There is a conversation that happens in small businesses only after something terrible has already occurred, and it happens quietly. Should we pay? It gets asked at eleven at night, phones ringing, servers dark. It is one of the hardest decisions an owner will ever make, and almost nobody has thought about it in advance.

We are not going to tell you what to choose. That is not our call, and anyone offering a confident universal answer is not being straight with you. What we can do is lay out the arguments on both sides, explain what law enforcement says and why, describe legal exposure most owners do not know exists, and be honest about what payment does and does not accomplish. One thing up front: this is not legal advice. If you are ever here, the decision belongs to you together with your attorney, your insurer, and law enforcement, not to a blog post.

Why the Decision Arrives at the Worst Possible Moment

Every feature of a ransomware incident degrades decision quality. That is not accidental. It is the business model.

  • You are operating blind. In the first hours, nobody knows how far the intrusion went, what was copied, or whether backups survived. You are making a large financial decision on incomplete information.
  • The clock is artificial but the pressure is real. Deadlines and escalating demands exist to prevent deliberation, while the genuine costs, payroll and customers and deliveries, compound by the hour.
  • Everyone is looking at the owner. In a small business there is no crisis committee. There is one person who signs.

This is not rare. In its 2025 Internet Crime Report, the FBI’s Internet Crime Complaint Center said it received more than 3,600 ransomware complaints during 2025 with losses exceeding 32 million dollars, including 460 from critical infrastructure organizations. Those are only the incidents someone chose to report.

The Case People Make for Paying

The argument for payment is rarely ideological. It is arithmetic done by someone watching a business die in real time, and it deserves to be stated seriously.

  • The downtime costs more. If a week offline means missed payroll, broken contracts, and customers who leave for good, an owner can reasonably conclude the demand is the smaller number.
  • Recovery is not guaranteed either. If backups were encrypted, incomplete, or never tested, rebuilding may take weeks with an uncertain outcome.
  • Data was stolen, not just locked. Modern attacks often copy information before encrypting it, adding a threat of publication. Some owners weigh payment against the harm of customer or employee data being exposed.
  • Obligations to other people. Employees have mortgages. Customers depend on delivery. Those duties are real, and an owner feels them personally.

The Case Against, and What Law Enforcement Says

Law enforcement’s position is unambiguous and worth reading in its own words. The FBI states plainly that it “does not support paying a ransom in response to a ransomware attack.” The reasoning has two parts.

The first is that payment does not buy what people think it buys. In the FBI’s words, “paying a ransom doesn’t guarantee you or your organization will get any data back.” You are relying on a criminal to hold up their end. Even where a decryption tool is provided, decryption is not restoration: tools can be slow or unreliable, files can come back corrupted, and the rebuild work remains. Payment also does nothing about data already copied, because you cannot confirm deletion of something you cannot see.

The second reason is the wider effect. The FBI notes that paying “encourages perpetrators to target more victims and offers an incentive for others to get involved in this type of illegal activity.” A single owner’s decision can be individually rational and collectively expensive. Reasonable people land in different places on that tension. The FBI asks victims to report incidents regardless of the payment decision, to a local field office or through ic3.gov.

The Legal and Sanctions Exposure Nobody Mentions

This is the part most owners have never heard, and it changes the shape of the decision. Paying is not only a business judgment. It can carry legal risk under U.S. sanctions law.

The Treasury Department’s Office of Foreign Assets Control has published an advisory on the sanctions risks of facilitating ransomware payments. Some ransomware actors are sanctioned persons or entities, or operate from embargoed jurisdictions, and payments to them are prohibited for U.S. persons. OFAC applies strict liability, meaning as the advisory puts it that “a person subject to U.S. jurisdiction may be held civilly liable even if such person did not know or have reason to know” it was engaged in a prohibited transaction. Good faith is not, by itself, a defense.

The same advisory describes what OFAC treats as mitigating factors: a “self-initiated and complete report of a ransomware attack to law enforcement,” “full and ongoing cooperation with law enforcement,” and “meaningful steps taken to reduce the risk of extortion by a sanctioned actor through adopting or improving cybersecurity practices,” which it associates with offline backups, response plans, and training. Preparation and reporting are not only good practice. They are the specific factors regulators say they weigh.

We will say it again because it matters: none of this is legal advice, and the analysis is fact specific. Involve counsel immediately rather than after a decision is made.

Who Belongs at the Table

If this ever reaches you, it is not a decision to make alone, and not one your IT provider should make. Four parties belong in the room.

  1. Legal counsel, first. Sanctions exposure, breach notification duties, contractual obligations, and privilege all attach here. Engage counsel before anything is decided.
  2. Your insurer. If you carry cyber coverage, the policy likely dictates notification timing, approved vendors, and what is covered. Acting before notifying them can jeopardize the claim.
  3. Law enforcement. Reporting is what the FBI asks for and is one of the mitigating factors OFAC identifies. It can also give you information you cannot obtain yourself.
  4. Your technical team. Their job is answering the factual questions the decision depends on: what is encrypted, what was copied, what backups survived, and how long a full restore would honestly take.

Know these names before you need them. An owner searching for a cyber attorney at midnight has already lost hours that mattered.

The Bottom Line: This Decision Is Made Months Earlier

Here is the honest conclusion. The ransom question is decided far more by what you did six months earlier than by anything decided that night. A business with tested, offline backups and a written response plan is having a difficult week. A business without them is having an existential one, with options narrowed to choices it never wanted.

The joint federal StopRansomware guidance, developed by CISA with the FBI, NSA, and MS-ISAC, makes the same point. It tells organizations to “maintain offline, encrypted backups of critical data, and regularly test the availability and integrity of backups in a disaster recovery scenario,” noting that “many ransomware variants attempt to find and subsequently delete or encrypt accessible backups.” It also tells them to “create, maintain, and regularly exercise a basic cyber incident response plan.” Both are unglamorous and cheap next to a ransom demand, and both preserve your ability to choose. We made the broader argument in our piece on what the Stryker cyberattack tells us and in our case for why cybersecurity is no longer optional for mid-sized businesses.

If you would rather never have this conversation for real, the work is finite: backups that are isolated and actually restored on a schedule, a short response plan with names and numbers, and relationships established before the bad day. That is what we help Denton County businesses put in place. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).