All notes
Cyber / 2025-02-14
When a ransom should not be paid
Payment creates a new trail and a new dependency. It is a board decision, not a restore button.
If backups are intact and containment is possible, ransom is rarely the better step. If data has already leaked, payment does not unpublish it.
If payment still goes ahead, it should immediately be treated as a source: txid, rail, who authorised it.
We do not advise ‘always pay’ or ‘never pay’. We describe the consequences of each choice.