AYush Chhabra

The Risk Gap

Perspectives on risk, security, and decisions that matter

Should You Ever Pay the Ransom?

Should you ever pay a ransom? Everyone says no. You don’t want to fund criminals. The FBI says don’t. Never give in to what they want. So don’t pay, right?

Okay. But what if you’re a hospital and human lives are on the line? What if you’re a data center, and now major companies the world actually relies on are down — billions of dollars lost instantly, every minute the clock keeps ticking? Maybe we should pay?

There’s no right answer there. And anyone who tells you there is hasn’t sat with the question long enough.

It depends on what you’re optimizing for

For some people, availability is everything. You need it all back, you need it back now, and the ransom is cheaper than the downtime. That’s a fair position. It makes sense. I’m not going to pretend a CFO making that call in the middle of a crisis is being unethical — they’re doing math the rest of us aren’t being asked to do.

For others, principle wins. You don’t pay because paying funds the next attack, marks you as someone who’ll pay again, and (depending on who the group is) might actually be illegal under OFAC. That’s also a fair position.

Both can be right. Both can be wrong. It depends on the situation, the threat actor, the data, the regulators breathing down your neck, and honestly, sometimes just how bad the week has been.

The real question

But here’s what I think the conversation should actually be about: where were your backups?

Because if you don’t have backups, if you don’t have a disaster recovery plan, if you don’t have anything resembling a tested restore — you screwed up a long time ago. The decision you’re agonizing over right now was already made for you months ago, when somebody said “we’ll get to that next quarter.”

The organizations that don’t pay tend to be the ones that prepared for the rainy day. They have isolated backups. They have segmentation. They have an IR firm on speed dial. When the ransom note hits, they’re inconvenienced, not destroyed.

The organizations that do pay are usually the ones who weren’t ready. And by the time the screen goes red, it’s too late to get ready.

So what should you actually be doing?

Be prepared. That’s it. That’s the whole point.

If you’re a senior leader and you don’t have the budget for backups, IR retainers, tabletop exercises, segmentation — go fight for it. Today. Not next quarter. Especially right now, in the age of AI, where exploits are being found faster and used more sophisticatedly than anything we’ve seen before. Attackers are scaling. Defenders need to scale with them.

It’s not a question of if you get hacked. It’s when. And when it happens, the only thing that matters is how prepared you are to get back online without a hiccup.

If you’re prepared, you don’t need to pay. If you’re not, you’re already cornered. Nobody wants to be the executive making a panicked decision at 2 a.m. about wiring bitcoin to a group in a country they can’t pronounce.

So don’t end up there. Get the budget. Build the plan. Test the restore. Run the tabletop nobody wants to run.

That’s the only part of this question I’m sure about.