Ex-hostage negotiators outline how companies should respond to a ransomware attack
Michael Sjøberg and Peter Skovbo explain how companies should respond to a ransomware attack, avoid costly early mistakes, and regain operational control.
Companies facing a ransomware attack should treat the incident as a hostage crisis for systems, say Michael Sjøberg and Peter Skovbo, two crisis negotiators who now advise private firms. In a recent interview the former Danish military hostage specialist and the head of Zurich-based Delta Crisis described practical steps to regain control, prioritise safety, and prevent expensive mistakes in the first hours. Their guidance frames technical response alongside negotiation, communications, and legal coordination to reduce harm and speed recovery. The duo warns that rapid emotional decisions and ad hoc actions often compound damage during a ransomware incident.
Former military negotiator frames the incident as a controlled escalation
Michael Sjøberg, who led hostage negotiations in the Danish military, argues that early incident response must separate tactical containment from strategic negotiation. He recommends an immediate designation of a single decision-maker for the crisis who can coordinate IT, legal, communications, and executive teams. That centralized command prevents conflicting directives that can undermine containment and forensic efforts. Sjøberg emphasizes that preserving information and time for analysis is as critical as stopping the attacker’s progress.
Containment and triage in the first hours
Rapid technical containment is the priority in the first hours after a ransomware attack, according to both advisers. Actions should include isolating affected systems, limiting lateral movement, and placing critical systems in a controlled offline state while preserving volatile logs and evidence. They caution against hastily wiping or restoring systems without forensic imaging, which destroys data investigators need to trace the intrusion. A clear technical triage — deciding what to shut down, what to preserve, and what to monitor — reduces the risk of further encryption or data exfiltration.
Negotiation tactics adapted from hostage work
Sjøberg and Peter Skovbo explain that negotiation with cybercriminals borrows principles from hostage mediation, including composure, information control, and delay. Negotiators urge firms to avoid emotional or adversarial language and to gather intelligence about the attacker’s demands, capabilities, and proof of access before making concessions. Controlled delay can create space for parallel remedial actions: restoring backups, hardening entry points, and seeking law enforcement support. The advisers stress that negotiation is a tactical choice, not an immediate default; alternatives such as technical recovery or legal remedies may be preferable.
Common early mistakes that escalate damage
The consultants identify several errors that frequently worsen outcomes for organisations struck by ransomware. Restarting systems without forensic capture, paying ransoms without verified decryption guarantees, and publicly speculating on the breach cause or scope are recurring missteps. They also flag the danger of fragmented decision-making, where multiple stakeholders give conflicting instructions that enable attackers to maintain access. Avoiding these mistakes requires clear protocols, pre-authorised roles, and a disciplined “no action without evidence” mindset.
Legal obligations, insurers, and law enforcement coordination
Sjøberg and Skovbo advise immediate engagement with legal counsel, cyber insurers, and, where required, law enforcement to satisfy notification obligations and preserve privilege. Knowing regulatory deadlines for breach reporting and communicating transparently with regulators can limit downstream penalties and litigation exposure. Insurers often require specific loss-mitigation measures and third-party forensics; early alignment reduces disputes over coverage. The advisers recommend pre-established relationships with forensic firms and counsel so these actors can be mobilised without delay.
Restoration, testing, and rebuilding resilience
Once active threats are contained, the focus should shift to verified restoration and resilience-building measures. Both advisers emphasise using tested offline backups, conducting controlled recoveries, and performing full forensic reviews to identify the initial infection vector. Post-incident learning must feed into updated incident response plans, tabletop exercises, and executive-level risk governance. Investing in redundancy, segmentation, and continuous monitoring reduces the chance that a future ransomware attack will produce the same level of disruption.
Companies should treat the first hours after a ransomware attack as mission-critical decision time and avoid impulsive fixes that obscure the root cause. Sjøberg and Skovbo recommend formalising a response playbook that combines technical triage, negotiated engagement when necessary, legal and insurer coordination, and deliberate communications with staff and customers. With clear roles, preserved evidence, and measured negotiation tactics, organisations can improve outcomes and restore operational control more quickly.