← Back to Guides
Cybersecurity
August 10, 2026
Ransomware — To Pay or Not to Pay the Ransom?

Ransomware in Mexico: To Pay or Not to Pay the Ransom?

Double extortion, subsidiaries as a top target, and insurers demanding proof: How to decide when faced with ransomware in 2026—and how to avoid having to make that decision.

Resource · Keptos

There’s one question no CEO wants to ask himself on a Friday at 6 p.m.: “The systems are encrypted, and they’re demanding a ransom—should we pay?” In 2026, that question is more complicated than ever, because ransomware is no longer just about hijacking files: it’s a multi-stage extortion scheme, and Mexican companies—particularly subsidiaries of international groups—are among its top targets.

How Ransomware Works in 2026: It's No Longer Just About Encryption

The classic model—encrypting files and selling the key—has evolved into double and triple extortion: before encrypting, attackers spend weeks inside the network, exfiltrate sensitive data, and then threaten to publish it, notify your customers, or report you to the regulator if you don’t pay. Even if you have perfect backups, the threat of publication remains on the table. That’s why the modern response to ransomware begins long before encryption: with detecting the reconnaissance phase.

To Pay or Not to Pay? The Honest Decision-Making Framework

The unanimous recommendation from cybersecurity agencies remains not to pay, and the reasons are sound:

  • Paying does not guarantee anything. A significant number of victims who pay do not recover all their data, and the decryption keys provided either fail or only partially decrypt the files.
  • You're funding the next attack —possibly against you: organizations that pay are marked as payers and are attacked again.
  • This could have legal consequences. Paying internationally sanctioned groups exposes the company—and a Mexican subsidiary of a European or American group inherits those restrictions from its parent company.
  • Your insurance provider may deny your claim. Cyber risk policies increasingly require evidence of preventive controls (MFA, tested backups, EDR). Paying out of pocket without coordinating with your insurer may void your coverage.

That said, the actual decision is never abstract: it depends on whether you have usable backups, what data was lost, and who else is involved—the insurance company, lawyers, headquarters, and authorities. The goal of a good security plan is to ensure that you never have to make this decision under pressure.

If this is happening right now: the first steps

  1. Isolate, don't shut down. Disconnect the affected devices from the network, but don't shut down the servers: forensic analysis can recover passwords from memory.
  2. Activate your incident response plan —if you have one. Define roles, timelines, and a single spokesperson. If you don't have one, this is when you'll realize it.
  3. Notify the following parties simultaneously: your security provider, your insurance company (before any payment decision is made), and the authorities—in Mexico, the National Guard (CERT-MX) receives incident reports.
  4. Verify backups in an isolated environment before restoring them: Attackers often encrypt or delete connected backups as their first move.
  5. Document everything with timestamps: the coroner, the insurance company, and—if you're a subsidiary—the parent company will require it.

Why Subsidiaries in Mexico Are a Top Priority

Ransomware groups study their victims. A subsidiary of a multinational company combines three attractive targets: ability to pay (the group’s resources), weak coordination with headquarters (security policies that didn’t translate well across the Atlantic), and reputational pressure (a breach in Mexico immediately escalates to the European parent company, with the “ RGPD ” in the background). We analyze this in detail in our report on how cyberthreats have evolved since 2020.

Prevention That Really Works

  • Reliable backups using the 3-2-1 rule—and proven to work. A backup that has never been restored is a hypothesis, not a plan. Documented, periodic restores are what separate a scare from a crisis.
  • EDR with automated responses across all endpoints — the weeks of prior activity can be detected if someone is watching.
  • MFA across the board, starting with remote access and privileged accounts: this remains the number one point of entry.
  • Network segmentation so that a compromised device does not bring the entire plant to a halt.
  • A written and rehearsed response plan, including an annual drill: the difference between 4 hours and 4 weeks of paralysis is decided before the attack.

The right question isn't "Would I pay?" but "Am I ready?"

At Keptos , we provide managed cybersecurity services for international companies and subsidiaries in Mexico: proven immutable backups, EDR, MFA , and an incident response plan tailored to your industry—with 30 years of experience and compliance LFPDPPP and RGPD. If you don’t know how you would respond today to a large-scale encryption attack, that’s exactly the assessment you need to make this week—not after the incident occurs.

Do you need specific help with this topic?

30 minutes with one of our directors. No sales pitch—straight to the point.

Free Diagnosis · 30 minQuote within 24 hours