or discover that some files are corrupted beyond what the decryption tool can fix. Paying is a bet on the attacker’s reliability, not a purchase with a guaranteed outcome, and that should factor directly into the decision.

Paying doesn’t mean the data wasn’t already stolen

Most modern ransomware operations exfiltrate data before encrypting it, specifically to add a second point of leverage: pay or we publish. Paying the ransom to recover encrypted files provides no assurance that the stolen data won’t be sold or leaked regardless — it addresses encryption, not the theft that likely already happened.

What should actually drive the decision

  • Whether verified, working backups exist — the single biggest factor in whether payment is even a live question
  • How critical the encrypted systems are to continued operation, and how long recovery would take without paying
  • Legal and regulatory obligations — in some jurisdictions and sectors, payment to sanctioned entities carries its own legal exposure
  • Insurance policy terms, since some cyber insurance explicitly covers or restricts ransom payments
  • Law enforcement guidance for the specific incident, which we always recommend involving early, not after the decision is already made

The best version of this decision

The businesses in the strongest position are the ones where tested backups make the question largely moot — recovery doesn’t depend on trusting an attacker’s decryption tool. That’s the outcome our backup and recovery work is aimed at, specifically so this decision, if it ever comes up, isn’t made from a position of having no other option.

← All Blogs

Related reading

Dealing with something similar?

Tell us what's going on — active incidents get a same-day response, 24/7.