Usually, no.
Paying a ransomware demand is a high-risk decision with no guaranteed outcome. You might not receive a working decryptor. You might recover only part of your data. The attackers may keep stolen information, demand more money, or target you again.
For a small business, the decision can feel impossible. Your files may be mission critical. Payroll, customer records, production systems, and accounting data may all be locked at once.
But payment should not be your first move.
Your first move should be containment, legal guidance, insurance notification, law-enforcement reporting, and a clear assessment of your recovery options.
WHAT PAYING A RANSOM ACTUALLY GETS YOU
Ransomware criminals promise a key or decryptor in exchange for cryptocurrency. That promise is not a contract you can enforce.
Payment may get you:
- A decryptor that works only on some files.
- A tool that is slow, corrupted, or technically defective.
- Instructions that fail because the attackers miscalculated or damaged their own malware.
- Continued extortion after payment.
- No meaningful help at all.
A decryptor is not the same as a complete recovery.
Even when a decryptor works, it may not restore databases, applications, permissions, file names, or system configurations correctly. You may still need to rebuild servers, replace compromised devices, reset credentials, and validate every restored system.
If the attackers stole data before encrypting it, payment may not prevent publication or resale. This is known as double extortion. You can pay and still face a data breach.
The Federal Trade Commission’s ransomware guidance makes the point plainly: even if you pay, criminals may keep your data or destroy your files.
THE DOWNSTREAM COSTS ARE EASY TO UNDERESTIMATE
The ransom is only one part of the cost. A payment can create additional operational, legal, and financial problems.
REPEAT TARGETING
A business that pays may be viewed as a proven source of revenue. That can increase the risk of repeat attacks.
The same criminal group may return. Another group may buy or share information about your company. Your exposed credentials may also remain useful long after the first incident.
Payment does not repair the weakness that allowed the attack. If the entry point was a stolen password, unpatched system, exposed remote access tool, or poorly protected backup, the attackers may still have a way back in.
SANCTIONS AND OFAC EXPOSURE
Some ransomware groups and cybercriminals are subject to U.S. sanctions.
The U.S. Treasury’s Office of Foreign Assets Control warns that companies involved in ransomware transactions may face sanctions risk if a payment is connected to a designated person or entity.
That does not mean every ransomware victim is automatically penalized. It does mean you cannot treat payment as a simple business expense.
Before anyone discusses payment, your company should involve:
- Legal counsel.
- Your cyber insurance carrier.
- Your insurer’s approved incident-response provider.
- A qualified sanctions-compliance resource.
- Law enforcement, where appropriate.
Do not attempt to identify or negotiate with the attacker alone. Do not assume that cryptocurrency makes a transaction untraceable or legally safe.
INSURANCE IMPLICATIONS
Your cyber insurance policy may cover some incident costs. It may also require you to follow specific procedures.
Those procedures can include:
- Reporting the incident within a defined timeframe.
- Using approved forensic and legal providers.
- Preserving evidence.
- Obtaining authorization before making a payment.
- Following reasonable security and backup requirements.
- Cooperating with law enforcement.
Contact your insurer as soon as you suspect ransomware. Do not wait until you have all the facts. The insurer can help coordinate forensic investigation, legal review, breach notification, recovery, and, if absolutely necessary, payment analysis.
A policy that covers ransom payments does not mean payment is automatically the best choice. Insurance may cover a financial loss. It cannot guarantee that your files will be restored or that your reputation will be unaffected.
BREACH-OF-CONTRACT RISK
Your customers may expect you to protect their data and maintain service availability.
A ransomware incident can trigger obligations under:
- Customer contracts.
- Service-level agreements.
- Data-processing agreements.
- Vendor agreements.
- Industry regulations.
- State breach-notification laws.
If customer data was accessed or exfiltrated, you may have notification obligations even if you pay. If systems remain unavailable, you may also face service credits, penalties, delayed deliveries, or contract disputes.
This is why technical recovery and legal review must happen together.
WHAT INSURERS AND LAW ENFORCEMENT EXPECT FIRST
If ransomware is active now, do not start by negotiating with the attacker. Start by preserving your options.
1. ISOLATE AFFECTED SYSTEMS
Disconnect infected devices from the network. Disable compromised accounts. Separate affected network segments where possible.
Do not immediately wipe every device. Evidence may be needed to determine how the attackers entered, what they accessed, and whether data was stolen.
2. CONTACT YOUR INSURER AND LEGAL COUNSEL
Follow your cyber insurance policy’s reporting instructions. Ask which incident-response, forensic, and legal providers are approved.
Legal counsel can help evaluate:
- Sanctions exposure.
- Breach-notification requirements.
- Contractual obligations.
- Regulatory reporting.
- Communications with customers and employees.
- Whether payment creates additional liability.
3. REPORT THE INCIDENT
Law enforcement generally discourages ransom payment because it does not guarantee recovery and funds criminal activity.
Reporting can still help your company. It creates an official record, supports broader investigations, and may provide access to threat intelligence about the group involved.
The National Institute of Standards and Technology’s ransomware guidance recommends preparing to protect, respond to, and recover from ransomware rather than assuming payment will solve the problem.
4. PRESERVE LOGS AND EVIDENCE
Keep relevant system images, alerts, email messages, ransom notes, network logs, and access records.
Do not modify or destroy evidence unnecessarily. A forensic investigation may reveal that the attacker had access weeks before encryption occurred.
5. ASSESS YOUR RECOVERY OPTIONS
Determine:
- Which systems are affected.
- Which data was encrypted.
- Which data may have been stolen.
- Whether backups are intact.
- When the last clean backup was created.
- How long restoration will take.
- Which systems are mission critical.
- Whether manual workarounds are possible.
- What customers and regulators must be told.
This assessment gives you something better than a panic-driven decision: a comparison between the known cost of recovery and the uncertain outcome of payment.
BACKUPS ARE ONLY USEFUL IF YOU CAN RESTORE FROM THEM
“ We have backups” is not enough.
Your backups must be protected from the same attack. If an attacker has administrative access to your network, they may also be able to delete or encrypt connected backups.
A resilient backup strategy should include:
- Offline or otherwise isolated backup copies.
- Multiple recovery points.
- Separate administrative credentials.
- Encryption in transit and at rest.
- Documented retention periods.
- Defined recovery priorities.
- Regular restoration tests.
- Clear ownership for recovery decisions.
Testing matters most.
A backup that has never been restored is an assumption. A tested backup is evidence.
Your infrastructure and cloud strategy should account for recovery time objectives and recovery point objectives in plain business terms:
- Recovery time objective: How long can a system be unavailable?
- Recovery point objective: How much recent data can the business afford to lose?
These are not abstract IT measurements. They determine whether your company can process orders, pay employees, serve customers, and continue operating after an incident.

THE REALISTIC ALTERNATIVE TO PAYING
The alternative is not simply “do nothing and hope.”
The alternative is a prepared recovery process supported by:
- Tested backups.
- Multifactor authentication.
- Current security patches.
- Endpoint protection.
- Email security.
- Network segmentation.
- Least-privilege access.
- Employee phishing awareness.
- Vendor access controls.
- A written incident-response plan.
- Clear communication responsibilities.
A strong security program reduces the chance of an attack and improves your options when controls fail.
No cybersecurity consulting firm can promise that you will never be attacked. We can help you identify weaknesses, prioritize mission-critical systems, document recovery steps, and support your internal team without creating unnecessary dependency.
If a specialized emergency incident-response firm is required, we will tell you. Honest guidance includes knowing when a situation falls outside our core expertise.
SHOULD YOUR BUSINESS EVER PAY?
Payment should be treated as a last resort, not a recovery strategy.
In an extreme situation, company leadership may decide that payment is necessary to protect the business. That decision should happen only after:
- Legal counsel reviews sanctions and regulatory risks.
- Your insurer approves the process, if applicable.
- Law enforcement has been contacted.
- A qualified incident-response team assesses the attacker and decryptor.
- Backups and other recovery options have been evaluated.
- The business understands that payment does not guarantee recovery or confidentiality.
- Leadership documents the decision and its reasoning.
The direct answer remains: most small businesses should not pay a ransomware demand.
Build the capability to recover instead.
PREPARE BEFORE THE DECISION IS URGENT
The best time to review ransomware readiness is before your systems are locked.
Five 9 LLC can help you evaluate your current environment, prioritize improvements, and build practical recovery processes through IT consulting, infrastructure planning, cloud support, and ongoing managed IT services for small business.
You do not need to have every answer before starting. You need an honest assessment of your exposure and a clear path forward.
Contact Five 9 LLC for a no-pressure conversation about your backups, recovery time, security controls, and incident-response readiness. We will help you understand what is working, what is not, and what deserves attention first.
