When a company is hit by ransomware, paying for a decryption key can seem like the least expensive path forward. But according to Veeam’s 2025 Risk to Resilience report, only 10% of organizations that paid recovered more than 90% of their data, while most recovered less than half. Worse still, 69% of those who paid a ransom reported being attacked more than once.1 These incidents can force impossible decisions. For example, research has shown a 35%–41% increase in mortality rates when hospitals were hit by ransomware.2 In cases like these, it is easy to see why payment can feel like the least bad option.