# Should Organizations Pay Ransom During a Cyber Attack? > By Johnathan Belcher — June 12, 2026 — 5 min read When an organization is hit by a cyber attack, paying the ransom might seem like the fastest way to regain access to data and reduce downtime. My view is that the answer is almost always no. A mature cybersecurity program should be built around preparation, resilience, and recovery planning so the business is not forced into a desperate decision when an attack happens. Paying ransom does not guarantee that stolen or encrypted data will be returned, and it can encourage more attacks by showing threat actors the organization is willing to pay. It may also create legal and compliance risks if the payment involves sanctioned entities or restricted groups. The Office of Foreign Assets Control (OFAC) has warned organizations about the risks of making ransomware payments to restricted threat actors, who are often connected to larger criminal or state-sponsored operations — meaning the money can fund further malicious activity. Many businesses still end up paying because they are unprepared and feel they have no better option. A lack of tested backups, incident response planning, and clear recovery procedures can turn a cyber incident into a business crisis. Organizations should invest in prevention and recovery before an attack, not after one. Building redundancy, keeping reliable offline backups, and training staff to respond quickly allows recovery without rewarding criminal behavior — a stronger long-term strategy even if it requires more upfront planning. ## Reference Lee, R. D., & Vibbert, J. (2021, October 6). [OFAC imposes sanctions on crypto exchange over ransomware payments, warns businesses on sanction risks](https://www.arnoldporter.com/en/perspectives/blogs/enforcement-edge/2021/10/ofac-imposes-sanctions-on-crypto-exchange). Enforcement Edge.