Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogCybersecurity

Should You Pay a Ransomware Ransom? How to Decide

Empty corporate boardroom at night with a conference desk phone and legal pad on a long table

Don't pay if you can restore. That's the whole decision compressed into one sentence, and it's why the ransom question gets settled months before the attack, in whatever you did or didn't do about backups.

But owners facing a live incident need more than a slogan. Here's what the current payment data shows, what the law says, and how the decision actually gets made in a small business.

None of this is legal advice. When a ransom is on the table, you want counsel and your insurance carrier in the conversation within hours.

At a glance

  • The FBI does not encourage paying, because payment guarantees nothing.
  • The median payment in Q2 2026 was $150,000, and payment rates hit record lows.
  • Paying for deletion of stolen data buys a promise you can't verify.
  • OFAC applies sanctions penalties on strict liability, so good faith is not a defense.
  • Tested, immutable, off-domain backups are what make the question moot.

Should you pay the ransom?

Only as a last resort, when restoring from backup won't recover the business and counsel has cleared it. The FBI's position is direct: "FBI, CISA, and ASD's ACSC do not encourage paying a ransom as payment does not guarantee victim files will be recovered" (#StopRansomware advisory). Payment buys a promise from a criminal, nothing more.

What does the payment data show?

Fewer victims are paying, and the ones who do are paying wildly inconsistent amounts. In Q2 2026, Coveware by Veeam reported a median ransom payment of $150,000 — down 50% from the prior quarter — against an average of $1,880,612, which jumped 176% because a handful of very large payments dragged it upward (Coveware by Veeam, Q2 2026).

The median is the number that matters to a 40-person company. The average is a story about a few large enterprises.

In cases where attackers only stole data and didn't encrypt anything, the payment rate "dropped to a historically low level of 15%." Coveware also reports that the share of its clients choosing to pay "sank to a new record low during the quarter."

Read that trend for what it is. Paying has stopped being the default, because enough victims have now watched it fail.

Why paying often doesn't deliver

The thing you're actually buying in a data-theft extortion case is deletion of stolen files. You can't verify it, and there's now hard evidence it doesn't happen.

After the LockBit takedown, Coveware's own write-up concluded that victims "were paying for a result that was never actually delivered." The firm's point is that the standard reassurance given to ransomware victims about deletion "turned out to be incorrect advice."

Decryption is different. Decryption keys usually work, because a gang whose keys don't work stops getting paid. But working keys aren't the same as a working business. You still have to decrypt every machine, validate the data, rebuild whatever the attackers broke on the way in, and figure out how they got there. Paying compresses none of that.

What are the legal risks?

Sanctions exposure is the one that catches small businesses by surprise. The U.S. Treasury's Office of Foreign Assets Control warned in its September 2021 advisory that it "may impose civil penalties for sanctions violations based on strict liability, meaning that a person subject to U.S. jurisdiction may be held civilly liable even if such person did not know or have reason to know that it was engaging in a transaction that was prohibited" (OFAC advisory).

Strict liability means good faith isn't a defense. If the group behind the attack is sanctioned, paying is a problem whether or not you knew who they were.

The same advisory notes that companies facilitating payments on a victim's behalf — including insurers and incident response firms — may also risk violating OFAC regulations. That's why reputable IR firms run sanctions checks before touching a negotiation, and why a firm that offers to "just handle it" without one is a firm to walk away from.

Then there's breach notification. Paying doesn't make the incident go away. If personal information was taken, state law still requires notice, and in New York the SHIELD Act obligations apply regardless of whether you paid.

Who actually makes the call?

Not your IT provider, and not whoever is most panicked at hour three. The decision belongs to the owner or board, with input from four people: outside counsel, your cyber insurance carrier, a forensics lead, and your finance lead.

Call the carrier first. Most policies require notification before you incur costs, and many will assign counsel and an IR firm from a pre-approved panel. Paying a vendor your carrier hasn't approved can cost you the claim. The cyber insurance requirements you agreed to at renewal govern what happens next.

Decide the process now, while nothing is on fire. An incident response plan that names who approves a payment, who calls the carrier, and where the policy number lives is worth more at 2 a.m. than any technical control.

What actually decides it: your backups

Every business that chose not to pay had the same thing in common. They could restore without the attacker's help.

That means three specific properties, and most small business backups fail at least one.

  • Immutable. Backups the attacker can't delete or encrypt with the domain admin credentials they just stole. Modern ransomware hunts backup servers first.
  • Off the domain. A backup appliance joined to the same Active Directory as everything else falls with everything else.
  • Tested. Not "the job says success." An actual restore of an actual server, done on a schedule, timed so you know how long a full recovery takes.

That last one separates the companies that recover from the companies that pay. Plenty of owners discover mid-incident that their backups cover file shares but not the virtual machines, or that a full restore takes weeks rather than the weekend they assumed.

Find out before you need it. Our managed IT and cybersecurity services include tested recovery, because an untested backup isn't a backup.

The first 24 hours

  1. Isolate, don't wipe. Disconnect affected machines from the network and leave them powered on. Wiping destroys the forensic evidence your insurer and counsel will need.
  2. Call your carrier and counsel. Before anything else costs money.
  3. Report it. "FBI and CISA urge you to promptly report ransomware incidents to a local FBI Field Office, FBI's Internet Crime Complaint Center (IC3), or CISA." Reporting doesn't commit you to anything.
  4. Assess the backups. What restores, and how long does it take? That answer, not the ransom note, drives the decision.
  5. Don't engage the attacker yourself. If there's going to be a conversation, a professional negotiator has it, after a sanctions check.

Frequently asked questions

Is it illegal to pay a ransomware ransom?

Not in itself, in the United States. It becomes a legal problem when the recipient is a sanctioned entity or individual, because OFAC applies civil penalties on a strict liability basis — meaning you can be liable without knowing. Have counsel and an IR firm run a sanctions check before any payment is made.

Will cyber insurance cover the ransom?

Many policies cover extortion payments, but only under conditions: prompt notification, use of panel vendors, and cooperation with the carrier's counsel. Coverage also depends on the controls you attested to at application. If you said you had MFA everywhere and you didn't, expect that to be examined.

If we pay, will the attackers delete our data?

There's no way to verify it, and evidence from law enforcement takedowns shows stolen data still sitting on criminal servers after victims paid. Treat stolen data as permanently out of your control and plan notification accordingly, whatever you decide about payment.

How long does recovery take without paying?

It comes down to how your backups are built and whether you've ever timed a full restore. Businesses with immutable, off-domain, regularly tested backups generally recover core operations in days. Businesses that have never run a restore test find out the hard way, during the worst week of the year.

Should we negotiate even if we don't plan to pay?

Sometimes, and only through a professional. Engaging can buy time to assess recovery options and can reveal what data the attackers actually hold. It can also escalate pressure. That's a call for counsel and your IR lead, not for a well-meaning employee with the attacker's chat link.

Want to know whether you could restore without paying? Request a complimentary recovery readiness assessment and we'll test a real restore, time it, and tell you exactly where you stand before someone else tests it for you.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.