Organizations across the globe need to develop a ransomware payment policy, anticipating a potential future attack. In previous articles, we have focused on mechanisms by which you can protect against and recover from ransomware attacks. Many clients have subsequently asked… what if we were to consider payment? Is it a viable option? What are the risks? Would we have to disclose to regulators, shareholders, or the public?