What payment actually buys — and what it does not
Paying buys a decryption tool of uncertain quality and a promise from criminals. Industry experience worldwide is consistent on the limits: decryption is often slow and partial, some data never returns, stolen data is not reliably deleted, and payment marks the payer — organisations that pay are documented to be re-targeted. Payment also does not shorten the hardest part of recovery: rebuilding trust in compromised systems, which you must do whether or not a decryptor works.
None of that makes the decision trivial for a company staring at a stopped business and no working backups. It makes the real lesson visible: the decision is lost or won months earlier, when backups were or were not isolated and restore-tested, and continuity plans were or were not built.
The decision factors, laid out
| Factor | Questions the board will ask | Where the answer comes from |
|---|---|---|
| Recovery capability | Can we restore from backups, and how long will it truly take? | Restore tests — not backup logs |
| Business tolerance | How long can critical activities run degraded or stopped? | The BIA and manual-mode plans |
| Legal and sanctions exposure | Is payment lawful here? Does the recipient trigger sanctions liability? | Counsel — engaged before, not during |
| Insurance position | What does the policy cover, require and forbid? | The cyber policy wording and insurer hotline |
| Data theft dimension | What was exfiltrated, and what are the notification duties? | Forensics plus data-protection counsel |
A decision this heavy should never be improvised at 3 a.m. The preparation artefact is a pre-agreed decision framework: who convenes, which factors are weighed, who has the final word, which advisers are on retainer. Write it in peacetime; it reads impossible to write during the event.
Why tested recovery changes everything
- It converts extortion into an outage. With isolated, restore-tested backups and rehearsed manual-mode, the attackers hold your inconvenience, not your survival.
- It changes the negotiation even if you engage. A credible recovery path collapses the attacker's leverage and the price.
- It satisfies the people you answer to. Boards, insurers and regulators all ask the same question after the event: could you have recovered without paying? «Yes, and here is the test evidence» is the only comfortable answer.
Frequently asked questions
Is paying ransom illegal in the UAE?
Treat this as a question for your counsel before any event — the lawfulness depends on circumstances including who the recipient is (sanctions exposure) and evolving regulation. Building the legal answer into your framework in advance is precisely the point of the framework.
Our insurer covers ransom payments. Does that settle it?
No — coverage is one factor, not a decision. Policies impose conditions, approvals and exclusions, and coverage does not remove sanctions or notification exposure, nor the operational reality that payment does not guarantee recovery.
What is the single best investment against ever facing this choice?
Isolated backups proven by regular restore tests, plus a rehearsed manual-mode for critical activities. Together they are the difference between an extortion and an outage — and they cost a fraction of one ransom demand.