The fundamental question: Negotiate or pay?
The decision on how to handle ransom demands should not be viewed as a simple yes/no question. Instead, a strategic approach is required that weighs various options and their consequences:
- Negotiation without intent to payCan buy time for technical solutions
- Negotiation with possible paymentIn life-threatening or unalternative situations
- Direct rejection: If adequate backup systems and emergency plans are in place
When is negotiation useful?
Negotiating with the attackers can offer several strategic benefits, even without any intention of making a payment:
- Time savingsEnables the activation of emergency plans and the restoration of backups
- Information gatheringProvides insights into attack methods and the extent of the affected data
- Damage controlCan reduce the immediate impact of the attack
- Negotiation marginAllows the reduction of potential claims
Professional support is essential for this..
The structured decision-making process
Phase 1: Orientation
- Convening of the crisis management team
- Analysis of the affected critical data
- Assessment of recovery options
- Business Impact Assessment
Phase 2: Prioritization
- Determination of technical requirements
- Coordination with management and the executive board
- Definition of negotiation objectives
- Assessment of the prospects of success
Phase 3: Implementation
- Involvement of negotiation experts
- Coordination with technical teams
- Legal protection of all steps
- Continuous reassessment of the situation
Legal frameworks in Austria
The legal situation regarding hacker attacks and ransom payments is complex and requires special attention:
- Criminal lawIs the payment of ransom a punishable offense?
- Insurance lawWhen does the cyber insurance provide coverage?
- Managing Director Liability: Do the corporate bodies of the company have liability?
- Data Privacy & Compliance: Are there reporting obligations to authorities?
Preventive measures
To protect themselves as best as possible against ransomware attacks, companies should timely take precautionary measures for an emergency:
- Implement robust backup strategies and test them regularly
- Develop and practice incident response plans
- Train employees regularly
- Keep IT security systems up to date
- Organize professional support in advance
Conclusion
The decision on how to handle ransom demands must be well-considered and take various factors into account. A structured decision-making process, legal safeguards, and professional support are essential in this regard. Preventive measures and rapid and competent action in an emergency are the pillars of a successful ransomware defense strategy.
For further information and individual consultation, please feel free to contact us Roman Taudes (taudes@atb.law) and his team are available at any time.