Ransomware · 3 September 2026
What a board should ask about ransomware
A board that only asks whether the backup exists arrives late. The useful questions are about evidence, payment, communication and the minimum operation that must survive.
By Rafael Núñez Aponte. Published on 3 September 2026. Updated on 4 September 2026.
Original text in Spanish. Read the original Spanish version

When ransomware “discovered the tie”, it ceased to be a problem of the systems area. Extortion, leakage and operational paralysis reach the board even if no one summoned them. The board that waits for the final report in order to ask arrives late.
Eight fronts the board must govern
Do not ask for the name of the malware family. Ask for options, assumptions and the time of the next update. These eight fronts fit in a board session if someone translates them.
- Continuity: which process, if it stops for 72 hours, puts the company at risk.
- Legal and regulatory: whom to notify, in how many hours, and with what evidence.
- Insurance: whether the policy covers extortion, interruption, forensic costs or only disk damage.
- Evidence: what was preserved, what was touched and who has chain of custody.
- Exfiltration: what data left, not only what data was encrypted.
- Pay or not pay: a written criterion, not improvisation under blackmail.
- Communication: spokesperson, situation sentence and audiences.
- Decision: who decides, with what threshold and at what time the decision is taken again.
Questions before the incident
- What is the business process that, if it stops for 72 hours, puts the company at risk?
- Have backups actually been restored, not merely “completed”?
- Who has authority to disconnect a production environment on a Saturday at 02:00?
- Does insurance cover extortion, or only material disk damage?
- Do we have a written criterion on paying or not paying, or are we going to invent it under blackmail?
Questions during the incident
- What evidence do we have that the actor is who they claim to be and that they will destroy what they promise to destroy?
- What data left, not only what data was encrypted?
- Whom are we obliged to notify and in how many hours?
- What minimum operation can we sustain without the main system?
- Who speaks with the press, and with what situation sentence?
Decision matrix: pay or not pay
Paying is not a technical decision. It is a governance, legal and reputational decision. Not paying is not one either. The matrix does not say what to do. It says what cannot be missing from the table.
- Operational impact: does the actual restoration fit within the maximum tolerable time, or has encryption already exceeded it?
- Exfiltration: is the blackmail only encryption, or also publication of third-party data?
- Legal: does paying violate sanctions, policy conditions or fiduciary duties?
- Trust: can the organisation explain the decision to regulators, clients and employees?
- Precedent: what signal is sent to other actors if payment is made, and what signal if it is not paid and there is no recovery?
What the board must not ask
It must not ask for the name of the malware family as if that would resolve the quarter. It must not demand certainties at minute 20. It must ask for options, assumptions and the time of the next update. The CISO who only receives reproaches in the crisis will not be able to tell the truth in time the next time.
What evidence to ask for each answer
- Backup restoration: date of the last real restore, not the last “completed” backup.
- Authority to disconnect: name, alternate and proof that it was rehearsed.
- Notification: a written legal deadline and an owner, not a “legal will look at it”.
- Pay or not pay: a prior signed criterion. An improvised answer under blackmail is insufficient.
These risk-governance questions are read in the language of identify, protect, detect, respond and recover of the NIST Cybersecurity Framework. They do not replace that framework: they keep the board from delegating it entirely to the technical area.
References
- NIST Cybersecurity Framework. NIST. Accessed: 2026-09-04. Las preguntas de la junta se plantean como gobierno del riesgo (identificar, proteger, detectar, responder y recuperar), no como inventario técnico.