Ransomware pay-or-not-pay — the decision playbook for the board and the CISO
Short definition
A neutral decision framework for the moment an extortion demand lands: who decides, which legal gates must clear before money can move, and what a payment does and does not buy.
Why this matters now
The pay-or-not-pay question is treated as a commercial judgement and it is not one. In the United States, OFAC can impose civil penalties on a strict-liability basis, and licence applications for ransomware payments carry a presumption of denial; in the United Kingdom, OFSI stated in January 2026 that such payments are unlikely to be considered appropriate for a licence at all. Meanwhile the outcome data has turned against payment: Coveware put the Q2 2026 payment rate at a record low, and the LockBit takedown showed victims had paid for data deletion that was never performed.
Key points
- ▸The sanctions screen is a gate, not a step: OFAC penalties are strict liability — not knowing the payee was designated is no defence.
- ▸OFSI guidance updated 28 January 2026: ransomware payments are unlikely to be considered appropriate for a UK licence.
- ▸NYDFS covered entities: notify the superintendent within 24 hours of a payment, justify it in writing within 30 days.
- ▸Coveware put the Q2 2026 payment rate at a record low; exfiltration-only extortion was paid in just 15% of cases.
- ▸A payment buys a promise, not an outcome — the LockBit takedown showed victims had paid for deletion that never happened.
- ▸Fix the decision authority before the demand: who approves, who is consulted, and the ceiling above which the board decides.
Scope — when this playbook fires
Use this playbook the moment an extortion demand has been received and somebody in the organisation has asked whether to pay it. It covers all three commercial shapes the demand takes:
- Encryption-only — systems are locked and a decryptor is on offer.
- Exfiltration-only — nothing is encrypted, data has been stolen, and what is on offer is a promise not to publish and to delete.
- Double extortion — both, usually priced as one number, which is the first thing to unbundle.
It also fires on re-extortion: a second demand from the same or a different crew over the same dataset, after a payment has already been made.
Not in scope. This playbook decides one question. It does not replace containment, eradication or forensics, all of which run in parallel and none of which wait for the commercial decision — if the entry point was an identity, run the identity provider compromise playbook alongside it. It does not cover the notification duties themselves, which have their own timelines under NIS2 Title 13 and DORA Art. 19. It does not cover fraudulent-payment recall in business email compromise, which is a different track with a different counterparty — see the M365 BEC playbook.
The sanctions gate — a legal decision before a commercial one
Before anyone models downtime against a ransom figure, the payment has to be lawful. Three regimes bite, and a multinational is exposed to all of them at once.
United States. The OFAC Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments of 21 September 2021 is explicit: OFAC may impose civil penalties for sanctions violations based on strict liability, meaning a person subject to US jurisdiction may be held civilly liable even if such person did not know or have reason to know that the transaction was prohibited. Licence applications involving ransomware payments are reviewed case by case with a presumption of denial. The advisory reaches facilitators as well as victims — financial institutions, cyber insurers and digital forensics and incident response firms are named directly.
United Kingdom. OFSI financial sanctions guidance for ransomware, updated 28 January 2026, confirms the same strict-liability construction — there is no requirement to prove intent — and adds that breaches are criminal offences carrying custodial sentences. On licensing it is blunter than OFAC: ransomware payments are unlikely to be considered appropriate for an OFSI licence.
European Union. Council Regulation (EU) 2019/796 freezes the assets of listed persons and entities and prohibits making funds or economic resources available to them, directly or indirectly. Italy has no ad hoc statute banning ransom payments; the binding constraint on an Italian entity is the EU asset-freeze regime, applied to whoever is actually on the other end of the negotiation.
How to run the screen in practice. Attribution is usually incomplete, which is precisely why the screen is procedural rather than conclusive. Capture and screen every identifier you hold — destination wallet addresses, negotiation portal URLs and handles, the ransom note text, the malware family and version, and the known affiliate structure behind it — against the OFAC SDN list, the UK sanctions list and the EU consolidated list. Then re-run the screen immediately before the transfer: designations change during an incident, and the screen that counts is the last one, not the first.
If the screen cannot be cleared, the answer is no. This gate is not a risk to be priced into the decision; it is a condition precedent to the decision existing at all.
Decide the authority before the demand arrives
The single best predictor of a defensible decision is that the decision rights were written down before the incident. Fix these in the incident response plan, not at 3am:
- Named approver and ceiling. Who can authorise a payment, up to what figure, and above which figure the board or a delegated board committee must decide. Record the escalation path with names and deputies.
- Counsel first. Engage external counsel before any contact with the actor, so that the negotiation record and the incident analysis sit under legal privilege where the jurisdiction allows it. The first message sent without counsel is the one that gets read out later.
- Insurer before contact, not after. Most cyber policies condition ransom cover on the insurer prior written consent. Making contact — or worse, paying — before notifying the insurer can void the cover you are relying on to fund the decision.
- Who speaks to the actor. A specialist negotiator, briefed by counsel. Never the CEO or CISO directly, and never an engineer who is simultaneously running containment: the two roles leak information into each other.
- Law enforcement contact, pre-decided. Both OFAC and OFSI treat a self-initiated, complete and timely report as a significant mitigating factor, and OFAC explicitly treats such a report as a voluntary self-disclosure. Know in advance which office you call — the local FBI field office, IC3 or the US Secret Service in the United States; the NCSC cyber incident portal plus Action Fraud or Police Scotland in the United Kingdom; the Polizia Postale and CSIRT Italia in Italy.
The failure this prevents is specific: an engineer, an MSP or a subsidiary manager paying unilaterally to make the problem go away, committing the group to a transaction that no one screened and no one approved.
The reporting clock runs whether or not you pay
Notification duties are triggered by the incident, not by the commercial decision. Negotiation tolls none of them, and no supervisor has accepted an active negotiation as a reason for a late filing.
- NIS2 Title 13 — essential and important entities: 24-hour early warning, 72-hour notification, one-month final report. The full sequence is in the NIS2 incident timeline playbook.
- DORA Art. 19 — financial entities: the 4h/72h/one-month major-incident cadence, detailed in the DORA incident playbook.
- GDPR Art. 33 — 72 hours to the supervisory authority wherever personal data was accessible, which in an exfiltration case is nearly always.
- NYDFS 23 NYCRR 500.17(c) — the filing that audits the decision itself. A covered entity that makes an extortion payment must give the superintendent notice within 24 hours of the payment, and within 30 days a written description of the reasons payment was necessary, a description of alternatives to payment considered, all diligence performed to find alternatives to payment and all diligence performed to ensure compliance with applicable rules and regulations including those of the Office of Foreign Assets Control. Read that requirement as a specification for the evidence you must be generating while you decide.
- United Kingdom, in motion. The Cyber Security and Resilience (Network and Information Systems) Bill had its Lords second reading on 14 July 2026, with committee stage set for 1 September 2026; it widens the definition of a reportable incident beyond significant disruption to capture ransomware and pre-positioning explicitly. The separate Home Office proposals — a payment ban for public bodies and critical national infrastructure, plus economy-wide payment reporting — are not carried in this Bill and should be tracked on their own track.
- United States, not yet in force. CIRCIA would add 72-hour incident reporting and 24-hour ransom-payment reporting for covered critical-infrastructure entities. The final rule has slipped repeatedly and is not in force — do not build the runbook on a date. Do build the 24-hour payment-reporting capability, because two regimes already demand it and a third is drafted around it.
For a group operating across these regimes, build one evidence base and export a summary per regime. Supervisors compare the filings, and divergent narratives assembled by separate teams are the discrepancy they find first.
The decision gates, in order
Run these in sequence. A later gate never reopens an earlier one.
Gate 1 — Sanctions. Cleared, or not cleared. If the screen cannot be resolved against every identifier you hold, the decision terminates here.
Gate 2 — Recovery viability. The question is not “do we have backups”. It is: have we restored this class of system from these backups in a test, when, what restore time did we measure, and does that time fit the tolerance the business has actually signed up to? If measured recovery fits inside tolerance, a decryptor buys nothing on the encryption side of the demand. Note that ransomware crews target backup infrastructure first, so the tested restore must be from media the intrusion could not reach.
Gate 3 — Unbundle what is being sold. A decryptor is a testable good: you can verify it before and after payment. A deletion promise is not — you cannot verify a negative held by a criminal counterparty, ever. Split a double-extortion demand into its two parts and treat only the testable part as having a defensible price.
Gate 4 — Proof before money. For data possession, demand a file tree plus decryption of a sample you nominate, not files they nominate. For a decryptor, demand a working decryption of a representative sample across file types and sizes, on a system you control. No proof, no transfer, no exceptions for time pressure.
Gate 5 — Residual factors. Life-safety exposure, systemic service continuity and regulated-continuity obligations legitimately change the weighting of Gates 2 to 4. None of them opens Gate 1.
What a payment actually buys — the Q2 2026 numbers
The market has already moved, and the board deserves the current numbers rather than the ones from the last incident it lived through. In its Q2 2026 cyber extortion trends report, published 29 July 2026, Coveware by Veeam recorded:
- The payment rate fell to a new record low.
- Average payment $1,880,612, up 176% on Q1 — driven by a small number of very large exfiltration-linked settlements.
- Median payment $150,000, down 50% on Q1. The widening gap between mean and median is the signal: a handful of outliers, not a rising general price.
- Exfiltration-only extortion was paid in just 15% of cases, described as a historically low level.
The outcome data is the substance of the argument. The report ties the falling payment rate to victims becoming sensitive to how volatile post-payment outcomes actually are: the LockBit takedown revealed that victims had been paying for deletion that was never actually delivered, and in the Klue case stolen data was retained by a separate criminal group despite the ransom being paid — leaving the victim exposed to continuing extortion over exactly the material the payment was meant to retire.
State it to the board in one line: a payment buys a probability, not an outcome, and the counterparty does not disclose the probability. For the exfiltration-only variant specifically, where there is no decryptor and the entire product is a promise, see the analysis of exfiltration-only ransomware in 2026 and the Silent Ransom Group campaign against law firms, whose large settlements are part of what pushed the Q2 average up.
Evidence checklist
Ordered by the gate that consumes each artefact.
For the sanctions gate - Every actor identifier captured and preserved: destination wallet addresses, negotiation portal URLs and handles, verbatim ransom note text, malware family and version, TTP mapping. - The screening result against each list, with the timestamp and the list version screened. - The re-screen run immediately before transfer, with its own timestamp.
For the authority gate - The pre-incident decision-authority record as it stood before the demand. - Approval minute with the time of decision and the names of those who approved. - Counsel engagement letter; insurer notification with its time and the consent response received.
For the recovery gate - Dated restore-test results for each affected system class, with measured restore times. - The business tolerance those times were compared against, and who owns it.
For the alternatives filing (NYDFS 30 days, and any supervisor asking the same question) - A written record of each alternative considered and why it was rejected. This is contemporaneous or it is worthless.
For OFAC and OFSI mitigation - The law enforcement report with submission time and reference number, and the cooperation log kept after it. - Evidence of the security measures already in place before the incident.
That last item is the one nobody can produce under pressure. OFAC treats meaningful steps taken to reduce the risk of extortion by a sanctioned actor as a significant mitigating factor, and NYDFS asks what diligence you performed — both are questions about dated records of what you were doing before the demand arrived, and neither is answered by a policy document written after it. Zero Hunt is built so that record exists as a by-product: scheduled and change-triggered campaigns run continuously against the perimeter, each campaign is timestamped and mapped across the 32 compliance frameworks the platform tracks — including NIS2 Title 13, DORA and GDPR — and exports as an ECDSA-signed report with chain-of-custody through the Trust Center. When counsel asks what you were doing about ransomware exposure in the six months before the demand, the answer is an evidence bundle with dates on it rather than a recollection.
Common failure modes
1. Contacting the actor before counsel and the insurer. The first message frequently breaches a policy condition on prior consent and creates a discoverable record outside privilege. Both are unrecoverable.
2. Treating backup existence as recovery capability. “We have backups” is not an answer to Gate 2. A measured restore time on a tested restore of the affected system class is. Anything else is a hope with a retention policy attached.
3. Paying to suppress publication. You are buying an unverifiable negative from a counterparty with a documented record of non-performance. Where a deletion promise is the entire product, price it as what it is.
4. Screening sanctions once. The screen run when the demand arrived is not the screen that protects the transfer. Designations change mid-incident; re-run it immediately before funds move.
5. Running negotiation and notification as one workstream. The 24-hour and 72-hour clocks do not pause for a negotiation, and the negotiation team is the wrong team to draft a regulatory filing. Staff them separately off a shared evidence base.
6. Inventing the decision authority during the incident. A decision made by whoever is most senior on the bridge at 3am will not survive the 30-day written justification, because there is no record of alternatives considered — nobody was assigned to consider them.
Goes deeper
Want this against your environment?
Book a 30-minute scoping call — we will map this directly to your current compliance scope and threat profile.