ARTICLE
22 October 2021

A Guide For Boards And Companies Considering Whether To Pay A Ransom Following A Cyber Attack

ML
Milbank LLP

Contributor

Milbank LLP is a leading international law firm that provides innovative legal services from 12 offices around the world. Founded in New York over 150 years ago, Milbank helps the world’s leading commercial, financial and industrial enterprises, as well as institutions, individuals and governments, achieve their strategic objectives.
Ransomware groups continue to proliferate, and attacks have become more common, sophisticated and successful.
United States Corporate/Commercial Law

Milbank Litigation & Arbitration partners Antonia M. Apps and Adam Fee, and special counsel Matthew Laroche, have authored "A Guide for Boards and Companies Facing Ransomware Demands." The article was first published on October 16, 2021 in the Harvard Law School Forum on Corporate Governance, a leading online resource on corporate governance issues. 

Ransomware groups continue to proliferate, and attacks have become more common, sophisticated and successful. While the US Department of the Treasury and other law enforcement and regulatory bodies have issued guidance and made public statements discouraging ransomware payments, the practical reality is that paying a ransom may make the difference between the failure or survival of a business. Victim companies and the boards overseeing them must be prepared to decide whether to pay quickly, pragmatically and decisively.

In "A Guide for Boards and Companies Facing Ransomware Demands," the authors address specifically the legality of paying the ransom and the potential applicability of the US sanctions regime and anti-money laundering statutes, particularly in light of recent actions by the Department of the Treasury. They also offer three practical assessments for companies determining whether to pay, including valuing the breached data in the context of a modern ransomware attack, the practical risks from paying the ransom, and methods for negotiating and paying.

Read "A Guide for Boards and Companies Facing Ransomware Demands" on the Millbank General Counsel blog here.

The article was first published on October 16, 2021 in the Harvard Law School Forum on Corporate Governance

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More