Ransomware

Ransomware Part 3: To pay or not to pay — the impossible question nobody wants to face

When every system in your hospital is encrypted, should you pay the ransom? There is no easy answer — but there is a right time to think about it.

Robert Shone 4 min read
Ransomware Part 3: To pay or not to pay — the impossible question nobody wants to face

Imagine you are the chief executive of an NHS trust. It is six in the morning. Your head of IT is on the phone telling you that every system in the hospital is encrypted. Patient records are inaccessible. Theatre scheduling has gone. The pharmacy system is down. The demand is for £2 million in Bitcoin, payable within forty-eight hours.

Nobody trains for this conversation in medical school.

The question of whether to pay a ransomware demand is one of the most difficult decisions any organisation can face — not because the answer is genuinely unclear in principle, but because the consequences of the wrong choice in practice are immediate and serious in ways that principles cannot fully account for.


The argument against paying

The official position of the UK government, the NCSC, the FBI, Europol, and virtually every law enforcement agency in the world is clear: do not pay.

The reasoning is sound. Paying funds criminal operations — the payment you make today funds tomorrow's attack on someone else's hospital. It does not guarantee you will get your files back; some groups take the money and disappear. It does not guarantee the stolen data will not be published anyway; double extortion groups often publish regardless. And it signals to the criminal market that your organisation will pay, which tends to result in being targeted again.

The UK government went further in late 2025, introducing legislation to ban ransomware payments by public sector organisations — NHS trusts, government bodies, local councils, schools. The ban is expected to come into full force during 2026. The intent is straightforward: remove the financial incentive that makes public sector targets valuable.

Only 17% of UK organisations hit by ransomware in the past year paid the ransom — down from 27% in 2024 and 44% in 2023. UK organisations are now more than three times more likely to recover from backups than to pay. These numbers suggest the culture is shifting, and that adequate preparation is increasingly making payment unnecessary.


The reality is more complicated

Everything above is true. The other side of the ledger is also true.

When a hospital cannot access blood results and a patient is waiting for surgery, the calculus is different from the calculation made in a boardroom in advance of an attack. When eleven schools cannot provide education to thousands of children because their systems have been encrypted before an exam period, the headteacher does not have the luxury of waiting three months for systems to be rebuilt from scratch.

The reality is that some organisations pay because they have no viable alternative that does not cause immediate, serious harm to the people they serve. Synnovis did not pay. Their data was published. Other organisations have paid and recovered quickly, with limited long-term consequences. Neither outcome is universal.

This is one of the reasons the debate about the payment ban is genuinely contested. Hospitals argue that an absolute ban removes a last-resort option from organisations whose primary responsibility is patient welfare, not counter-terrorism policy. Law enforcement argues that every payment increases the incentive to attack again. Both are right. The tension between them is not resolvable through simple rules.


What happens after the decision either way

If you pay: you may receive a decryption key, and your systems may recover more quickly than if you rebuilt from scratch. Your data may or may not still be published. You have no guarantee, no receipt, and no legal recourse.

If you do not pay: you begin the process of rebuilding, which typically takes months. Every device on the compromised network has to be assessed and rebuilt. Data has to be restored from backups — if backups exist, are current, and were stored somewhere the attackers could not reach. The stolen data may be published. The organisation operates at reduced capacity throughout.

In both cases, the attack has already been successful by the time the choice is being made. The decision is not about whether to suffer — that has already happened — but about which form of suffering is most manageable.


The right time to make this decision

The single most important insight in this article is this: the right time to think about how you would respond to a ransomware attack is not when it is happening.

Every organisation — including schools, GP practices, small businesses, charities, local sports clubs that manage membership databases — should have some version of an incident response plan that answers: what do we do if we lose access to our systems? Where are our backups? Who do we call? How do we communicate with staff and members and customers when email is down? What can we do manually while systems are being recovered?

Organisations that had clear answers to these questions before an attack recovered faster, paid less often, and suffered less disruption than those that did not. The preparation is not glamorous. It involves conversations that nobody particularly wants to have because they require imagining something unpleasant. But those conversations are far less painful than the alternative.


What does this mean for me?

For individuals: the payment question is primarily an organisational one. For personal devices hit by ransomware, the answer is almost always do not pay — the amounts demanded from individuals are typically smaller, the likelihood of receiving a working decryption key is lower, and good backups are the realistic solution.

For anyone in an organisation: ask whether your organisation has an incident response plan. Ask where the backups are and when they were last tested. These are reasonable, responsible questions.

For parents and patients: understanding that the payment question exists — and that it is genuinely difficult — helps make sense of why ransomware incidents sometimes take so long to resolve, and why public sector organisations are not simply careless when they get hit.

Next Friday: backups, resilience, and why the best time to prepare for ransomware is before it arrives.


🧠 The Human Factor

Technology involved Ransomware decryption mechanisms, cryptocurrency payment infrastructure, and the negotiation processes that increasingly professional criminal groups manage
Root cause The payment dilemma exists because ransomware attacks are designed to create a choice between two forms of harm — paying funds crime; not paying prolongs suffering. The only way out of the dilemma is preparation that makes payment unnecessary
What was at risk In organisations that pay: direct funding of further criminal activity and no guarantee of recovery. In organisations that do not: extended disruption and potential data publication
Prevention Incident response planning before an attack; tested offline backups; cyber insurance that covers ransomware incidents and includes incident response support

References and sources

  • UK government ransomware payment ban for public sector — announced late 2025
  • Sophos: State of Ransomware 2025 — payment rate statistics
  • UK ransomware payment trends 2023–2025 — cybersecstats.com
  • NCSC: Ransomware guidance, including payment advice — ncsc.gov.uk
  • Synnovis decision not to pay — The Register, November 2025