By Mackenzie Gryder
Overview
When ransomware strikes, organizations must make high-stakes decisions quickly while systems are offline, operations are disrupted, and leaders are working with incomplete information. Proper preparation can greatly improve an organization’s ability to make the right decisions on time. The more organizations can pre-establish decision-making authorities, build a network of trusted advisors, and maximize their recovery options, the faster they can lower the temperature in the high-pressure environment of crisis response. This blog will examine some of the ways organizations can set themselves up right now to make the best decisions possible during a ransomware incident.
- Establish decision-making authority before an incident. Clearly define who can make operational, restoration, communications, and ransom-related decisions.
- Build trusted relationships in advance. Know how to engage legal counsel, incident response providers, cyber insurers, cybersecurity partners, and law enforcement before a crisis.
- Maximize recovery options. Reliable, tested, and protected backups give organizations greater flexibility when responding to ransom demands.
- Capture decisions during the response. A dedicated record-keeper can document key decisions, assumptions, timelines, and challenges for later review.
- Turn lessons learned into action. Post-incident reviews can identify gaps in planning, recovery, communications, and security controls before the next incident.
- Practice before the pressure is real. Tabletop exercises help leaders test decision-making, clarify roles, and identify coordination gaps in a low-consequence environment.
Research Shows Organizations Think More Clearly Than We Assume
Recent research from the Australian Institute of Criminology (AIC) examined the decision-making process of ransomware victims. The AIC interviewed 33 individuals who experienced ransomware attacks to better understand how victims made decisions during their incidents. Rather than reacting emotionally, many of the respondents relied on trusted advisors, including internal leadership, legal counsel, cybersecurity experts, insurers, and law enforcement, to evaluate available options.
Most participants ultimately chose not to pay the ransom because they distrusted threat actors and believed payment offered no guarantee of recovering their data or preventing future harm. The decision not to pay aligns with longstanding FBI guidance, which discourages ransom payments because payment does not guarantee recovery and may increase the likelihood of future targeting. Organizations that demonstrate a willingness to pay can become more attractive targets for future attacks, reinforcing the value of investing in resilience rather than relying on negotiation.
The research also found that organizations with viable recovery options, particularly reliable backups, were significantly more confident in declining ransom demands. Those findings built on similar research from the same authors that demonstrated that confidence in backup systems simplifies decision-making because organizations know they have another path to data recovery.
Learning While Responding: Capture Decisions Before They’re Forgotten
Responding to ransomware is stressful. Teams often move rapidly from one urgent decision to the next, leaving little time to document why they made those choices. By the time operations are restored, important details about the decision-making process may already be forgotten.
Assigning a dedicated record-keeper during an incident can help capture key decisions, assumptions, timelines, and challenges without distracting responders from their primary responsibilities. These notes become invaluable during the post-incident review, allowing organizations to identify what worked, where uncertainty existed, and how decision-making can improve before the next incident.
A post-mortem should take place as soon as practical after recovery while events remain fresh. The goal is not simply to review the technical response, but to understand how leadership made decisions under pressure and how planning, communications, and recovery processes can be strengthened for the future. This process is critical because organizations that fail to address the weaknesses exposed during an incident often remain vulnerable. According to Black Kite’s latest ransomware research, 43% of ransomware victims still had at least one unpatched critical vulnerability after completing incident response, and 31% continued to have vulnerabilities that the Cybersecurity and Infrastructure Security Agency (CISA) identified as actively exploited. These findings underscore the importance of deliberately turning lessons learned into concrete improvements, rather than viewing the recovery phase as the end of the incident.
Gate 15 can support organizations beyond the initial response by facilitating post-incident reviews that examine not only what happened but also how decisions were made throughout the incident. These reviews can help organizations translate lessons learned into actionable improvements to response plans, recovery procedures, communications, and leadership decision-making.
Planning: Reducing Decision-Making Under Pressure
A ransomware attack affects more than the IT team; it touches executive leadership, legal counsel, communications, operations, human resources, finance, and external partners.
Without predefined roles, valuable time can be lost determining basic questions:
- Who has authority to make operational decisions?
- Who contacts cyber insurance providers?
- Who coordinates with outside legal counsel and forensic investigators?
- Who engages with law enforcement?
- Who communicates with employees, customers, partners, and the public?
- When should leadership brief the board?
- Which business systems must be restored first?
Answering these questions during an active incident creates unnecessary delays and increases stress. Establishing decision authority, communication pathways, and escalation procedures beforehand allows leaders to focus on the evolving situation rather than organizational logistics.
Equally important is knowing who to call before an incident occurs. Building relationships with incident response providers, cyber insurance contacts, legal counsel, cybersecurity partners, and law enforcement before a crisis eliminates uncertainty when every minute matters. These partners should be incorporated into tabletop exercises whenever possible, so notifications, escalation paths, and decision roles are practiced before a real event.
Making Recovery a Decision, not a Hope: Backups and Data Resilience
The AIC research reinforces one of the most important lessons in ransomware preparedness: organizations that can confidently recover are far less likely to feel pressured into paying a ransom. Recoverability provides leverage. The AIC research found that organizations with confidence in their backups were significantly more likely to decline ransom demands because they knew they had another path forward. Earlier research by Voce & Morgan reached a similar conclusion, finding that reliable backups reduce uncertainty and simplify decision-making during an incident. When leaders know they can restore systems and data, negotiations become an option rather than a necessity; when recovery is uncertain, attackers gain leverage.
Effective recovery begins with more than simply maintaining backups. Modern ransomware groups frequently attempt to locate, encrypt, or delete backup repositories before deploying ransomware, making offline, immutable, or otherwise protected backups an important component of resilience. Just as importantly, organizations should regularly test restoration procedures, validate recovery runbooks, and establish realistic recovery time objectives so leadership understands what recovery will look like during an incident. Recovery exercises should include executive leadership, legal counsel, communications teams, and other key stakeholders to ensure technical recovery and organizational decision-making occur in parallel rather than independently.
Recovery planning should also account for today’s ransomware tactics, where many groups combine encryption with data theft to increase pressure on victims. As a result, resilience extends beyond backups alone. Strong data governance—including classifying sensitive information, minimizing unnecessary data retention, understanding where critical data is stored, and removing outdated or redundant information—can reduce the amount of information available for extortion and limit an attacker’s leverage.
Recovery planning should also extend beyond enterprise systems. One participant in the research described developing a pre-established procedure employees could follow if a company-managed device became infected. Even when a single endpoint is affected, clear guidance on who to contact, how to isolate the device, and how replacement or restoration will occur can reduce confusion, speed response, and minimize disruption. Preparing these resources before an incident helps ensure recovery is consistent rather than improvised under pressure.
Ultimately, recovery planning should begin long before an attack occurs. Organizations that can restore operations confidently while limiting the value of stolen data during ransomware incidents have greater flexibility and control. Rather than being driven by an attacker’s timeline, leadership is better positioned to make deliberate, informed decisions based on operational priorities and risk.
These relationships and processes are most effective when they are established and practiced before an incident. Gate 15 can help organizations develop and exercise ransomware response plans, bringing key stakeholders together to clarify roles, test escalation procedures, and practice the decisions they may face during a real event.
Exercises: Turning Crisis Decisions into Practiced Decisions
Tabletop exercises give leaders a low-consequence environment to test assumptions, clarify decision rights, and identify coordination gaps before a real incident forces those choices under pressure.
Exercises transform ransomware response from an unfamiliar crisis into a practiced process.
Gate 15 supports this readiness by designing and facilitating exercises that help organizations:
- Walk through realistic ransomware scenarios.
- Identify capability and process gaps.
- Improve coordination across teams.
- Refine incident response procedures.
- Strengthen executive decision-making under pressure.
What Organizations Can Do Now
Leadership:
- Define who can make incident, restoration, communications, and ransom-related decisions before an event occurs.
- Confirm board briefing expectations, external advisor contacts, and escalation thresholds during annual tabletop exercises.
Technical Teams:
- Test backup and restoration procedures.
- Review recovery priorities.
- Validate incident response processes.
- Ensure known exploited vulnerabilities are addressed.
The Organization:
- Train employees on their role during an incident.
- Review internal and external communication plans.
- Maintain updated emergency contact lists.
- Document lessons learned following exercises and incidents.
Conclusion
Preparation cannot prevent every ransomware attack, but it can materially improve how organizations respond. By investing now in leadership planning, validated recovery, trusted advisors, and realistic tabletop exercises, organizations can reduce uncertainty, preserve leverage, and make better decisions when it matters most.
Gate 15 works across Critical Infrastructure sectors to help organizations protect their people, places, data, and dollars. The threat environment is constantly shifting, and we are here to boost your resilience with plans, exercises, threat analysis, and operational support against both emerging and enduring threats. Contact our team at Gate15@gate15.global to see how we can assist you in delivering on your mission. Join Gate 15’s Resilience and Intelligence Portal (the GRIP)! Sign up today to stay informed of what’s new in all-hazards homeland security and join us in securing America’s people, places, data, and dollars.
Gate 15: Technology-enhanced, human-driven, homeland security risk management.

Understand the Threats.
Assess the Risks.
Take Action.
