The Ethical Dilemma Of Ransomware Payments: Should You Pay Or Not

In 2023, businesses paid over $1 billion in ransom payments, the highest amount ever in any calendar year. Experts predict that ransom payments will be even higher in 2024 as the rate of ransomware attacks continues to grow. Most of these attacks target sensitive businesses in sectors such as healthcare and finance, which are heavily affected by any form of downtime.

Also, over 85% of these attacks target small businesses, which may be due to the weak security measures in place compared to large enterprises. If your organization is hit by a ransomware attack, you are immediately faced with the ethical dilemma of whether to pay the ransom or not. Authorities in almost every jurisdiction recommend against paying ransom, as it encourages more future attacks. However, some business leaders decide to pay ransom if the encrypted data is extremely important to the operations of the business.

In today’s article, we will answer the question of whether you should pay ransom or not. But first, let’s discuss the legal side of this question.

 

What does the law say?

In the United States, there isn’t a federal law explicitly prohibiting ransom payments to cybercriminals. While it’s generally legal to pay ransom, cybersecurity experts often advise against it. They argue that paying ransom may encourage further attacks and doesn’t guarantee the safe return of stolen data.

In some situations where a company’s critical assets are at stake and there are no other viable options, a company may decide to pay the ransom. Legally, they are allowed to do so to mitigate potential damages. However, paying ransom may have other indirect legal consequences such as money laundering which we will discuss later in the article.

 

Why do businesses choose to pay ransom?

No backups made

Backing up crucial data is a fundamental practice in cybersecurity. However, if a business fails to create backups or if the backups are also affected during a cyberattack, they might be forced to pay the ransom to regain access to their data. Without backups, paying ransom might seem like the only option to recover important information. That’s why it is crucial to have multiple backups for sensitive data to avoid being in such situations.

 

Minimize Downtime

A cyberattack can severely disrupt a business’s operations, leading to significant downtime. During this period, the business may lose revenue, productivity, and even credibility among customers. To minimize these losses and quickly resume normal operations, some businesses usually opt to pay the ransom to regain control of their systems and data.

 

External pressure and lack of alternatives

Businesses usually face pressure from various stakeholders, including shareholders, customers, and other partners, to resolve cyber incidents as soon as possible. If there are no viable alternatives to recover the encrypted data or restore systems, the pressure to pay ransom may increase. This is mainly common with public companies.

Most shareholders will put pressure on the company to pay the ransom to avoid a bigger loss in their investment if the attack significantly affects the company’s operations. Investors are usually concerned about their money and not how the company’s reputation could be damaged in the long term.

 

Insurance Coverage

Some businesses have cyber insurance policies that include coverage for ransom payments. In such cases, the decision to pay ransom may be influenced by the availability of insurance coverage. If paying ransom is covered by the policy, it may seem like a more viable option for mitigating financial losses associated with the cyberattack.

According to Statista, companies with cyber insurance received over 72% of the clean-up costs required to deal with the ransomware attacks they had faced in 2021. Overall, companies with cyber insurance are more likely to pay ransom as compared to those that are not insured.

 

Why you Should not Pay Ransom

Besides the quick results that may come from paying the ransom, cybersecurity experts and authorities don’t recommend it. Here is why:

It encourages the Criminals to Launch More Attacks

Paying ransom can create a dangerous precedent, encouraging cybercriminals to continue their illegal activities. If attackers know that their demands will be met, they will be motivated to launch more attacks, targeting more businesses and individuals. This can lead to a surge in cybercrime, making it a lucrative business for criminals.

By not paying ransom, you are denying them a source of income and reducing the incentive to launch future attacks. A recent study shows that 80% of victims who pay ransom are hit the second time. This same study shows that 40% paid again and 70% of them were charged a higher amount compared to the first attack. Such numbers clearly show that paying ransom creates more harm than good to your company and other businesses.

 

Hacker May Simply Increase the Demand

Cybercriminals often use ransomware attacks as a negotiating tactic, hoping to extract as much money as possible from their victims. If you pay the initial ransom, the attacker may see this as a sign of weakness and increase their demands. The attackers know that businesses are only willing to pay the ransom if the affected data is crucial for their operation.

So, paying ransom will often lead to a never-ending cycle of negotiations, with the attacker constantly increasing their demands. By not paying ransom, you are taking away the attacker’s leverage and reducing the likelihood of further extortion.

 

No Guarantee You’ll Get the Data Back

Paying ransom does not guarantee that the attacker will unlock your data or stop the attack. Cybercriminals may take the money and run, leaving you with nothing. In some cases, the attacker may not have the capability to unlock the data, or they may have sold the decryption key to another criminal gang.

A 2023 report by Sophos indicated that 92% of the companies that paid ransom didn’t get their data back. 29% were only able to recover half of the affected data. That means there is only an 8% chance that you will get all your data back when you pay the ransom. By not paying the ransom, you are not wasting valuable resources on an uncertain outcome.

 

It Could Affect Your Cyber Insurance Rates

Cyber insurance policies are designed to help businesses recover from cyberattacks. However, if you pay ransom, your insurance company may view this as a sign of weakness or negligence. This could lead to increased premiums or even policy cancellation. By not paying ransom, you are demonstrating a commitment to cybersecurity and reducing the likelihood of increased insurance costs.

 

Future Legal Action

Paying ransom could have future legal implications, both domestically and internationally. Law enforcement agencies may view paying ransom as a sign of complicity or obstruction of justice, leading to future legal action. Ransom payments are also usually made using dubious means that may violate international sanctions or anti-money laundering regulations, leading to legal consequences. By not paying ransom, you are avoiding potential legal pitfalls and demonstrating a commitment to ethical business practices.

 

Final Thoughts

While paying ransom might seem like a quick fix to regain access to data after a cyberattack, it’s a risky decision with significant downsides. Not only does it encourage further attacks, but it also offers no guarantee of data recovery and can even lead to legal complications.

Instead, businesses should prioritize strong backups, and robust security measures, and implement their incident response plans to minimize downtime and resist the temptation of ransom payments. Collaborating with law enforcement is also crucial to combat ransomware attacks and protect sensitive data.

To further strengthen your digital defenses, you take advantage of our penetration testing service. This service involves in-depth analysis of your systems to detect any vulnerabilities attackers could take advantage of to launch ransomware and other forms of cyberattacks. You can reach out to our support team for more details about this service and other similar services geared towards preventing ransomware attacks.

 

CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

Abdallah Alhajeid

WordPress Developer

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation