Crisis / Ransomware Response
When the attack is live, negotiating alone isn't enough.
I read the technical evidence and the other side at the same time. Attack path, capability, behaviour and negotiation form a single operational picture.
I align the owner, technical team and negotiation around the same set of facts.
Situation
In a crisis, the outcome depends on how quickly you understand who you're up against.
A ransomware attack combines technology, psychology and time pressure. Whoever sees only part of that negotiates and decides on an incomplete picture.
- 01
Read the attack. Logs, entry path, tooling, persistence and the quality of the attack show what the other side can actually do.
- 02
Classify the other side. Professional operators, Ransomware-as-a-Service affiliates, and opportunistic attackers behave differently. That changes the strategy.
- 03
Bring it all together. Technical situation, negotiation, recovery and business decision must all rest on the same facts.
Why me
I don't negotiate separately from the technical evidence. I negotiate from it.
My perspective is that of an attacker and penetration tester. That's why, in logs, tools and mistakes, I see not just technical traces, but clues to the other side's experience, working style and likely next steps.
The technical assessment determines how I negotiate: which signals I send, where I create uncertainty, and how I learn more about the other side from every reaction.
If you understand the attack, you negotiate with a very different picture of your opponent.
Process
Technology, negotiation and recovery aligned.
In a real crisis, I work directly with the owner or executive leadership and run technology, negotiation and recovery in parallel. Short lines of communication, one shared picture, clear decisions.
- 01
Classify the attack.
Quickly condense technical traces, entry path and the other side's behaviour into a reliable operational picture.
- 02
Set the strategy.
Jointly weigh options, time pressure, room to negotiate and technical risk.
- 03
Lead the negotiation.
Read the other side, influence it deliberately, and check every reaction against the technical situation.
- 04
Secure the recovery.
Lead the technical team, question measures, and only bring systems back online once the known attack path is closed.
Evidence
Technical analysis changes the negotiation.
Real ransomware case
In an active ransomware case, the quality of the attack and the other side's behaviour didn't add up. Technical traces pointed early to Ransomware-as-a-Service rather than a seasoned professional operator. That assessment changed the negotiation. In parallel, I worked directly with the owner and led the technical response. In the end, the settlement was well below what other victims of the same attackers had paid. I also oversaw the controlled recovery.
Paying a ransom is, in principle, never the desired solution. In this case, no usable backups remained, and the decision had to be made while the business was at a standstill.