Ransomware decisions under pressure: a framework for boards

When a ransomware crisis strikes, would your board know who decides what, and when?

Ransomware is not only a technology incident. It is also a test of board oversight, governance effectiveness and decision-making under pressure.

According to S-RM’s 2026 Cyber Incident Insights Report, ransomware accounted for 64% of the cyber incidents S-RM responded to in Asia-Pacific in 2025, compared with a global average of 45%.

When an incident occurs, boards may be required to make consequential decisions before investigations are complete and the full picture is clear. Information may be partial or contradictory, operational disruption may be escalating, and stakeholder expectations may be intensifying.

In these circumstances, effective governance is not about having every answer. It is about ensuring that decisions are timely, authorised, evidence-based and defensible.

Is your board ready to make critical decisions under pressure?

Before an incident occurs, boards and leadership teams should be able to answer critical questions such as:

  • Who has decision-making authority?
  • What information must be verified first?
  • What triggers threat actor engagement?
  • Has the board rehearsed any of this together?

Prepared organisations establish decision rights, escalation thresholds and governance structures before a crisis, instead of debating them while an incident is unfolding. 

Ransomware decisions under pressure: a framework for boards

Read more

An executive's guide to cyber crisis decision-making 

Produced jointly by Howden and S-RM, Ransomware decisions under pressure: a framework for boards is designed to support boards in asking better questions and assess their readiness across decision-making protocols, governance and decision quality before a real incident occurs.

It is a decision-support framework for reflection and discussion, not a prescriptive incident response manual. Boards can use it to ask better questions, support readiness conversations and inform tabletop exercises before pressure builds. 

The guide explores:

  • Board readiness: Moving from assumptions to clear decision protocols
  • Decision-making authority: Establishing who can decide, approve and escalate
  • Early-stage decisions: Navigating the first 48 to 72 hours with incomplete information
  • Threat actor engagement: Understanding how specialist-supported engagement may provide intelligence and decision support
  • The broader governance challenge: Looking beyond a binary “should we pay or should we not pay” question
  • Insurance readiness: Understanding how cyber and D&O liability insurance may support response capability and decision quality
  • Pressure-testing: Rehearsing governance, escalation and response capability/arrangements before an incident

The framework also includes a Board Ransomware Readiness checklist to serve as a readiness reference and discussion support tool for boards and leadership teams.

Good governance strengthens response

The most effective boards do not rely on improvisation. They establish clear authority, pressure-test assumptions and rehearse decision-making before a crisis occurs.

The objective is not to predict every scenario, but to ensure leadership can make timely, authorised and defensible decisions when uncertainty is at its highest. 

Ransomware 2

Download your complimentary copy of Ransomware decisions under pressure: a framework for boards

A practical field guide to help boards navigate ransomware decisions under pressure.

Gain greater clarity on governance, decision-making and preparedness, ahead of a live ransomware incident.