FC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 QFC Health Index1,428.60+0.42%Novo NordiskDKK 812.4+1.10%Intuitive SurgicalUSD 546.9−0.30%EU AI Act — Art. 6in forceM+7FDA 510(k) AI clearances (YTD)312+18 w/wNHS AI Diagnostic Fund£123mcommittedKarolinska trials open48+2Reimbursement CPT codes (AI)17+1 Q
Thursday, 17 September 2026 · Oslo · London · New York

Cybersecurity · Long-form Report

What actually happens in the room when a company decides whether to pay.

Incident responders describe a decision process that has almost nothing to do with the ransom note and almost everything to do with backup restore times.

An empty meeting room with a single chair and window light
An empty meeting room with a single chair and window light

Independent coverage

A

By AJ Dellinger

Contributing Writer — Cybersecurity / Tech Policy · Freelance

Edited by Nathaniel "Nate" Whitaker

Published 14 September 2026

8 min read

Evidence: Reporting

Responders who sit in these rooms describe a consistent sequence. The note arrives, the executive team convenes, and within an hour the discussion stops being about the criminals and becomes a discussion about the organisation's own recovery estimates.

If the restore estimate is two days and credible, nobody pays. If it is three weeks and nobody trusts it, the conversation changes immediately.

The estimate is usually wrong

The single most common finding in post-incident reviews is that the documented recovery time objective had never been tested at full scale. Partial restores had been tested. The dependency order between systems had not.

That is why the decision so often turns on fear rather than data. Nobody in the room can say with confidence how long the business will be down.

What changes the outcome

Three things, all boring, all cheap relative to a ransom. An offline copy that is genuinely offline. A restore rehearsal conducted at least annually with the actual dependency order. And a written, pre-agreed decision framework so the question is settled before the day it matters.

The regulatory layer

Reporting obligations now compress the timeline further in both the United States and the European Union. An organisation that has not rehearsed its notification path is rehearsing it during the worst week of its year.

"The number on the note is not the negotiation. The negotiation is against your own restore clock."

Sources

Published 14 September 2026