Executives want to pay an extortion demand to prevent publication — what must the pre-decided ransom position answer?
answer
- two purchases, one word
- a decryptor is testable, a promise is not
- sanctions screening before any transfer
- insurer consent is a policy condition
- engaging is not paying
basics
~20 sIt must separate buying a decryption tool from buying a promise to delete stolen data, and settle in advance who signs, whether sanctions screening and insurer consent allow payment at all, and that engaging a negotiator is not the same as paying.
solid answer
~50 sForce the two purchases apart. A decryption tool is a technical capability with a testable outcome, and if restores are working you may not need it. A promise to delete exfiltrated data is unverifiable and unenforceable — the counterparty is the party that stole it, the same data resurfaces in later listings, and nothing you receive constitutes proof of deletion. That is the sentence the standing position exists to make before the room is under pressure. The position must also have pre-resolved the constraints: sanctions screening of the actor and payment channel, because paying a sanctioned entity can breach the law regardless of intent; insurer consent, which most policies require before any extortion payment; who signs and what the board and auditors are told; and whether a funded payment channel even exists, since standing one up takes days. Finally it should state that opening a negotiation to buy time and extract proof is a separable decision from paying.
go deeper
Know that a ransom demand covers two different things — a decryption tool and a promise to delete stolen data — and that only the first has a testable outcome.
Explain why a deletion promise cannot be verified, why clean backups solve only the encryption half, and why any payment involves sanctions and insurance constraints before it involves money.
Show how you would run recovery and the payment question in parallel, obtain proof of possession through a negotiator without committing, and keep the decision with the person who owns it.
Own the standing position in front of a board: what will never be bought and why, who signs, what must be screened and consented before any transfer, and how the organisation behaves on publication day after refusing.
## Two purchases wearing one word "Paying the ransom" hides two entirely different transactions, and a leadership team that has not separated them will make a poor decision under pressure. **Purchase one: a decryption capability.** You are buying a tool that reverses encryption you cannot otherwise reverse. This is at least testable — you can require a proof decryption of a chosen file before payment, and afterwards you find out whether the tool works, which for hypervisor-level encryption of large datastores is frequently slow and partial. If recovery from backups is viable, this purchase can be worth nothing, and the recovery track and the payment track should be run in parallel precisely so that this stays true. **Purchase two: a promise to delete data.** You are buying a statement of intent from a criminal counterparty. There is no verification, no enforcement, and no remedy. Victims who paid have subsequently been listed again by the same brand or seen the same data appear elsewhere. Nothing that can be produced — a video of a folder being deleted, a signed note — is evidence, because the marginal cost of retaining a copy is zero. And critically, the payment does not extinguish any obligation you owe to the people whose data was taken. The position should therefore state plainly what the organisation will not buy at any price, and this is the category. ## The constraints the position must have already resolved When the pressure arrives, these questions are asked in the wrong order and answered badly. Pre-resolve them. - **Legality and sanctions.** Payments to sanctioned entities can breach sanctions law even where intent is absent, so the actor and the payment channel must be screened by counsel or a specialist before any transfer. The playbook must name who performs the screening and how long it takes. - **Insurer consent.** Most policies condition extortion cover on the insurer's prior consent and the use of panel counsel and approved vendors. A payment made first and reported second may be uninsured. - **Who signs.** Not a committee. A named executive, with a named alternate for out of hours, and a documented record of the basis for the decision. - **Feasibility.** Sourcing and funding a payment channel takes days at short notice. If the organisation has not decided in advance whether it will ever be able to pay, the answer during the incident may be no by default — which is a legitimate position, but it should be a chosen one rather than a discovered one. - **What is disclosed and to whom.** Board, auditors and, where relevant, disclosure obligations. A payment is a material act, not a private operational choice. ## Engaging is not paying The most common false binary is pay-or-silence. Opening a channel through a specialist negotiator is a separable decision with its own value: it buys time, tests whether the actor will move the deadline, elicits proof of what is actually held, and yields observations about the counterparty. It is not consent to pay and must be authorised as its own step, with an explicit instruction on what may and may not be said. A playbook that treats first contact as the payment decision loses the option. ## Planning for refusal If the position is refusal — the common outcome — then the playbook has to carry the consequence, because refusal has a publication day. Decide in advance who is told and in what order when the data appears; how the affected parties are supported; that the organisation's public account will be a plain one; and that the deadline passing is not the end of the incident, because the intruder's access is a separate question from the extortion. In the scenario this playbook is written for, the disconnect held, the ransom was refused, the timer expired and the data was published anyway — and everything the organisation had to do next had been decided when nobody was watching a countdown. ## What a good answer sounds like A strong candidate does not perform a moral position. They say: we separate the decryptor from the deletion promise; we will not buy the deletion promise because it cannot be verified; whether we would ever buy a decryptor depends on whether recovery is viable and is a named executive's call under sanctions and insurer constraints; we open a negotiation channel early because it costs us little and buys information and time; and we plan for publication day regardless of the decision, because the leverage disappears only when the data is public or the actor loses interest, and neither is under our control.
- Backups are clean and recovery is on track. Does that end the payment conversation?It ends the decryptor half of it. The extortion leverage is publication, and no restore touches the copy sitting on the actor's infrastructure. Teams that equate recovery with resolution are surprised when the pressure continues after the estate is back, which is exactly when an unprepared executive is most tempted to pay for a deletion promise.
- What has to be true before any payment could actually be made?Sanctions screening of the actor and payment channel through counsel or a specialist; the insurer's consent where the policy requires it; a named executive signature with the basis recorded; legal review for the jurisdictions involved; and a funded payment channel that already exists. That is days of lead time, which is why it is pre-decided rather than arranged live.
- Why insist that opening a negotiation is authorised separately from paying?Because they have different costs and different values. Contact buys time, tests whether the deadline is movable and extracts proof of what is held, at little cost beyond disciplined messaging. Collapsing the two means teams either avoid contact and lose information, or treat first contact as commitment and lose the option to refuse cleanly.
- What does the position need to say about publication day?That refusal has a sequel: who is told, in what order, with what support for affected parties, and with an account the organisation can stand behind. It also has to say that the extortion ending is not the incident ending, since the intruder's access and persistence are a separate question from the deadline.
saying these in an interview costs you the question
- Treats paying as one decision rather than two
- Believes a deletion promise is verifiable or enforceable
- Thinks a payment removes notification obligations
- Overlooks sanctions exposure on the payment channel
- Pays before obtaining insurer consent
- Assumes clean backups end the extortion
- Treats opening a negotiation as agreeing to pay