Call NowFree Quote
Cybersecurity

Should You Pay a Ransomware Demand?

This is a decision most businesses hope they never have to make, and a genuinely difficult one under real pressure, systems down, a countdown on screen, and a business to keep running. This isn't legal advice, but here's what's actually worth understanding before an incident, not during one.

What the ACSC Actually Recommends

The Australian Cyber Security Centre's consistent guidance is not to pay. The reasoning: payment funds further criminal activity, there's no guarantee data is actually returned or deleted as promised, and payment doesn't undo the fact a breach happened, notification obligations under the Notifiable Data Breaches scheme can still apply regardless of whether a ransom was paid.

Why Businesses Still Consider It Anyway

In practice, some businesses weigh the cost of extended downtime, and the absence of a working backup, against the ransom demand and decide payment looks like the faster path back to operating. This is almost always a symptom of not having invested in tested backups beforehand, by the time a ransom note appears, the options left are genuinely worse than the ones available a month earlier.

The Real Risks of Paying

  • No guarantee of a working decryption key - some victims pay and still don't fully recover their data.
  • No guarantee stolen data isn't kept or sold anyway - a decryption key doesn't undo data theft that may have already occurred.
  • Marking your business as a payer - businesses known to pay are more likely to be targeted again.
  • Possible legal complexity - sanctions and legal considerations around paying certain groups exist and are worth legal advice at the time, not assumptions made in advance.

The Decision That Actually Matters Happens Before an Incident

The real leverage point isn't the payment decision itself, it's whether a business has a tested disaster recovery plan and immutable, offline-capable backups in place beforehand. A business that can restore from backup has a genuine choice, one that can't is making the decision under duress with far fewer real options. See our step-by-step look at what a ransomware restore actually involves for what that recovery path looks like in practice.

Frequently Asked Questions

Is paying a ransom illegal in Australia?

There's no blanket ban on ransomware payments for most Australian businesses, but the position is genuinely complex, sanctions laws can make paying certain groups illegal, and reforms in this area have been actively discussed. This is a question for a lawyer at the time of an actual incident, not something to assume the answer to in advance.

What does the ACSC actually recommend?

The Australian Cyber Security Centre's guidance is not to pay, on the basis that payment funds further criminal activity, doesn't guarantee data is returned or that copies weren't kept, and doesn't undo the fact a breach occurred, which may still trigger notification obligations regardless of payment.

Does cyber insurance cover ransom payments?

Some policies do, with conditions, but this varies significantly and coverage details matter more than most businesses realise until they need it. Understanding what your specific policy actually covers before an incident, not during one, is worth the time.

If we decide not to pay, are we definitely losing our data?

Not necessarily, this is exactly why tested, offline or immutable backups matter so much, a business with genuinely working backups can often decline to pay and still recover, which is the strongest argument for investing in backups before an incident rather than treating payment as the fallback plan.

We can make sure a payment decision is never the only option left on the table.

Cybersecurity Services →

Not confident your backups would actually let you say no?

Call 0433 087 091 for a free, no-obligation IT health check.

Book a Free IT Health Check

For related reading, see Ransomware Recovery: The Restore Process, How to Protect Your Business from Ransomware, and Cyber Insurance for Perth Businesses.

Share this article