
Double extortion, subsidiaries as a top target, and insurers demanding proof: How to decide when faced with ransomware in 2026—and how to avoid having to make that decision.
There’s one question no CEO wants to ask himself on a Friday at 6 p.m.: “The systems are encrypted, and they’re demanding a ransom—should we pay?” In 2026, that question is more complicated than ever, because ransomware is no longer just about hijacking files: it’s a multi-stage extortion scheme, and Mexican companies—particularly subsidiaries of international groups—are among its top targets.
The classic model—encrypting files and selling the key—has evolved into double and triple extortion: before encrypting, attackers spend weeks inside the network, exfiltrate sensitive data, and then threaten to publish it, notify your customers, or report you to the regulator if you don’t pay. Even if you have perfect backups, the threat of publication remains on the table. That’s why the modern response to ransomware begins long before encryption: with detecting the reconnaissance phase.
The unanimous recommendation from cybersecurity agencies remains not to pay, and the reasons are sound:
That said, the actual decision is never abstract: it depends on whether you have usable backups, what data was lost, and who else is involved—the insurance company, lawyers, headquarters, and authorities. The goal of a good security plan is to ensure that you never have to make this decision under pressure.
Ransomware groups study their victims. A subsidiary of a multinational company combines three attractive targets: ability to pay (the group’s resources), weak coordination with headquarters (security policies that didn’t translate well across the Atlantic), and reputational pressure (a breach in Mexico immediately escalates to the European parent company, with the “ RGPD ” in the background). We analyze this in detail in our report on how cyberthreats have evolved since 2020.
At Keptos , we provide managed cybersecurity services for international companies and subsidiaries in Mexico: proven immutable backups, EDR, MFA , and an incident response plan tailored to your industry—with 30 years of experience and compliance LFPDPPP and RGPD. If you don’t know how you would respond today to a large-scale encryption attack, that’s exactly the assessment you need to make this week—not after the incident occurs.
30 minutes with one of our directors. No sales pitch—straight to the point.