Ransomware
Extortion Demand: Who Decides, and by What Criteria?
When ransomware hits, the payment decision formally belongs to management, not IT, but it hinges on sanctions checks, insurance terms, and forensic findings a crisis team prepares. Here is who decides, what criteria matter, and why a payment can itself be illegal.
By KaitoSec Team · Published 5 September 2026 · 17 min read
The decision on a ransom payment formally rests with management or the executive board, personally liable under Section 43 of the German Limited Liability Companies Act (§ 43 GmbHG) and Section 93 of the German Stock Corporation Act (§ 93 AktG). It is prepared by a crisis team that checks sanctions law before every payment, since paying a listed actor can itself be unlawful. According to Bitkom Research, 15 percent of German companies hit by ransomware have already paid, usually without having defined this process in advance.
Who Decides on an Extortion Demand When It Actually Happens?
Formally, the decision lies with management or the executive board, since they bear the duty of care for business decisions under § 43 GmbHG and § 93 AktG. It is prepared by an interdisciplinary crisis team of IT, legal, privacy, and communications, not a single person acting on impulse.
In practice, this situation rarely hits large corporations with well-rehearsed crisis management. Municipal utilities, local governments, and KRITIS operators (Germany's critical-infrastructure sector) have built CISO functions in response to NIS2, the IT Security Act 2.0, or DORA, but rarely a tested crisis team. A security incident with extortion characteristics therefore often catches these organizations unprepared, even though responsibility is clearly defined by law. How often this arises is shown by a Bitkom survey: 34 percent of German companies suffered ransomware damage in the past twelve months.
The duty of care owed by management and executive boards is not negotiable. § 43 GmbHG requires managing directors to exercise the care of a prudent businessperson and makes them personally liable for breaches of duty. § 93 AktG sets out the same duty for the executive board and, in paragraph 1, sentence 2, adds the so-called Business Judgment Rule: "There is no breach of duty if the board member could reasonably assume, when making a business decision, that they were acting on the basis of adequate information for the benefit of the company."
In hindsight, what matters most is the path to the decision, not its outcome. Document which information was available at the time, which options were examined, and who recommended them. Without this documentation, a later breach of duty weighs more heavily, similar to NIS2 fines and penalties: there too, provable action determines the severity of the consequences.
The crisis team is part of the incident response process, not a substitute for decision-making authority. It gathers facts, evaluates options, and issues a recommendation. The team typically includes:
- IT leadership or the CISO, for the technical findings
- Legal, for liability and contract questions
- The data protection officer, for reporting obligations
- Communications, for internal and external messaging
- External forensics, if the attack vector is unclear
- Specialized ransomware negotiation service providers, if a negotiation is being considered at all
This role often goes unfilled until mid-incident. Name it in advance.
Who Is Personally Liable if the Decision Was Wrong?
Managing directors are personally liable with their private assets under § 43(2) GmbHG, and executive board members under § 93(2) AktG, if they breached their duty of care. The Business Judgment Rule acts as a shield here: anyone who decided on an adequate information basis and in good faith for the company's benefit is not automatically liable for a poor outcome. But that protection only applies if the decision-making process is documented. Without a recorded log of the crisis team meetings, all that remains is the claim of having acted with care.
What Role Does the Crisis Team Play Relative to Management?
The crisis team provides the basis, not the signature. It compiles the forensic findings, assesses legal risks including sanctions law, and formulates a recommendation. This separation prevents a specialist department from deciding on something management ultimately bears liability for. The same pattern showed up in the 2026 cyberattack on the Berlin state network: the crisis team prepared, and the political level decided.
Must the Supervisory Board or Shareholders Be Involved?
Yes, regardless of legal form. Inform the supervisory board or shareholders promptly about the situation, the options examined, and the decision made. This is part of the duty of care and guards against the accusation of acting alone, without oversight. A shareholder resolution approving payment does not, however, relieve management of liability under § 43(2) GmbHG, since the power of representation rests with them. Involving these bodies protects against reputational damage, not automatically against personal liability.
By What Criteria Is the Pay-or-Don't-Pay Decision Made?
Regardless of the legal situation, the BSI and Bitkom generally advise against payment, since it finances future attacks and guarantees nothing about data release. Even so, operational viability, cyber insurance, and forensic findings all feed into the criteria before a recommendation reaches management.
Before every decision, review at least these factors:
- Availability of tested backups: if everything can be cleanly restored, the most important pressure factor for paying disappears.
- Criticality of the affected processes: an encrypted archive system carries a different weight than a failed production control system or a central ERP system.
- Time pressure from business interruption: the longer the downtime, the greater the economic temptation to take the faster route.
- Cyber insurance conditions: many policies contractually require the insurer to be involved before any payment, sometimes with its own negotiation service provider.
- Forensic findings: only the technical analysis shows which group is behind the attack, which data has actually been exfiltrated, and how robust the encryption really is.
How these factors play out in practice is shown by a 2025 Bitkom Research survey: among affected German companies, 15 percent paid a ransom, 70 percent did not, and 15 percent gave no answer. Among those who paid, the amount was between 10,000 and 100,000 euros for 19 percent, and between 100,000 and 500,000 euros for 34 percent (Bitkom Research 2025, slide 15).
Legally, a payment moves in a grey zone. There is no blanket ban on payment in Germany, but a payment can touch on criminal offenses: if money demonstrably flows to a criminal organization, liability under Section 129 of the German Criminal Code (§ 129 StGB) can come into play, and under § 261 StGB (money laundering) if the funds are used further. This assessment is not legal advice for any individual case; it merely shows why the decision needs legal review.
This exact mix of economic trade-offs, insurance law, and criminal risk is precisely why the decision cannot rest with IT: anyone who only knows the technical recoverability sees neither the liability questions nor the terms of the policy.
What Role Does the BSI and Bitkom Recommendation Play?
The official position of the BSI, BKA, Europol, and ENISA is unanimous: do not pay, involve the police, and restore systems from backups. Felix Kuhlenkamp, a Bitkom security-policy officer, summed up the reasoning, speaking in German: "Anyone who falls victim to ransomware should under no circumstances pay a ransom. First, doing so finances the perpetrators' next attacks, usually carried out by organized crime. Second, the malware is often so poorly written that the attackers cannot even fully reverse the encryption." (Bitkom, September 4, 2024, translated from the German original) This recommendation is the starting point for weighing the criteria, not an automatic veto: it feeds in as a strong argument against payment, without replacing the other factors.
How Do Cyber Insurance and Forensic Findings Feed Into the Criteria?
Cyber insurance is rarely a blank check. Many policies tie cost coverage to conditions: approval before every payment, exclusion of certain payment channels in case of a sanctions violation, or an obligation to bring in a service provider named by the insurer. Clarify the policy before an incident happens, not while it is underway.
The forensic findings provide the factual basis in parallel: which attacker group is likely behind it, how reliably the ransomware can be decrypted, and which data has demonstrably been exfiltrated. Without these findings, every decision remains a guess.
When Is a Payment Considered Anyway?
Legal scholars discuss whether a payment could, under certain circumstances, be justified under § 34 StGB (necessity as a legal justification), for instance when life, limb, or a critical supply, not just operations, are directly at risk. This question is not conclusively settled and is no blanket instruction: for most cases of pure business interruption, the trade-off between economic damage and legal risk remains. That is precisely why, in the end, management must decide, grounded in law, forensics, and insurance, not a single specialist view.
Why Can a Payment Itself Be Unlawful?
If the recipient of a ransom payment is listed on an EU sanctions list, for instance under Regulation (EU) 2019/796 on cyberattacks, the payment is unlawful regardless of how the extortion plays out. Since February 2026, there is no grace period for this: new listings take effect immediately, and fines for companies have risen sharply.
This danger is not theoretical. Several active ransomware groups, and actors connected to them, are already on sanctions lists, which are continuously expanded. A definitive list would therefore be misleading; what always matters is a case-by-case check against the lists current at the time of payment.
The legal situation has been tightened further since early 2026. The Act Amending Criminal Offenses and Sanctions for Violations of Restrictive Measures of the European Union was promulgated in the Federal Law Gazette (Bundesgesetzblatt) on February 5, 2026, took effect the next day, and implements Directive (EU) 2024/1226. § 19(7) of the Foreign Trade and Payments Act (AWG) raises the fine ceiling for intentional violations by companies to 40 million euros, four times the previous 10 million. § 18(11) AWG was rewritten and, apart from humanitarian exceptions, no longer provides any grace period after new sanctions listings are announced. For the decision-making process, that means: The sanctions check cannot wait until the ransom negotiation is underway, because there is simply no time left allotted for it.
What Does the EU Sanctions Regulation on Cyberattacks Cover?
Regulation (EU) 2019/796, known as the Cyber Diplomacy Toolbox, lets the Council of the European Union freeze the funds and economic resources of persons, organizations, and entities responsible for, or supporting, cyberattacks against the EU or its member states. Article 3 lists these actors, along with connected persons, in Annex I. Central to the payment question is Article 3(2): it prohibits making funds or economic resources available, directly or indirectly, to listed persons or organizations.
Articles 4 to 7 set out exceptions:
- Basic needs of listed natural persons
- Legal and administrative costs
- Court-ordered payments
None applies to a ransom payment made to a ransomware group.
Who Checks Whether an Actor Is Sanctioned in Germany?
In Germany, the Federal Office for Economic Affairs and Export Control (BAFA) oversees goods- and technology-related embargoes; the Deutsche Bundesbank handles financial sanctions. Three screening tools matter most:
- The EU Consolidated Financial Sanctions List
- The Federal Financial Sanctions List
- The EU Sanctions Map
One special feature concerns indirect payment channels: under common EU sanctions practice, the payment ban also covers an unlisted recipient if a listed person holds a 50 percent or greater stake in them. Indirect payments through intermediaries or negotiators therefore offer no protection.
How Can This Check Be Prepared Before a Crisis?
This check belongs in preparation, not the acute negotiation phase. Decide now which unit will handle it in an emergency, typically legal or an outside law firm experienced in sanctions law, and build the relevant screening tools into your incident response plan as a fixed component. Anyone who only clarifies this once the ransom demand is on the table loses time the new deadlines no longer allow for. With the grace period gone, there is no room left for a retrospective check anyway: a listing takes effect from the moment of publication, not after some transition period.
Who Speaks Publicly Once an Extortion Attempt Becomes Known?
Communication responsibility belongs in the crisis plan, not in an ad hoc decision on the day the incident becomes public, because contradictory statements are hard to correct afterward. In the 2026 cyberattack on the Berlin state network, a crisis team under the State Information Security Commissioner pulled together the facts, while the Governing Mayor took the public position.
This separation follows a general principle: factual communication (to authorities, internally, to the crisis team) and public positioning (management or leadership) run on different channels with different responsibilities. The pressure behind this is real: per the 2025 BSI situation report, 72 percent of the 950 recorded ransomware cases involved an additional data leak, that is, a threat to publish stolen data. Anyone taking a public position is therefore often doing so under time pressure and with incomplete knowledge.
Who Should Be Designated as Spokesperson in Advance?
Decide who will speak publicly in an emergency before the emergency happens. One person or function, typically management or the head of communications, represents the company publicly; the crisis team supplies only the verified factual basis and does not itself speak to press or public. That way, substantive responsibility stays where the facts converge, and communicative responsibility stays where decisions get made. This separation prevents several people from giving information in parallel with different levels of knowledge.
Also define a deputy in case the designated spokesperson is unavailable during the incident itself.
What Does the Berlin State Network Case Show About Coordinated Communication?
This separation of roles is clearly visible in the 2026 cyberattack on the Berlin state network: a crisis team under the State Information Security Commissioner coordinated the technical and operational response, while Governing Mayor Kai Wegner publicly represented the political stance. Speaking in German, he stated that Berlin would not be extorted. Technical coordination and public positioning thus ran through two separate but coordinated roles, complemented by the early involvement of the LKA, the public prosecutor's office, and the BSI.
Which Statements Should Be Agreed Before an Incident?
Certain positions can be defined in advance rather than negotiated anew during an incident:
- Fundamental stance on paying a ransom demand
- Handling press inquiries about affected individuals or customers
- Handling questions about the state of the investigation, as long as it is not yet public
Formulate these guidelines carefully, since early statements about an ongoing incident often change as the investigation progresses. A statement made too early and too specifically ties you to a state of knowledge that may turn out to be provisional. Put these guidelines in writing and have them reviewed by legal or privacy before an incident occurs.
What Must Be Prepared Before an Incident for the Article 34 GDPR Deadline?
Article 34 of the GDPR requires prompt notification of affected individuals once a personal data breach poses a high risk to their rights and freedoms, independent of the 72-hour deadline under Article 33 for notifying the supervisory authority. Anyone who only develops risk criteria, contact channels, and message templates once an incident is underway loses exactly the days this deadline does not allow for.
How Does Article 34 Differ From the Notification Under Article 33 GDPR?
The two obligations address different recipients and are triggered by different thresholds. Article 33 GDPR requires the controller to notify the competent supervisory authority of every personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of those concerned. If this deadline is exceeded, a reason for the delay must be given.
Article 34 GDPR, by contrast, concerns the affected individuals themselves and applies only when the breach is likely to result in a high risk to their rights and freedoms. Article 34 has no fixed hourly deadline, but it does carry the same standard as Article 33: without undue delay.
When Does a "High Risk" Exist That Triggers the Deadline?
Whether a high risk exists is measured against general criteria: the type of data affected, the reversibility of possible consequences, the number of people affected, and the likelihood that harm will actually occur. The controller is exempt from the notification obligation, among other cases, when:
- The data was protected by effective technical measures such as encryption
- The high risk has already been eliminated by subsequent measures
- Individual notification would involve disproportionate effort (in which case a public announcement replaces individual notification)
Anyone notified too late, or not at all, is not left without legal protection: affected individuals can demand information about the processing of their data under Article 15 GDPR and, where damage is provable, claim compensation under Article 82 GDPR.
What Groundwork Shortens Response Time in an Emergency?
In 2025 alone, 461 data leaks involving data from German institutions and consumers became known, per the BSI situation report, including dates of birth, postal and email addresses, health and financial data, and passwords. At this scale, groundwork done before an incident determines whether the initial assessment takes hours or days.
- Define a risk assessment matrix in advance that specifies at which data category and number of affected individuals a high risk within the meaning of Article 34 should be assumed.
- Keep an up-to-date contact database of affected individuals ready, rather than compiling it only during the incident.
- Draft notification message templates in advance that only need to be adapted to the specific case in an emergency.
- Assign clear responsibility, typically to the data protection officer, for the initial assessment of whether the high-risk threshold has been reached.
These procedures can be trained in a tabletop exercise that plays through the decision paths before an incident occurs, instead of inventing them on the fly. We've described the exact deadline cascade under NIS2 and GDPR in detail in our article on NIS2 reporting obligations.
Frequently Asked Questions About Extortion Demands After Cyberattacks
Is Paying a Ransom Generally a Criminal Offense in Germany?
No, there is no blanket criminal provision against the payment itself; being extorted is not illegal per se. Risks arise case by case through § 129 StGB (supporting a criminal organization), through money laundering offenses, and above all through sanctions law if the recipient is listed.
Who Must Document the Decision on a Payment?
Management or the executive board: only a documented, informed decision is protected by the Business Judgment Rule under § 93 AktG or the standard of care under § 43 GmbHG. Without documentation, proof of adequate care is missing in a dispute, and it must be created before the decision, not reconstructed afterward.
What Happens if It Only Becomes Apparent After Payment That the Recipient Was Sanctioned?
Sanctions law applies regardless of fault, and strictly; an oversight does not protect against the consequences. Since February 2026, the former 48-hour grace period after new listings has also been dropped; the AWG now provides only humanitarian exceptions. The check must therefore happen before payment, via BAFA's embargo responsibility and the Federal Financial Sanctions List.
Must Cyber Insurance Be Involved Before a Payment?
Almost always, yes: many policies contractually require approval, or at least coordination with the insurer, and expressly exclude payments made in violation of sanctions. Review the insurance terms early, as a fixed step in the decision process, not only after the payment has already gone out.
How Does a GRC Platform Support Preparation for This Decision?
A platform like KaitoSec maps crisis team playbooks, sanctions-check steps, and reporting deadlines as traceable, documented processes, maintaining evidence for the Business Judgment Rule along the way. The payment decision itself always remains a human decision by management; you can walk through this with your own example in a demo.
- Ransomware
- Incident Response
- GDPR
- Sanctions Law
- Crisis Management
More articles
- What does ISO 27001 certification cost for a mid-sized company?
- Cyberattack on a small power plant in the United Kingdom: four days of downtime below the reporting threshold
- KRITIS-Dachgesetz and NIS2: What Applies to Whom?
- The cyberattack on Berlin's state network: seven days undetected, five days of data outflow