• Link to Instagram
  • Link to LinkedIn
  • Link to Facebook
  • Support
  • Resource Center
  • News & Events
  • Blog
  • Pay Online
Cumulus Global
  • What We Do
    • Managed Cloud Services Provided by Cumulus Global
    • Cloud Computing Security, Privacy, Compliance, & Continuity
    • Collaboration, Productivity, & Transformation
    • Managed Infrastructure & Platforms
  • How We Do It
    • Understand & Assess
    • Cloud Computing Strategy & Planning
    • Cloud Migration & Deployment
    • Cloud Managed Services
    • Service & Support for Cloud and IT Solutions
    • Global Strategic Services
    • Guide, Educate, & Train
  • What We Offer
    • Managed Cloud Services
    • IT Admin, Service, and Support
    • Security CPR® Managed Security
    • Google Cloud Workspace / Education / Chrome / Voice
    • Google Cloud Platform Computing Services
    • Microsoft 365 and Office 365 Managed Services
    • Microsoft Azure
  • Who We Are
    • Our Mission
    • Our Team and Opportunities
    • Our Cloud Computing Partners
    • Our Reviews and Testimonials
    • Our Community
    • Our Sustainability
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
Blog - Latest News

Responding to Ransomware: Police, Pay, or Panic?

November 28, 2022/in Cybersecurity, General

ransomware response plan
In today’s digital landscape, the threat of ransomware looms large, posing a significant risk to businesses and organizations of all sizes. Ransomware, a malicious form of cyber attack, can swiftly encrypt critical data and hold it hostage until a ransom is paid. These attacks can disrupt operations, compromise sensitive information, and inflict financial losses. In the face of this evolving threat, having a robust ransomware response plan is imperative.

At Cumulus, we understand that responding to ransomware is complicated.  With the continuing increase of successful cyber attacks against small businesses, we hear a lot of debate on two aspects of your ransomware response to a successful attack.

  • Should you contact law enforcement?
  • Should you pay the ransom?

Both of these questions have pros and cons. How and when you answer these questions can have a long-lasting impact on you and your business. Read on to learn about top ransomware response plans, how to prevent a ransomware attack, and other vital information to keep you and your business safe.

Ransomware Incident Response Strategies

Involving Law Enforcement

The debate about if and when to contact law enforcement often centers around what happens after law enforcement gets involved.  Typically, you would contact your local police department which, in turn, would contact the cyber crimes unit of your state police (if your state has one) and/or the FBI. You can also report a ransomware attack directly to the FBI or the Cybersecurity and Infrastructure Security Agency (CISA).

The biggest risks to involving law enforcement are the effects of a criminal investigation. You may not be able to repair and rebuild your systems until a forensic investigation is complete. In some cases, your computers may be considered evidence as part of a criminal investigation. By delaying your access to your computers, these actions can disrupt your ability to recover those systems.

The biggest advantages to involving law enforcement is the assistance the cyber security agencies can provide during the investigation and recovery. The FBI Cyber Division, CISA, and the National Cyber Investigative Joint Task Force can help identify the specific attack. For known variants, they often have valid decryption keys.  If involved quickly enough, the FBI and other agencies have a history of recovering at least some ransoms and thefts (e.g. the Colonial Pipeline incident).

If you have cyber insurance, you may not have a choice about reporting the attack to law enforcement.  Your carrier may require you to involve law enforcement as a condition for processing your claim. Your insurer may also mandate a forensic analysis to fully understand the scope of the attack and the necessary steps to recovery.

Paying the Ransom

Responding to ransomware, you want to move quickly and correctly. Wiping and rebuilding systems, restoring your data from backups, and recreating missing or damaged data takes time and money. Decrypting the data can be faster and easier.  Paying the ransom is tempting. Your insurance carrier may also pressure you to pay the ransom to lower the cost of the claim.

Before you pay a ransom, consider the following:

  • As noted above, law enforcement may already have decryption key;
  • It is a funding mechanism for hackers to carry out future and repeated attacks;
  • Paying a ransom does not guarantee you will receive a decryption key;
  • Even with the decryption key, you may not be able to recover all of your data;
  • Attackers will often demand additional payments to prevent the release of stolen information; and
  • Paying the ransom is likely to be a federal crime as it may be funding hostile nations, terrorism, human tracking, or child exploitation.

To the latter point, paying ransom to an organization or government on a sanctions list, including those tied to terrorist activities, violates US law (18 USC 2339A, 2339B, 2339C). In October of 2020, the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) issued a warning that “Ransomware Payments with a Sanctions Nexus Threaten U.S. National Security Interests” and could result in civil and criminal actions.

Recommended Actions For a Ransomware Response

When responding to ransomware, you will need to work with your cyber insurance carrier. Contacting law enforcement early is more likely to help your recovery than hinder it.

  • Additional expertise
  • Simultaneous investigation/forensics with your insurer
  • The possibility of known decryption keys for your ransomware variant
  • The ability to cover lost or stolen funds
  • The potential identification of the source of the attack

These benefits can mitigate the damage and help speed recovery.

Paying the ransom should always be a last resort. To avoid violating US law and facing the risk of criminal charges or civil sanctions, paying a ransom should not be done without consulting law enforcement.

For more information about cyber security and protecting your business, visit our Resource Center, or schedule an introductory call with one of our Cloud Advisors.

 

Share this entry
  • Share on Facebook
  • Share on X
  • Share on Pinterest
  • Share on LinkedIn
  • Share on Tumblr
  • Share on Vk
  • Share on Reddit
  • Share by Mail
https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png 0 0 Allen Falcon https://www.cumulusglobal.com/wp-content/uploads/2018/06/Cumulus-Global-logo-with-spacing.png Allen Falcon2022-11-28 10:00:062025-10-09 13:56:43Responding to Ransomware: Police, Pay, or Panic?

Recent Posts

  • Secure Gemini AI in Google Workspace
  • Your Path to Full Cloud Adoption
  • How We Use AI for Data Enrichment

Featured Blog Topics

  • Artificial Intelligence / AI
  • Managed Cloud Services
  • Cybersecurity

Read

  • Blog
  • Newsletter
  • Microsoft Cloud Monday
  • Google Workspace Wednesday

Watch

  • 3T@3 Series
  • Coffee and Clouds
  • Event Recordings
  • Cumulus Global Channel

Explore

  • Library
  • Events Calendar

Phone / Fax / Email

  • 866-356-1202
  • 508-948-4070
  • info@cumulusglobal.com

Headquarters / Boston

  • Street Address

    4 Bellows Rd / 2nd Floor
    Westborough, MA 01581

  • Mailing Address

    PO Box 1129
    Westborough, MA 01581-6129

Regional Offices

  • Southeast Office

    120 W Trinity Pl
    Decatur, GA 30030

Copyright © 2026 - Cumulus Global | Privacy Policy | Terms of Service | Disclaimer | Website by Cold Spring
Link to: Cumulus Global Receives Inc.’s Inaugural Power Partner Award Link to: Cumulus Global Receives Inc.’s Inaugural Power Partner Award Cumulus Global Receives Inc.’s Inaugural Power Partner Award2022 Inc. Power Partner Award Link to: Google Workspace Transition Update – 12/01/22 Link to: Google Workspace Transition Update – 12/01/22 Google Workspace Transition Update – 12/01/22
Scroll to top Scroll to top Scroll to top