It’s a question that’s been around as long as lunch money: Do you pay the bully? Companies impacted by ransomware face this tough decision. Business leaders have to quickly understand factors like downtime and data backups, all while a deadline to pay approaches. A reader asked during an IT Brew live event in April: When an attack hits and the clock is ticking, who owns the decision to pay—IT, legal, the CEO? How does that actually get decided? We talked with legal and risk pros about who usually makes the call, and where the IT pro fits in the payment plan. In the room. When it comes to ransomware, the decision-maker can vary between organizations. Anna Rudawski, privacy and cybersecurity partner at global law firm A&O Shearman, sees the choice to pay or not pay often coming down to some combination of the CEO, CFO, and COO. What to consider before opening your wallet.—BH |