Few things cause a business owner to panic like ransomware. And when systems freeze, files lock, and the business grinds to a halt, paying the ransom feels like the only way out. But the research shows that paying ransomware doesn’t guarantee you get your data back. In fact, it often costs more than the alternative.
According to a 2024 survey from Veeam, ransomware data loss is worse than ever. Only one in three businesses (32%) that paid the ransom actually got their data back last year, compared with more than half (54%) in 2023. That’s a sobering drop, and a clear sign that cybercriminals are no longer keeping their end of the bargain.
This guide walks you through the actual numbers: what happens when you pay, what happens when you don't, and how to make a decision that protects your business instead of feeding the criminal economy.
Should a Small Business Pay a Ransomware Demand?
Usually no. A small business should consider paying the ransom as a last resort, not as part of its ransomware recovery plan. Payment does not guarantee decryption, data removal, or the restoration of secure operations, which is why U.S. federal authorities advise against paying.
Why shouldn't businesses pay by default?
- A decryption program might not work correctly or quickly, and the attackers could demand more money after the first payment.
- The attackers could retain and later leak or resell the stolen data.
- Paying can make the business appear willing to pay and fund future attacks. Cybercriminals share information about companies that are willing to pay, putting you on a virtual target list.
When should you consider paying the ransom?
- Your business should only consider paying after determining that:
- There are no viable backups or a plan to rebuild essential services in a timely manner.
- There is a real and documented threat to life, safety, or critical operations.
- Your insurer, your legal counsel specializing in incident response, and law enforcement have been notified.
- Specialized legal counsel and payment service providers have conducted due diligence regarding legal and sanctions matters.
- Management understands and accepts that payment does not guarantee decryption, deletion, confidentiality, or future security.
How Long Does it Take to Recover From Ransomware?
Paying for a ransomware decryption key does not accelerate recovery. Receiving a key is only the beginning. The victim still needs to decrypt servers and endpoints, validate data integrity, eliminate the attacker's persistence, restore identities, remediate the intrusion vector, and securely restore services.
However, companies with intact and tested backups have at least the same probability, and according to survey data, even a higher probability, of recovering within a week, avoiding ransom payments and substantially reducing recovery costs.
What Happens to Your Data If You Pay the Ransom?
When you pay a ransom and receive a decryption key, you expect to get your data back. That's literally the deal. Except it doesn't always work that way.
According to Sophos's State of Ransomware report (which surveyed 3,400 organizations), companies that pay the ransom recover only about 60% of their data on average. That's a 40% data loss despite payment.
In some cases, it's worse. Semperis's 2024 survey found that 35% of organizations that paid received corrupted decryption keys or no keys at all. They paid thousands of dollars and got nothing.
Why Decryption Keys Sometimes Don't Work
Poor encryption implementation. Some ransomware variants are built hastily by criminal gangs. The encryption tools they provide are buggy, slow, or incomplete.
Partial encryption. Attackers encrypt files in stages as they move through your network. You may have files encrypted at different times with different keys. Not all files decrypt cleanly.
Corrupted backup. Ironically, even if the attacker's key works perfectly, the data it unlocks might already be corrupted from the encryption process itself.
Intentional sabotage. Some threat actors provide broken keys deliberately after payment fails. Their business model relies on repeat victims, not satisfied customers.
Encryption flaws. In some cases—like the Vect ransomware that emerged in January 2026—the encryption contains mathematical flaws that render decryption impossible, even with the "correct" key.
What Are the Risks Involved in Paying Ransomware Attackers?
Payment isn't a simple transaction. It comes with hidden costs and risks that often outweigh the immediate benefit.
Legal Risk #1: Sanctions Violations (Criminal Liability)
The U.S. Treasury Department maintains a list of sanctioned individuals and entities. If the attacker is on that list, paying them is illegal under the International Emergency Economic Powers Act.
Not "could get you fined." Not "might trigger an investigation." Illegal. Criminal liability.
How do you know if the attacker is sanctioned? You have to research them. That's where professional negotiators earn their fee, by validating that the threat actor isn't on the OFAC list before payment is processed. If you pay a sanctioned actor without checking? You could face:
- Criminal prosecution
- Civil fines up to $300,000+ per violation
- Seizure of assets
- Corporate liability if your CEO approved the payment
Legal Risk #2: Regulatory Fines (Don't Disappear After Payment)
Paying the ransom doesn't make the breach go away. You still have to disclose the breach, notify affected parties, and comply with regulations.
- GDPR (if you handle EU data): $1-15 million in fines or 2-4% of global revenue (whichever is higher)
- HIPAA (if you handle health data): $100-$50,000 per violation, per year. For a 50-person healthcare practice with 10,000 patient records exposed, that could be $5-50 million.
- State data breach laws: 48 states have notification requirements. Most trigger fines if you don't notify within 30-72 days. Paying the ransom doesn't give you an extension.
Payment doesn't reduce these fines. The regulators don't care that you paid. They care that there was a breach. Fines are typically imposed based on the breach's severity, not your response.
Operational Risk #1: The Repeat Attack Problem
Here's the thing about paying: attackers talk to each other. Organizations have documented that after paying once, they're targeted again within months. The second time, the demand is higher.
Why? Because:
- Your payment was logged in the criminal underground ("XYZ Corp paid $200K, they're good for higher numbers")
- Your security is still weak (they got in once, they can get in again)
- You've shown you'll negotiate (they know you might pay again)
Data from Semperis shows that 32% of attacked companies paid ransoms four or more times in a single year. If a criminal enterprise figures out that Company A will pay, they'll extract value from Company A repeatedly. Same attackers, different variants, same payment pattern.
Operational Risk #2: Downtime
The actual cost of downtime varies from one industry to another, and from one business to the next. So, what's Your downtime cost? Calculate the financial impact of being offline.
- How much revenue do you lose per day when offline? ($500? $5,000? $50,000?)
- How many days can you afford to be down? (1 week? 1 month?)
- What's your threshold before the business faces existential risk?
How Do Ransomware Payment Negotiation Services Work?
If paying makes sense for your situation, you don't do it alone. You hire professionals. Sophos found that 47% of organizations that paid less than the initial demand said direct negotiation helped reduce the payment.
What These Services Provide
Professional ransomware response firms (like CYPFER, Cyber Centaurs, Coveware, and others) offer:
- Threat validation: They confirm the attacker actually has your data and can decrypt it. Some attackers bluff; negotiators can call that.
- Demand reduction: They negotiate with the attacker (via email, Telegram, or chat) to reduce the payment demand.
- Threat actor profiling: They research whether the attacker is known, trustworthy (in criminal terms), or likely to follow through on promises.
- Cryptocurrency handling: They guide you through buying cryptocurrency, setting up wallets, and transferring funds securely—without you having to become a crypto expert.
- Coordinated response: They work with your legal counsel, insurance carrier, and IT team to ensure compliance with your cyber insurance policy and regulatory obligations.
The Cost
Negotiation services typically charge 10-15% of the negotiated ransom amount. If they reduce your demand from $500K to $250K and charge 15%, you pay them $37,500 and the attacker $250,000. Net cost: $287,500 vs. the original $500K demand.
This isn't cheap, but for some businesses in certain instances, it can be substantially cheaper than the alternative.
The Ethical Debate
In January 2026, two former ransom negotiators of a major incident response firm (DigitalMint) pleaded guilty to colluding with ransomware attackers to deploy BlackCat/ALPHV ransomware and extort multiple companies. Total losses exceeded $9.5 million.
Not all negotiation firms are trustworthy, some have questionable practices or undisclosed relationships with threat actors. You need to vet them carefully, check references, and ensure they're working with law enforcement (FBI, IC3) as appropriate.
What Is the Alternative to Paying Ransomware?
Here's where backup strategy becomes critical to your decision. Despite the likelihood of permanent data loss to ransomware, Veeam’s EMEA ransomware research found that the proportion of organizations recovering data without paying a ransom more than doubled, from 14% in 2023 to 30% in 2024.
Businesses are becoming more savvy about data recovery and cybersecurity breaches, but attackers know backups are the kryptonite to their business model. So they specifically target them. According to recent incident response data:
- 96% of ransomware attacks target backup infrastructure
- 76% of attacks successfully compromise backup systems
If your backups are on the same network, accessible from your production systems, or protected only by the same credentials as your user accounts, an attacker will find and destroy them.
The organizations that recover quickly and completely have:
- Air-gapped backups: Backups stored offline or on a completely separate network that attackers can't reach.
- Immutable backups: Once data is written to backup storage, it can't be modified or deleted for a set retention period (e.g., 30 days). This is standard in cloud backup services.
- Learn more about off-site immutable cloud backup
- Multi-factor authentication: Backup access requires approval from multiple people or systems, so one compromised account can't wipe all backups.
- Regular testing: They restore from backup at least quarterly to verify backups actually work. Many organizations discover their backups are corrupted only when they try to restore.
Read more: Data Backup Schedule: How Often Should SMBs Back Up Data?
What Does Cyber Insurance Cover When You're Hit With Ransomware?
Ransomware represented 60% of the value of large cyber-insurance claims in the first half of 2025 according to Allianz. Your cyber insurance might save your business when your IT is properly structured. Take a look at what good cyber insurance entails.
What Most Policies Cover
- Ransom payments (sometimes, but not always)
- Professional incident response services (IR firms, forensics)
- Legal counsel (breach notification, compliance)
- Credit monitoring (if customer data is exposed)
- Business interruption losses (in some policies)
What They Often Don't Cover
- Ransom payments if they violate OFAC sanctions (your insurer won't pay if payment is illegal)
- Regulatory fines (varies by policy, but many exclude government penalties)
- Losses from repeated incidents if you didn't improve security after the first attack
- Ransoms paid without the insurer's approval (you must involve them in the negotiation)
- Recovery costs if you used unapproved vendors (always coordinate through your insurer)
The Claims Process
When you're hit, you need to:
- Notify your insurer immediately (usually within 24-48 hours)
- Don't pay without approval (if you do, the claim might be denied)
- Work with their recommended vendors (IR firms, negotiators)
- Document everything (every decision, every communication, every cost)
Note: if you deviate from this process by hiring your own negotiator, paying without approval, or using unauthorized vendors your insurer can deny the claim.
The Premium Impact
After a ransomware claim, expect your cyber insurance premium to increase 15-25% the next renewal cycle. This can add $10,000-$50,000+ annually to your costs.
If you get hit multiple times (and 32% of victims do), your premium becomes unaffordable and you might be dropped from coverage entirely.
How to Protect Your Business From Ransomware?
The smartest defense is preparation. Investing in proactive cybersecurity and reliable data recovery strategies is the most effective way to protect your business from ransomware, data loss, and costly disruptions. Begin by auditing your backup systems to guarantee that copies of important data are stored securely and offline. Train employees to recognize phishing attempts. Here's what you can do right now:
Test your backups this month. For real. Actually restore a system. If you can't, your backup strategy is theoretical.
Get cyber insurance if you don't have it. Read the fine print. Know what's covered. Know the claims process.
Segment your backups. They should not be accessible from your main network. Cloud backup with immutable retention is the easiest approach for SMBs.
Build your incident response plan. Write down who's responsible for what when ransomware hits. Having a plan written down changes everything. Document this. If you're hit, regulators will ask what your response plan was. Having a documented plan shows good faith.
If you're hit and considering payment: Get legal counsel involved immediately. Get your insurance carrier involved. Hire professional negotiators. Don't wing it.
The ransomware landscape has shifted. Paying is no longer the default path. The new default is "refuse to pay, recover from backups, and improve your security so it doesn't happen again."
For SMBs with that strategy in place? Ransomware is survivable. Yes, even costly. But not catastrophic.
Premier Technologies builds and manages immutable backup systems for SMBs across Southern Wisconsin and Northern Illinois that restore your entire environment in hours. We take on the liability, so you never have to negotiate with criminals.
Get an assessment of your backup segmentation, recovery testing, and incident response readiness.


