Skip to content

Disaster recovery

Should you pay the ransom after a ransomware attack?

Official guidance, survey data and EU reporting duties, so you can make the decision calmly, or better, never have to make it.

A car waits at a night-time crossroads between a dark foggy road and a lit road, illustrating the ransom decision

The short answer

In most cases, no. The FBI, the Dutch NCSC and the No More Ransom project all advise against paying. Payment doesn't guarantee you get working data back, it funds the next attack, and organisations that pay are often hit again. The alternative is a tested restore from backups that attackers couldn't reach or change.

Key takeaways

  • The FBI, the Dutch NCSC and No More Ransom (Europol and the Dutch police) all advise victims not to pay a ransom.
  • Paying is no guarantee: in Cybereason's 2024 study, 78% of organisations that paid were hit by a second ransomware attack.
  • Organisations whose backups were compromised were almost twice as likely to pay (67% against 36%), according to Sophos.
  • Paying or not, NIS2 Article 23 reporting deadlines (24 hours, 72 hours, one month) and the GDPR 72-hour breach notification still apply.
  • The decision is easiest to avoid: immutable, isolated and tested backups mean you can restore instead of negotiating.

Should you pay the ransom?

No, not as a rule. Every major law enforcement and cyber security authority advises against paying, and the reasons are practical, not only moral. Paying should never replace a disaster recovery plan.

It's 07:30 on a Tuesday. Every screen shows a ransom note and the attackers want bitcoin within 72 hours. The pressure to pay is real. Here is what the authorities say:

  • FBI: "The FBI does not support paying a ransom in response to a ransomware attack," because payment doesn't guarantee recovery and encourages attacks on other victims (IC3).
  • NCSC Netherlands: there is "no guarantee that payment leads to the return of your data"; payment funds criminals, and some victims faced higher demands or new attacks (NCSC, what to do in a ransomware attack).
  • No More Ransom, run with Europol and the Dutch police: "The general advice is not to pay the ransom," because it confirms that ransomware works (nomoreransom.org).
  • NCSC UK, with the British insurance associations ABI, BIBA and IUA, published guidance for organisations considering payment in 2024 that stresses reporting, impact assessment and recording every decision.

More victims are refusing. The Verizon 2026 DBIR, as summarised by Help Net Security, reports that 69% of ransomware victims did not pay.

What actually happens when you pay?

You buy a decryption key and a promise, from a criminal. Neither is guaranteed to work, and the attackers often stay a step ahead.

  • Data isn't always usable. In Cybereason's 2024 study of more than 1,000 security professionals, fewer than half (47%) of those who paid got their data and services back uncorrupted.
  • You become a repeat target. The same study found that 78% of organisations that paid were hit by a second ransomware attack.
  • Decryption is slow. Decrypting server by server takes time, and you still have to rebuild, check for backdoors and validate data before you can trust the systems again.
  • Stolen data stays stolen. Many groups copy data before encrypting it, and a promise to delete it is worth little.

According to the Sophos State of Ransomware 2026, the median ransom payment was $769,000 and the average recovery cost, excluding the ransom, was $1.7 million. Paying adds to the recovery bill.

There is no general EU-wide ban on paying a ransom, but paying can still break the law, and it never removes your reporting duties. Get legal advice before any payment.

  • Sanctions. A payment to a sanctioned person or group can be unlawful. The NCSC UK guidance warns of this for UK sanctions; EU sanctions regimes work on the same principle, and you often can't know who is behind a wallet.
  • NIS2 reporting. Under Article 23 of Directive (EU) 2022/2555, essential and important entities must send an early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours and a final report within one month. Payment changes none of this.
  • GDPR. If personal data was encrypted or stolen, Article 33 of Regulation (EU) 2016/679 requires notification to the supervisory authority within 72 hours where feasible. In the Netherlands that's the Autoriteit Persoonsgegevens.
  • Policy is tightening. In July 2025 the UK confirmed plans, still needing legislation, to ban ransom payments by public bodies and critical infrastructure (The Register).

In the Netherlands, the Cyberbeveiligingswet has applied NIS2 since 15 August 2026; in Germany, the NIS2UmsuCG has applied since 6 December 2025. Check our NIS2 compliance guide to see whether your organisation is in scope.

What should you do in the first hours after a ransomware attack?

Contain, preserve, report and check your backups, in that order, before anyone talks about paying. These steps follow the advice of the Dutch NCSC and Microsoft's own ransomware playbook.

  1. Isolate affected systems. Disconnect them from the network. The NCSC ransomware incident response plan advises not to switch systems off but to put them in sleep mode, so evidence in memory is preserved.
  2. Disable compromised accounts and reset credentials, starting with administrator accounts. Microsoft's response playbook also advises disconnecting online backups until the attack is contained.
  3. Call your IT partner and start a timestamped incident log. Management, insurers and regulators will review it later.
  4. Report to the police. The NCSC notes that police may already hold decryption keys from earlier cases.
  5. Check No More Ransom for a free decryptor for your strain, using the Crypto Sheriff tool.
  6. Verify your backups are intact and clean before you restore anything.
  7. Start the reporting clock: NIS2 early warning within 24 hours if you're in scope, and GDPR notification within 72 hours if personal data is affected.

For the full sequence from detection to normal operations, see our ransomware recovery timeline.

Why do organisations still pay?

Mostly because they have no working alternative. When the backups are gone, paying looks like the only way back.

The data shows this clearly. In Sophos' analysis of compromised backups, attackers tried to compromise backups in 94% of ransomware attacks. Organisations whose backups were compromised were almost twice as likely to pay (67% against 36%), and their median ransom demand was more than double: $2.3 million against $1 million. In the Sophos State of Ransomware 2025, 49% of victims paid.

Paying the ransomRestoring from protected backups
Who controls the outcomeThe attackerYou and your IT partner
Data integrityUncertain; files can be corruptedKnown restore point, scanned before use
SpeedNegotiation, then slow decryption and rebuildDepends on preparation and testing
Repeat riskHigh: you are known to payLower, once the entry point is closed
Legal exposureSanctions risk, extra scrutinyReporting duties only
Stolen dataStill in criminal handsStill in criminal hands

If paying is ever on the table, the NCSC UK guidance lists the questions to answer first: the real business impact, whether workarounds exist, the cost of each recovery option, and whether the root cause is fixed. Record each decision and who made it.

To put a number on the impact, use our cost of downtime model.

How do you make sure you never have to decide?

Make your backups something attackers can't reach, change or delete, and prove you can restore from them. Then a ransom note is a recovery task, not a negotiation.

  • Follow the 3-2-1-1-0 rule: three copies, on two media types, one offsite, one immutable or air-gapped, and zero errors after verification.
  • Separate backup admin access from your normal domain, and require MFA for every admin action.
  • Back up your SaaS data too. Microsoft 365 is not a backup; see does Microsoft 365 back up your data?
  • Test restores regularly, including full systems, and write down how long they take.
  • Plan where you recover. Restoring onto infected infrastructure invites a second encryption.

What to do next

Don't pay as a reflex, and don't make the decision alone. Contain the attack, report it, check No More Ransom and verify your backups. The organisations that end up paying are mostly the ones whose backups failed, so the real decision is made months before the attack.

Mindtime keeps immutable backups (Object Lock) plus an air-gapped copy, scans backups for malware and checks every backup job automatically. Admin actions require MFA. After an attack, VMs boot instantly in an isolated recovery environment on a separate, clean network, and critical workloads are restored on a 4-hour SLA. Our disaster recovery service adds standby infrastructure and quarterly automated DR tests with evidence for auditors.

Not sure whether your backups would survive an attack? Get a free assessment and we'll look at it with you, in Dutch, German or English.

This article is information, not legal advice.

Frequently asked questions

Should I pay the ransom if I'll otherwise lose my files?

First check whether you really will. Report to the police, check nomoreransom.org for a free decryptor, and ask your IT partner to verify every backup, including cloud and offsite copies. If paying still looks unavoidable, get legal advice on sanctions first. Paying is no guarantee: in Cybereason's 2024 study, fewer than half of payers got their data back uncorrupted.

Is it illegal to pay a ransomware ransom in the EU?

There is no general EU-wide ban on paying, but a payment to a sanctioned person or group can be unlawful, and you rarely know who controls the wallet. Paying also doesn't change your duties: NIS2 Article 23 requires reports within 24 hours, 72 hours and one month, and GDPR Article 33 requires breach notification within 72 hours. Always take legal advice.

Do you get your data back if you pay the ransom?

Sometimes, but often not completely. Cybereason's 2024 study found that 47% of organisations that paid got their data and services back uncorrupted. Decryption tools from attackers can be slow and buggy, and stolen data remains in criminal hands either way. The No More Ransom project advises not to pay, because there's no guarantee you'll receive a working key.

Will we be attacked again if we pay?

There's a high risk. In Cybereason's 2024 study, 78% of organisations that paid were hit by a second ransomware attack. Paying shows you are willing to pay, and if the original entry point isn't found and closed, attackers can come back the same way. Fix the root cause and reset credentials before you reconnect restored systems.

Who should I contact after a ransomware attack in the Netherlands?

Call your IT partner or helpdesk first, then report to the police; businesses can call 0900-8844 to make an appointment. If you fall under the Cyberbeveiligingswet, report the incident to your CSIRT and supervisor within 24 hours. If personal data is affected, notify the Autoriteit Persoonsgegevens within 72 hours. Check nomoreransom.org for a free decryptor.

Sources

  1. RansomwareFBI Internet Crime Complaint Center (IC3), 2026 (accessed)
  2. Wat te doen bij een ransomware-aanval?Nationaal Cyber Security Centrum (NCSC), 2026 (accessed)
  3. Incidentresponsplan RansomwareNationaal Cyber Security Centrum (NCSC), 2022
  4. Guidance for organisations considering payment in ransomware incidentsNCSC UK, ABI, BIBA and IUA, 2024
  5. No More RansomNo More Ransom (Europol, Dutch National Police and partners), 2026 (accessed)
  6. 78% of organizations suffer repeat ransomware attacks after paying (Cybereason Ransomware: The True Cost to Business 2024)Infosecurity Magazine, 2024
  7. The State of Ransomware 2025Sophos, 2025
  8. State of Ransomware 2026Sophos, 2026
  9. The impact of compromised backups on ransomware outcomesSophos, 2024
  10. Lessons for organizations from the Verizon 2026 Data Breach Investigations ReportHelp Net Security, 2026
  11. UK to ban ransomware payments by public sector organizationsThe Register, 2025
  12. Responding to ransomware attacksMicrosoft Learn, 2026 (accessed)
  13. Directive (EU) 2022/2555 (NIS2 Directive)EUR-Lex, Publications Office of the European Union, 2022
  14. Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex, Publications Office of the European Union, 2016
Part ofDisaster Recovery