
Ransomware, negotiation, and cyber insurance: a PR executive guide
Pay ransom? What does the policy cover? Legal and insurance decisions PR executives must make before an incident.
When ransomware encrypts a Caguas distributor's operations on a Tuesday morning, the CEO's first call is usually legal; the second, the insurer. Brian Krebs has documented how groups adjust ransoms based on estimated target revenue — negotiating without counsel is poker without seeing cards.
Before an incident, Puerto Rico executives must understand three things: what the policy covers (response, forensics, extortion, business interruption), which exclusions apply (missing controls, acts of war), and who legally authorizes ransom payment. OFAC can sanction payments to listed groups — your attorney and broker must align before the crisis call.
CISA discourages paying ransom as a general rule but acknowledges business decisions under pressure. Document tested backups, client communication plans, and pre-approved forensic IR contacts. Continental insurers serving PR increasingly require MFA, EDR, and offline backup evidence before issuing — do not wait for renewal to implement.
Technical negotiation — working decryptor, sandbox test, timeline — belongs to your IR team or policy-included response vendor. The CEO should not be in chat with attackers. Bruce Schneier notes payment does not guarantee deletion of exfiltrated data; treat double extortion as persistent post-payment risk.
Puerto Rico has mainland firms with local subsidiaries on global policies and local SMBs with limited local coverage. A written playbook, annual tabletop with legal/finance/IT, and carrier hotline numbers stored outside the compromised domain beat any "cyber resilience" slide deck.

Writes about practical cybersecurity for SMBs in Puerto Rico and the Caribbean — no fluff, just what actually needs to get done.


