Should Organizations Pay Ransom During a Cyber Attack?

by Johnathan Belcher 📅 June 12, 2026 ⏱️ 5 min read

When an organization is hit by a cyber attack, paying the ransom might seem like the fastest way to regain access to data and reduce downtime. My view is that the answer is almost always no. A mature cybersecurity program should be built around preparation, resilience, and recovery planning so the business is not forced into a desperate decision when an attack happens.

Paying ransom does not guarantee that the stolen or encrypted data will be returned. It can also encourage more attacks by showing threat actors that the organization is willing to pay. In some cases, it may even create legal and compliance risks if the payment involves sanctioned entities or restricted groups.

The Office of Foreign Assets Control (OFAC) has warned organizations about the risks tied to making ransomware payments to restricted threat actors. These groups are often connected to larger criminal or state-sponsored operations, which means the money can be used to fund further malicious activity. From that perspective, paying the ransom can do more harm than good.

That said, many businesses still end up paying because they are unprepared and feel they have no better option. A lack of tested backups, incident response planning, and clear recovery procedures can turn a cyber incident into a business crisis. The real lesson is that organizations should invest in prevention and recovery before an attack, not after one.

If a company builds redundancy into its systems, keeps reliable offline backups, and trains its staff to respond quickly, it can recover without rewarding criminal behavior. That is the stronger long-term strategy, even if it requires more planning up front.

References

Back to Blog