Cybersecurity · Long-form Report
What actually happens in the room when a company decides whether to pay.
Incident responders describe a decision process that has almost nothing to do with the ransom note and almost everything to do with backup restore times.

Independent coverage
By AJ Dellinger
Contributing Writer — Cybersecurity / Tech Policy · Freelance
Edited by Nathaniel "Nate" Whitaker
Published 14 September 2026
8 min read
Evidence: Reporting
Responders who sit in these rooms describe a consistent sequence. The note arrives, the executive team convenes, and within an hour the discussion stops being about the criminals and becomes a discussion about the organisation's own recovery estimates.
If the restore estimate is two days and credible, nobody pays. If it is three weeks and nobody trusts it, the conversation changes immediately.
The estimate is usually wrong
The single most common finding in post-incident reviews is that the documented recovery time objective had never been tested at full scale. Partial restores had been tested. The dependency order between systems had not.
That is why the decision so often turns on fear rather than data. Nobody in the room can say with confidence how long the business will be down.
What changes the outcome
Three things, all boring, all cheap relative to a ransom. An offline copy that is genuinely offline. A restore rehearsal conducted at least annually with the actual dependency order. And a written, pre-agreed decision framework so the question is settled before the day it matters.
The regulatory layer
Reporting obligations now compress the timeline further in both the United States and the European Union. An organisation that has not rehearsed its notification path is rehearsing it during the worst week of its year.
"The number on the note is not the negotiation. The negotiation is against your own restore clock."
Sources