It is a Monday morning. The files no longer open, a message displays an amount and a countdown. Someone then asks the question no one wanted to hear: do we pay?

This article will not give you a ready-made answer, because none exists. It gives you what you need to avoid deciding badly: what payment actually buys, what it does not buy, and why this question is settled well before a ransom screen appears.

What do Swiss authorities recommend, and why?

The National Cyber Security Centre (NCSC) advises against paying. Most European authorities hold the same position. This recommendation rests on three concrete reasons, which are worth understanding rather than simply accepting as a principle.

Payment finances criminal activity. Ransomware groups are organisations with salaries, purchased tools and subcontractors. Every ransom paid directly finances the next attacks, including against companies comparable to yours. This is a collective argument, one that carries little weight for a business at a standstill, but it is real.

Payment marks you as a payer. Groups exchange, resell and document their targets. A company that has paid is a company known to pay, to have the funds, and to have a low tolerance for disruption. This status circulates, and it attracts attention.

Payment buys no guarantee. This is the most important point, and the one the next section details.

What does payment actually guarantee?

Nothing about a ransom is contractual. You transfer funds to a criminal organisation in exchange for a promise, with no recourse if it is not kept.

Paying is not restoring

Even when the decryption key works, you recover files, not a healthy information system. The attacker's access, the accounts created and the backdoors installed remain in place until they have been actively sought out and removed. Paying does not exempt you from any of the rebuilding steps.

Three gaps consistently appear between what people think they are buying and what they actually get.

The key can be faulty or very slow. The decryption tools provided by attackers are often of poor quality. They sometimes fail on certain file types, corrupt databases, or run so slowly that fully decrypting a server takes several days. A company that hoped to restart the next day ends up at a standstill for just as long as with a proper restoration.

The deletion of stolen data cannot be verified. No technical proof can establish that a copy no longer exists elsewhere.

Nothing prevents a second attack. If the original flaw is not fixed, it remains open, for the same group or for another one. A company that pays without properly rebuilding its system remains exactly as vulnerable as before, minus the cash it paid out.

These three gaps have one thing in common. They do not depend on your negotiating skill or on the amount paid. They stem from the very nature of the exchange: you are not signing a contract, you are hoping that a criminal organisation keeps its word.

Double extortion changes the calculation

Modern ransomware no longer just encrypts. It starts by copying the data out, then encrypts. The attacker then holds two levers: preventing you from working, and threatening to publish what they took.

This development has a direct consequence for business owners. A well-backed-up company can restore its systems and refuse to pay for decryption, and still receive a second demand, this time for silence.

Paying for silence is the worst kind of payment

Paying for a key produces at least one observable result: the files open, or they do not. Paying for a deletion produces nothing observable. You hand over a sum and keep hoping, with no way to ever verify it, and you have signalled along the way that the threat works on you.

This is also why the question of data theft must be handled independently from that of restoration. The topic is covered in our article on data theft.

Why do some managers pay anyway?

An article that ignored this reality would not be honest. Companies do pay, including well-advised ones, and their reasons are neither irrational nor contemptible.

Operations come to a complete halt. Employees arrive in the morning unable to work, while still being paid. Orders do not go out, invoices do not get issued, production stops. Customers, for their part, do not wait indefinitely: after a few days, some go elsewhere, and do not come back.

On top of this comes time pressure. The manager must decide within hours, with incomplete information, often without yet knowing which data was taken or how long a restoration would take.

Acknowledging this pressure is not the same as encouraging payment. It is understanding why the only effective protection is to never end up in this position in the first place.

The questions to settle before deciding

If the question does come up regardless, it is not answered with a yes or a no. It is answered by first establishing the facts.

QuestionWhy it is decisive
Are our backups intact and usable?A backup connected to the network was probably encrypted along with everything else
How long would restoration take?Three days of downtime and three weeks do not lead to the same decision
What data was stolen?Determines the real risk of publication and the reporting obligations
What does our insurance policy say?Some policies exclude payment, others require their prior approval
What legal obligations apply?Breach reporting and informing the people concerned are independent of payment

On the legal side, stay cautious. A payment can raise questions depending on the identity and location of the recipient of the funds, particularly regarding international sanctions. These questions are not improvised: they are examined with legal counsel, and that review is documented. Your reporting obligations, meanwhile, are detailed in our article on reporting a data breach.

A collective, documented decision, never improvised

Three principles hold regardless of the final choice.

The decision belongs to management. Never to the IT manager alone, never to the person who discovers the screen. The person handling the technical crisis is not the one committing the company.

The insurer and legal counsel are consulted before, not after. A payment made without notifying the insurer can void the coverage. The clauses that govern this point, along with the most frequent exclusions, are detailed in our article on what cyber insurance really covers.

Everything is documented. Who decided, when, based on what information, with what advice. This record will serve you with your insurer, with the authorities and, where applicable, with your own business partners.

The only decision that is truly yours

A company able to restore its data within a few days does not face this dilemma: it refuses, it restarts, and it deals with the theft question afterwards. This capability is built today, not on the morning of the attack, and it is confirmed by testing a full restoration at least once a year. This is all explained in our article on backups and the 3-2-1 rule.

Preparing rather than having to choose

Ransomware remains a constant threat in Switzerland: 57 ransomware-related incidents were reported to the NCSC in the second half of 2025, and these figures only count the cases that were reported.

The practical conclusion is short. The question “should we pay?” is the symptom of insufficient preparation, never a problem you solve on the spot. The companies that never had to ask it are the ones with disconnected, tested backups and a written plan describing who does what. For the immediate steps to follow, see the first hours after an attack, and to understand how these attacks work, our article on ransomware.

These benchmarks are a foundation, they do not replace an analysis of your own situation. Knowing how long your company would actually take to restart, and what data an attacker could take, requires looking at your specific infrastructure. This is a modest effort compared to the stakes: the amount at issue on the day of an attack, added to the days of downtime, far exceeds the cost of preparing calmly in advance. The cyber check-up offers an initial assessment, and the attack cost simulator lets you put a figure on what a shutdown would mean in your case. The other emergency reflexes are grouped in the Responding to an attack pillar.