Cybercrime

Ransom demands in hacker attacks

When to negotiate, when to pay?

If you are currently affected by a ransomware attack, we are available to assist you at any time by phone available. We take over the coordination of an incident response team and support you in all aspects of damage management.

In today's digital business world, ransomware attacks pose one of the most severe threats to Austrian companies. In such attacks, cybercriminals encrypt mission-critical data and demand a ransom for its release or threaten to publish sensitive information.. The decision whether to negotiate or pay is complex and requires a careful evaluation of various factors.

Cybercrime

Table of Contents

The fundamental question: Negotiate or pay?

The decision on how to handle ransom demands should not be viewed as a simple yes/no question. Instead, a strategic approach is required that weighs various options and their consequences:

  • Negotiation without intent to payCan buy time for technical solutions
  • Negotiation with possible paymentIn life-threatening or unalternative situations
  • Direct rejection: If adequate backup systems and emergency plans are in place

When is negotiation useful?

Negotiating with the attackers can offer several strategic benefits, even without any intention of making a payment:

  • Time savingsEnables the activation of emergency plans and the restoration of backups
  • Information gatheringProvides insights into attack methods and the extent of the affected data
  • Damage controlCan reduce the immediate impact of the attack
  • Negotiation marginAllows the reduction of potential claims

Professional support is essential for this..

The structured decision-making process

Phase 1: Orientation

  • Convening of the crisis management team
  • Analysis of the affected critical data
  • Assessment of recovery options
  • Business Impact Assessment

Phase 2: Prioritization

  • Determination of technical requirements
  • Coordination with management and the executive board
  • Definition of negotiation objectives
  • Assessment of the prospects of success

Phase 3: Implementation

  • Involvement of negotiation experts
  • Coordination with technical teams
  • Legal protection of all steps
  • Continuous reassessment of the situation

Legal frameworks in Austria

The legal situation regarding hacker attacks and ransom payments is complex and requires special attention:

Preventive measures

To protect themselves as best as possible against ransomware attacks, companies should timely take precautionary measures for an emergency:

  • Implement robust backup strategies and test them regularly
  • Develop and practice incident response plans
  • Train employees regularly
  • Keep IT security systems up to date
  • Organize professional support in advance

Conclusion

The decision on how to handle ransom demands must be well-considered and take various factors into account. A structured decision-making process, legal safeguards, and professional support are essential in this regard. Preventive measures and rapid and competent action in an emergency are the pillars of a successful ransomware defense strategy.

For further information and individual consultation, please feel free to contact us Roman Taudes (taudes@atb.law) and his team are available at any time.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Business Email Compromise (BEC)

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes