Ransomware Negotiation Is Now a Staffed Business Process

Ransomware groups now run negotiations as a staffed commercial function. Intel 471 reports that operators research a victim's annual revenue and cyber insurance coverage before setting a demand, typically 1% to 5% of yearly revenue, and split the work across researchers, negotiators, and staff who apply public pressure. Preparation, not pricing, decides the outcome.
What did Intel 471 actually describe?
Intel 471 described ransomware negotiation as a repeatable commercial process rather than an improvised shakedown. In a Help Net Security video published on September 8, 2026, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, walked through how groups profile a victim, calculate a demand, run test decryptions to prove they hold a working key, and shift deadlines based on how the victim responds.
The division of labor is the detail worth sitting with. According to Intel 471, some groups separate the work across researchers who profile the target, negotiators who handle the conversation, and staff whose specific job is applying public pressure. That is an org chart, not a crew.
Behind those roles sits a criminal service economy. Intel 471 describes suppliers offering language skills, data review, and legal analysis to extortion groups. A negotiator who does not speak fluent English can rent one. A group that wants to know which stolen files carry the most regulatory weight can pay someone to read them.
The pressure is applied on several fronts at once. Multi-extortion, as Intel 471 uses the term, combines data theft with distributed denial of service attacks and direct contact with the victim's customers and journalists. Encryption is only one lever, and increasingly not the main one.
Why do attackers research your revenue and insurance first?
Attackers research revenue and insurance because both set the ceiling on what a victim can plausibly pay. Intel 471 reports that demands commonly land between 1% and 5% of annual revenue. A company with $40 million in revenue should expect an opening number somewhere between $400,000 and $2 million, calculated before the first message ever arrives in an inbox.
Here is the part the coverage tends to skip. In most intrusions, the attacker has been reading email for days or weeks before anyone notices. That means your cyber insurance policy is often not a private financial arrangement by the time the negotiation starts. Declarations pages, broker correspondence, renewal quotes, and board decks discussing coverage limits are all sitting in mailboxes and file shares the intruder already has.
The practical consequence is uncomfortable but simple. The attacker may know your policy limit before your own executive team has been briefed on the incident. Treating insurance documents with the same handling discipline as payroll data is a small change that removes a large piece of the attacker's pricing model.
Deadlines get set the same way. Intel 471 notes that timelines move depending on how a victim responds, which means the countdown is a negotiating instrument rather than a fixed technical constraint. A victim who replies quickly and emotionally teaches the other side that pressure works.
What do the payment numbers say about who is being targeted?
The payment data shows a market splitting in two. Coveware by Veeam reported that in the second quarter of 2026 the average ransom payment rose 176% from the prior quarter to $1,880,612, while the median payment fell roughly 50% to $150,000. A handful of very large data theft cases pulled the average upward. The typical victim still faced a six-figure decision, not a seven-figure one.
Fewer of those victims are paying at all. Coveware by Veeam reported that the overall payment rate hit a record low in the second quarter of 2026, and that the payment rate for cases involving data theft alone, with no encryption, fell to 15%. Declining has become the common outcome rather than the exception.
The targeting data should end any argument about whether mid-market firms are too small to bother with. Coveware by Veeam found that organizations with 11 to 10,000 employees accounted for 75.8% of its cases in the quarter, with the 101 to 1,000 employee band the single largest at 35.4%. By sector, software services led at 17.2%, followed by healthcare at 14.1%, professional services at 13.1%, and financial services at 9.1%.
Bill Siegel, CEO of Coveware by Veeam, framed the lesson in the firm's quarterly report this way: "Organizations that prepare for the 'rare' incident are the ones who can survive it." That is a preparation argument, not a technology argument.
The decision most companies have not made yet
The decision most mid-market companies have not made is who holds authority during an extortion event. Intel 471 points directly at pre-incident preparation covering who is authorized to speak and which stakeholders to involve. In practice, the calls that stall are rarely technical. They are questions about authority, and they surface at 2am with a countdown already running.
Four questions decide how the first 24 hours go, and most incident response plans answer none of them:
Who is permitted to communicate with the threat actor, and is anyone else forbidden from doing so?
Who can approve or refuse a payment, and above what dollar amount does the board have to be involved?
At what point do the insurer's panel counsel and approved negotiator take over, and who makes that call?
Is the managed service provider or outsourced IT team authorized to speak on the company's behalf, to the attacker or to anyone else?
Most mid-market incident response plans name tools and vendors. Very few name a person with a dollar threshold next to their name. That gap is the one attackers are actually exploiting, and it costs nothing to close.
Look at the asymmetry honestly. The group on the other end has run this process hundreds of times with specialists in each seat. Your leadership team has run it zero times. The disadvantage is not intelligence or budget. It is rehearsal. Defining and testing that decision authority ahead of time is exactly the work a virtual Chief Information Security Officer (vCISO) or fractional CISO does, and it is the reason Purple Shield Security treats extortion readiness as a leadership exercise rather than a tooling one.
What should a business do?
Three things are worth doing this week, and none of them require buying software. Name the person who can authorize or refuse a payment along with the dollar threshold that pulls in the board. Confirm what your cyber insurance policy actually requires in the first 24 hours. Then run a 60-minute tabletop that starts at the ransom note rather than at the alert.
On decision authority: write down one primary spokesperson, one primary payment decision-maker, and a named alternate for each. Put the dollar threshold in writing. Ambiguity here is what turns a bad night into a bad quarter.
On insurance: read the notification clause, not the summary. Many policies require notice inside a defined window and require you to use the insurer's approved counsel and negotiator. Calling your own attorney first can complicate coverage. Ask your broker for the panel list now, while nothing is on fire.
On communications: decide in advance what you will say to customers, staff, and regulators if stolen data is published. Intel 471 describes groups contacting customers and journalists directly as part of the pressure campaign, which means the story can start without you.
Two more items that get missed. Store the plan somewhere the attacker cannot reach, because a response plan that lives only on the file share being encrypted is not a plan. And if you operate in healthcare, legal, or financial services, map which regulatory clocks start the moment data theft is confirmed. That mapping belongs in a risk assessment done on a quiet week, not in the first hour of an incident.
Then run the tabletop. Start it at the note, not at the detection alert. Time how long it takes the room to reach a decision. That number is your real readiness metric.
Frequently asked questions
Should we decide in advance whether we would pay a ransom?
Decide the process in advance, not the answer. Name who can approve a payment, set the dollar threshold that triggers board involvement, and confirm your insurer's requirements. The answer itself depends on facts you will not have until the incident, such as backup integrity and what was actually taken. Coveware by Veeam reported that the payment rate for data theft cases without encryption fell to 15% in the second quarter of 2026, so declining is now the normal outcome.
Does having cyber insurance make us a bigger target?
Coverage does not attract an attack, but it shapes the demand once you are in one. Intel 471 reports that groups research a victim's insurance coverage as part of setting the number. Treat declarations pages, policy limits, and broker correspondence as sensitive documents and keep them out of general file shares and mailboxes an intruder could already be reading.
Is a test decryption proof that we will get our data back?
No. A test decryption proves that an attacker holds a working key for the sample files they selected. It says nothing about whether the full decryptor performs at scale, how many days restoration will take, or whether specific systems will fail to decrypt. Treat it as one input to a recovery estimate, never as a guarantee of recovery.
Does paying guarantee that stolen data is deleted?
No, and there is public evidence on the record. After law enforcement disrupted LockBit in February 2024 under Operation Cronos, investigators found the group had retained victim data it had promised to delete. Coveware by Veeam also documented a June 2026 supply chain compromise at Klue by a group called Icarus, where a separate criminal group was later found holding victim names and data samples after a payment had reportedly been made to guarantee deletion.
Are companies our size actually targeted?
Almost certainly, if you are in the mid-market. Coveware by Veeam found that organizations with 11 to 10,000 employees made up 75.8% of its cases in the second quarter of 2026, and the 101 to 1,000 employee band was the largest single group at 35.4%. The median victim company size was 750 employees.
Ransomware negotiation is a business decision made under time pressure with incomplete information, and the firms that come through it intact tend to be the ones that made the hard calls on an ordinary Tuesday. Purple Shield Security works with mid-market and regulated businesses to define incident decision authority, test it in a tabletop, and align it with their insurance and regulatory obligations before anyone needs it. If you want a second set of eyes on your incident response readiness, that is a conversation worth having.



