---
title: "Ransomware. Should You Pay? - Christian Espinosa"
description: "Explore the complex &quot;to pay or not to pay&quot; ransomware dilemma, weighing the risks to critical services like healthcare against rigid organizational policies…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "Ransomware. Should You Pay? - Christian Espinosa",
      "description": "Explore the complex \"to pay or not to pay\" ransomware dilemma, weighing the risks to critical services like healthcare against rigid organizational policies…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/131b572a-493c-41df-9026-43a9d13e910b/ransomware-should-you-pay-card.png",
      "datePublished": "2020-07-03T01:12:45+00:00",
      "dateModified": "2026-06-26T05:36:45.247Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/ransomware-should-you-pay"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"Ransomware. Should You Pay? - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "What do you do if you get ransomware in healthcare or critical infrastructure? Should you pay the ransom? How do you prevent ransomware?"
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# Ransomware. Should You Pay?

July 3, 2020 4 min read 887 words 

I was watching Chicago Med the other night, Season 2, Episode 19. The show isn't usually on my list, but this episode hit home: Chicago Med was infected with ransomware. Every computer system went down. Doctor's tablets, MRI machines, patient history, diagnostic systems; all useless.

![](/__l5e/assets-v1/6739ab99-8557-4c07-8b5c-b79b02e67cc0/d3095526dda5.jpg)

The takeaways

1.  01 
    
    Paper lab requests, whiteboards for patient status, old-school methods for diagnosis.
    
    What to do next Ask your security lead this week for the one-page view of paper in your environment, and read it end to end.
    
2.  02 
    
    Many people have polarizing opinions on just about everything, including this topic.
    
    What to do next Open your current people plan today and identify the one gap you would not want an auditor to find.
    
3.  03 
    
    Every second in this delay increased the risk that your spouse might die.
    
    What to do next Ask your security lead this week for the one-page view of risk in your environment, and read it end to end.
    
4.  04 
    
    The Chicago Med hospital administrator was adamant about not paying the ransom, but one of the doctors paid the ransom himself.
    
    What to do next Run a 20-minute tabletop with your team this month using chicago as the scenario.
    

I was watching Chicago Med the other night, Season 2, Episode 19. The show isn't usually on my list, but this episode hit home: Chicago Med was infected with ransomware. Every computer system went down. Doctor's tablets, MRI machines, patient history, diagnostic systems; all useless. The staff had to go manual. Paper lab requests, whiteboards for patient status, old-school methods for diagnosis. It was chaos.

A debate started about paying the ransom. It was only $30,000. The staff had different opinions. Some wanted to pay, others refused.

This is a debate worth having. I don't see a clear answer to "should I pay the ransom." The answer is always, "it depends."

![Ransomware Attack - Manual method](https://1kggaz45g7tf2360kdj0h7g1-wpengine.netdna-ssl.com/wp-content/uploads/2020/02/chicagomed-manualprocesses.jpg) 

The reliance on medical technology makes manually processes like this prone to mistakes

I tend to look at everything from a risk perspective. Sure, it’s easy to say “our policy is we do not pay the ransom”, but at what cost? Many people have polarizing opinions on just about everything, including this topic. It’s easy to make recommendations from afar. What if your spouse was in a hospital and needed immediate emergency treatment, but treatment was delayed because of ransomware? Every second in this delay increased the risk that your spouse might die. Would you still support the policy “we do not pay the ransom”, even if it meant your spouse may die? Is $30k worth more than your spouse?

Also, the rationale for the “we do not pay the ransom” policy goes something like this. “if the hackers know we do not pay the ransom, they won’t attack us”. This is flawed logic because many cybercriminals release ransomware into the “wild”, non-directed, to spread to as many systems as possible, so they can maximize odds of success and returns.

The Chicago Med hospital administrator was adamant about not paying the ransom, but one of the doctors paid the ransom himself. After the ransom was paid, all the systems came back online and everything went back to “normal”. The doctor that paid the ransom simply stated that the risk was too great and that he had calculated the ROI and it was an easy decision.

_But, wait…what if you pay the ransom and the hackers just take your money and don’t decrypt your systems?_

This is certainly a possibility, although it is almost never the case. Most cybercriminals are in the business of making money, so their business models support this objective. Cybercriminals probably analyze risk in greater depth than most IT Staff of Cybersecurity Staff.

Risk is a real issue that is almost always overlooked. Sure, screw paying the ransom if:

-   Your IT/Cybersecurity Staff has an up-to-date and rehearsed Incident Response Plan
-   Your IT/Cybersecurity Staff has current, up-to-date backups that can be restored quickly
-   Your IT/Cybersecurity Staff can source the ransomware infection and prevent it from occurring again after the backup restoration
-   Your IT/Cybersecurity Staff knows which vulnerability the ransomware exploited
-   Your IT/Cybersecurity Staff knows the extent of the infection; did the infection hit the backup systems?

In the Chicago Med episode, they had to end up diverting patients to other hospitals because of the ransomware. The Chicago Med IT Staff seemingly did not have a plan, at least a timely one, to restore the hospital systems.

I’m certainly not advocating people pay the ransom, but blindly making blanket policies without understanding risk is a huge problem, especially at places where time is of the essence, such as hospitals.

## So, what can you do to help with RANSOMWARE? I recommend 3 things to start:

1.  **Perform a risk assessment against your environment**; identify your critical assets (data and systems). Not everything is critical. Narrowing your focus to what is critical, then prioritizing accordingly allows you to better protect these systems and restore them in a prioritized manner. Too many organizations try to equally protect everything. This is a huge mistake, as everything is half-ass protected, which doesn’t cut it. It’s better to protect your 10 critical assets 100% and leave the 90 noncritical assets at 50%. This is better than all 100 assets being protected at 60%, which is a common mistake.
    
2.  Once you know your critical systems, make sure those systems (and the applications installed on them) are **patched routinely and that they are backed up** (the system itself as well as the data on the system) as frequently as needed.
    
3.  **Critical system backups security and testing. Make sure the backup system is secure.** If the ransomware hits the backup system, the backups are no good. Also, make sure you know how to restore from backups. This seems simple, yet it is often overlooked. I’ve seen many organizations back up their data routinely and religiously and never once test the restoration procedures. During an incident, they found out that the restoration procedures did not work at all or only partially worked.
    

If you’re unclear on how to perform the risk assessment or need help with a cybersecurity plan, Alpine Security can help you with our [CISO-as-a-Service](https://bluegoatcyber.com/services).

Frequently asked

### What is the core idea behind "Ransomware. Should You Pay? - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-should-you-pay&text=Ransomware.%20Should%20You%20Pay%3F) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-should-you-pay) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-should-you-pay) [Email](mailto:?subject=Ransomware.%20Should%20You%20Pay%3F&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fransomware-should-you-pay)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### Ransomware Attacks: New Ways to Exploit Old Vulnerabilities - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/ransomware-attacks-new-ways-to-exploit-old-vulnerabilities)
-   [
    
    ### Top 10 Largest Healthcare Data Breaches by Number of Records Stolen - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/top-10-largest-healthcare-data-breaches-by-number-of-records-stolen)
-   [
    
    ### Hacking Medical Devices for Profit and Terror - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/hacking-medical-devices-for-profit-and-terror)

[← Previous essay 

Aviation Cybersecurity – Hacking Aircraft - Christian Espinosa

](/blog/aviation-cybersecurity-hacking-aircraft)[Next essay → 

The Cybersecurity Status Quo Needs to Change - Christian Espinosa

](/blog/the-cybersecurity-status-quo-needs-to-change)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)