Signature scenario · The hardest decision

Pay or recover? Examining the decision nobody wants to face

The honest answer is uncomfortable: by the time the question is asked, most of the answer is already fixed — by the state of your backups, your plans and your preparation. Here is the decision, examined without slogans.

What payment actually buys — and what it does not

Paying buys a decryption tool of uncertain quality and a promise from criminals. Industry experience worldwide is consistent on the limits: decryption is often slow and partial, some data never returns, stolen data is not reliably deleted, and payment marks the payer — organisations that pay are documented to be re-targeted. Payment also does not shorten the hardest part of recovery: rebuilding trust in compromised systems, which you must do whether or not a decryptor works.

None of that makes the decision trivial for a company staring at a stopped business and no working backups. It makes the real lesson visible: the decision is lost or won months earlier, when backups were or were not isolated and restore-tested, and continuity plans were or were not built.

The decision factors, laid out

FactorQuestions the board will askWhere the answer comes from
Recovery capabilityCan we restore from backups, and how long will it truly take?Restore tests — not backup logs
Business toleranceHow long can critical activities run degraded or stopped?The BIA and manual-mode plans
Legal and sanctions exposureIs payment lawful here? Does the recipient trigger sanctions liability?Counsel — engaged before, not during
Insurance positionWhat does the policy cover, require and forbid?The cyber policy wording and insurer hotline
Data theft dimensionWhat was exfiltrated, and what are the notification duties?Forensics plus data-protection counsel

A decision this heavy should never be improvised at 3 a.m. The preparation artefact is a pre-agreed decision framework: who convenes, which factors are weighed, who has the final word, which advisers are on retainer. Write it in peacetime; it reads impossible to write during the event.

Why tested recovery changes everything

Frequently asked questions

Is paying ransom illegal in the UAE?

Treat this as a question for your counsel before any event — the lawfulness depends on circumstances including who the recipient is (sanctions exposure) and evolving regulation. Building the legal answer into your framework in advance is precisely the point of the framework.

Our insurer covers ransom payments. Does that settle it?

No — coverage is one factor, not a decision. Policies impose conditions, approvals and exclusions, and coverage does not remove sanctions or notification exposure, nor the operational reality that payment does not guarantee recovery.

What is the single best investment against ever facing this choice?

Isolated backups proven by regular restore tests, plus a rehearsed manual-mode for critical activities. Together they are the difference between an extortion and an outage — and they cost a fraction of one ransom demand.

The signature scenarios hub

The best position is never needing the question. Test yours in five minutes.

Request a gap assessmentTake the free readiness check
NCEMA-ready gap assessment