Ransomware is malware that encrypts an organisation's data and demands payment for the key. Modern operations almost always steal the data first and threaten publication, so paying to decrypt does not resolve the exposure — the breach-notification and regulatory obligations arise from the theft, not from the encryption.
Double extortion changed the legal analysis
Early ransomware was a business-continuity problem: files were encrypted, and the question was whether to pay or restore from backup. Current operations exfiltrate the data before encrypting it, then threaten to publish.
That single change moves the incident from operations to legal. If data left the environment, the organisation likely has a reportable breach regardless of whether it pays, whether it decrypts, and whether the attacker keeps their word. Notification obligations, regulatory reporting deadlines and contractual duties to customers all turn on the exfiltration — and a payment that produces a decryption key does nothing about any of them.
The practical error we see most is an organisation treating a successful restore as the end of the matter.
The forensic question that governs everything
Almost every downstream decision depends on one finding: what data actually left, and whose was it?
This is harder than it sounds and it is where the investigation earns its cost. Attackers stage data before exfiltrating it, use ordinary cloud services as the destination to blend with normal traffic, and delete logs on the way out. Establishing scope requires network telemetry, endpoint artifacts, and cloud audit records — which is why preserving logs in the first hours matters more than almost anything else the organisation does.
An investigation that cannot establish scope forces the worst-case assumption, and the worst-case assumption is expensive: notification to everyone whose data might have been involved, rather than to those whose data was.
Paying
A legal question before a commercial one. Payments to sanctioned entities carry strict-liability exposure under OFAC rules, and attribution of a ransomware group to a sanctioned actor is frequently uncertain at the moment the decision must be made. That analysis belongs with counsel and, in many cases, with a specialist firm, before any negotiation begins.
Beyond legality, decryption tools supplied by attackers are frequently slow and imperfect, restoration from them can take longer than restoring from backup, and a promise to delete stolen data is unverifiable by construction.
The first day
- Preserve before remediating. Reimaging infected systems destroys the evidence needed to establish scope. Image first where feasible.
- Preserve logs immediately. Firewall, VPN, endpoint, cloud and authentication logs have short retention and are the primary record of exfiltration.
- Engage counsel early, so the investigation proceeds under privilege where that is available.
- Notify the insurer. Most policies require prompt notice and many restrict which vendors may be engaged; retaining a firm first can jeopardise coverage.
- Do not communicate with the attacker ad hoc. Every message is discoverable and may be reviewed by a regulator.
Prevention that actually correlates with outcome
Offline, tested backups; multi-factor authentication on remote access; network segmentation limiting lateral movement; and rapid patching of internet-facing systems. None are novel. What distinguishes organisations that recover in days from those that recover in months is almost always whether the backups were genuinely offline and whether anyone had tried restoring from them before the day it mattered.
From our work
Dealing with ransomware in a live matter?
Our examiners and testifying experts work these questions for a living. Tell us what you're facing.
Reviewed by Law & Forensics. See our editorial standards.
