The call comes in at 2 a.m. Systems are locked, a ransom note is on every desktop, and somebody on the leadership team is already searching for a phone number. That is the worst possible moment to be choosing a ransomware recovery consultant for the first time, and yet that is exactly when most organizations do it.
This article is grounded in current advisory work, not retrospective analysis. Mark Lynd is a 5x CEO/CIO/CISO with Thinkers360 Top 10 global rankings across Cybersecurity and Artificial Intelligence and was ranked #1 globally in Cybersecurity in 2023. He is currently Head of Executive Advisory and Strategy at Netsync, advising enterprise C-Suites and boards on the AI and cybersecurity questions moving fastest in 2026. The frameworks and patterns referenced here are from active engagements this quarter.
The Numbers Behind the Urgency
The financial stakes justify the panic even when the panic itself is the wrong response. IBM's 2025 Cost of a Data Breach Report put the global average cost of a breach at $4.44 million, the first year-over-year decline in five years, while the average cost for U.S. organizations rose to an all-time high of $10.22 million. Organizations are also increasingly refusing to pay. IBM found 63% of organizations refused ransom demands in 2025, up from 59% the year before.
Sophos, in its State of Ransomware 2025 report, found the average cost to recover from a ransomware attack, excluding any ransom paid, fell to $1.53 million in 2025 from $2.73 million in 2024, a 44% drop, alongside a decline in the share of organizations paying a ransom to 49% from 56%. The same report found 97% of organizations that had data encrypted were able to recover it, though reliance on clean backups hit its lowest point in six years. Coveware's quarterly ransomware data shows just how volatile payments remain even as overall averages trend down. Its second quarter 2025 report put the average ransom payment at $1,130,070, more than double the prior quarter, with a median payment of $400,000, also up 100% quarter over quarter. Coveware also found data exfiltration played a role in 74% of cases, reflecting attackers' shift toward stealing and threatening to leak data rather than only encrypting it.
Those numbers tell a story most executives have not internalized. Recovery costs and ransom demands do not move in a straight line, and the gap between what a well-prepared organization pays and what an unprepared one pays is enormous. Preparation, meaning who you have already vetted and retained before an incident, is a large part of what determines which side of that gap an organization ends up on.
The Three-Firm Trap
The single most common and costly mistake organizations make is treating "ransomware recovery" as one service performed by one type of firm. In practice it is at least three distinct disciplines, and very few firms are genuinely excellent at all three.
The first is negotiation. A small number of specialist firms handle direct communication with threat actor groups, understand the norms and behavior patterns of specific ransomware operations, and know how to verify a decryption key works before a full payment clears. This is a narrow, high-stakes skill built on pattern recognition across many prior negotiations, not something a general IT services provider should attempt for the first time during a live incident.
The second is digital forensics and incident response, often called DFIR. This is the technical work of determining how attackers got in, what they touched, whether they are still present, and how to eradicate them before restoring systems. It requires deep technical tooling and experienced analysts, and it is a different skill set entirely from negotiation.
The third, and the one organizations most often skip entirely, is executive and board-level incident governance. Someone has to translate technical findings into decisions leadership and the board can actually make, manage regulatory notification timelines, coordinate with legal counsel and the cyber insurance carrier, and communicate with customers and the public without making the legal or reputational damage worse. This role requires people who have sat on the leadership side of a crisis, not just the technical side.
Organizations that hire a single generalist vendor and expect that vendor to be excellent at all three roles are usually disappointed in at least one of them. Organizations that hire three separate specialists with no prior working relationship are usually disappointed by the coordination failures between them during the exact hours when coordination matters most. The right answer is neither extreme. It is knowing, before an incident happens, exactly which firm or team covers which of the three roles, and confirming they have either worked together before or have a clear protocol for handing off between each other.
A Worked Example
Picture a mid-market manufacturer with no incident response retainer in place. Ransomware hits on a Friday night. The internal IT team, capable at day-to-day operations but with no incident response experience, calls the company's longtime managed service provider. The MSP is good at patching and help desk work, but has never negotiated with a ransomware group and has no forensic tooling to determine whether the attackers are still inside the network. Over the next 48 hours, the MSP attempts negotiation on its own, mishandles the initial contact in a way that spooks the threat actor group into raising the price, and simultaneously fails to identify a second point of persistence the attackers left behind. Systems get restored, a ransom gets paid at a higher figure than a specialist negotiator would likely have achieved, and three weeks later the same attacker group is back inside the network through the access point nobody found the first time.
Now picture the same incident at a company that signed an incident response retainer the year before. A single call activates a DFIR team with a contractual response time, a vetted negotiation specialist is looped in within hours if the ransom note indicates a known threat actor group, and an executive communications lead who has managed prior incidents is already drafting the board and regulatory notification timeline before day two ends. The technical outcome may still involve a ransom payment. But the negotiation is handled by someone who does it professionally, the forensic sweep is thorough enough to catch the second access point, and leadership spends its time making decisions instead of searching for phone numbers.
The Strongest Case for a Single Full-Service Vendor
There is a real argument for consolidating with one full-service incident response firm rather than pre-vetting three separate specialists, and it deserves fair treatment. Coordination overhead during a live incident is genuinely dangerous. Every handoff between separate firms is a place where information gets lost, responsibility gets unclear, and precious hours disappear into email threads trying to establish who owns which decision. A single firm with an internal negotiation team, internal forensic capability, and internal crisis communications staff eliminates that handoff risk entirely, because everyone reports to the same incident commander from hour one.
This argument is strongest for organizations without the internal sophistication to manage multiple vendor relationships under pressure, and it is a legitimate reason to prefer a full-service firm over assembling a coalition of specialists from scratch. The mistake is assuming that hiring one firm automatically means all three disciplines inside it are equally strong. Many full-service incident response firms subcontract negotiation quietly to a partner specialist rather than staffing it internally, and many are stronger on the technical forensic side than on executive-level crisis communication. The fix is not choosing between one firm or three. It is asking any full-service candidate, before signing a retainer, to name specifically who on their team handles each of the three disciplines and how long that person has done that exact work, rather than accepting a single logo as proof of depth in all three.
Monday Questions for Leadership and the Board
Leadership and the board should be able to answer these questions today, not during the incident. Do we have a signed incident response retainer in place right now, or would our first call during an attack be to a vendor we have never contracted with. Does our retainer specify a response time SLA, and has anyone verified that SLA against our cyber insurance carrier's approved vendor panel to avoid a coverage dispute after the fact. Who specifically handles negotiation, who handles forensic investigation, and who handles executive and regulatory communication, and are those three people or firms already known to each other. When was our incident response plan last tested against a realistic ransomware scenario, and did that test include the crisis communication piece or only the technical recovery piece. And if we have never asked our current vendor whether they subcontract negotiation, why not.
The organizations that recover fastest are not the ones that panic least. They are the ones that already knew, before the ransom note appeared, exactly who to call and what each of those calls was for.