Intel 471: Ransomware Negotiation Is Now a Run-the-Numbers Business Process
Intel 471's intelligence team says ransomware negotiation has become a structured business process: crews research a victim's revenue and insurance, price demands at 1 to 5 percent of annual revenue, and prove their key with a test decryption. Here is what defenders should settle first.
Ransomware crews no longer improvise the money part. According to threat-intelligence firm Intel 471, the people who set the ransom, run the chat, and lean on the deadline are following a repeatable business process, complete with research files, a pricing formula, and a proof-of-service step. Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, walked through that process in a September 8, 2026 Help Net Security video, and the through-line for defenders is uncomfortable: by the time the note lands, the attacker has already done more homework on your finances than most boards do in a quarter.
The single most useful fact in that breakdown is the pricing. Ross says demands are often set at roughly 1 to 5 percent of a victim's annual revenue. That is not a number pulled from the air during the chat. It is the output of reconnaissance the crew ran before it ever encrypted a file, and it reframes the whole encounter. A ransom negotiation is not a hostage drama. It is a vendor with a very ugly product line trying to close a deal, and it has priced you the way a salesperson prices an account.
What the Attacker Knows Before They Knock
The demand is calibrated, not guessed. Ross describes crews researching a victim's revenue and insurance coverage before setting a figure, which is how the 1-to-5-percent band gets anchored to something real rather than aspirational. Public companies hand over most of what a crew needs in annual reports and filings; private targets leak it through headcount, sector norms, and whatever a broker or a breached mailbox reveals about a cyber-insurance policy. The insurance piece matters most, because a known coverage limit tells the attacker roughly how much cash can move without a board fight.
For a defender, the takeaway is not to hide your revenue from the SEC. It is to notice that two of the numbers an attacker prices against, your revenue and your insurance limits, live in documents and inboxes that far too many people inside the company can reach. The blast radius of a compromised finance or risk mailbox is not just the data in it. It is the negotiating leverage it hands the other side.
The Negotiation Is Staffed Like a Company
Ross describes a division of labor that would look familiar in any mid-size firm. Some groups split the work between researchers who build the victim profile, negotiators who run the chat, and staff whose only job is applying public pressure. Around that core sits a criminal service economy that rents out the capabilities a crew does not keep in-house: native-language speakers to sound credible to a target, analysts to sift stolen data for the most damaging material, and even legal analysis to estimate a victim's regulatory exposure.
That specialization feeds multi-extortion. Beyond encrypting systems, Ross points to data theft, distributed denial-of-service attacks, and direct contact with a victim's customers and journalists as pressure levers a crew can pull in sequence. The message underneath is that the encryption is only the opening move. The business model is built to keep finding new places to hurt until someone pays or the crew decides the account is not worth the effort.
The CyberSignal has tracked this professionalization from the other side of the desk. The rise of the dedicated response role, covered in our look at cyber negotiators, exists precisely because the adversary now shows up with a script and a support team. And when a target refuses to engage on the crew's terms, the standoff plays out publicly, as it did when Berlin declined to pay extortionists during a widening breach of its state network.
Test Decryption and the Flexible Deadline
Two mechanics in Ross's account deserve a defender's attention because they reveal how the crew manages trust and time. The first is the test decryption. Attackers offer to decrypt a small sample of files, which Help Net Security's write-up describes as "test decryptions that prove they hold a working key." It is a proof-of-service step, the criminal equivalent of a free trial, meant to establish that paying would actually return data. It says nothing about whether the crew will hand over everything, or whether it kept a copy of what it stole.
The second is the deadline. Ross says the clock moves depending on how a victim responds. A countdown that looked immovable in the first message will stretch when a target engages and shrink when the crew senses urgency or leverage. The deadline is a tactic, not a fact, and treating it as a hard physical constraint is exactly the mistake the pressure is engineered to produce. Recognizing that the timer flexes is not a negotiating trick for defenders to deploy. It is context that keeps a response team from making a rushed, irreversible call because a screen said they had six hours.
Where the Business Model Leaves Openings for Defenders
A process this structured has seams, and the seams are where detection lives. The research Ross describes happens before encryption, which means the loudest part of an attack is not the first thing that happens. Someone has to find and read your annual figures, locate the cyber-insurance policy, and stage stolen data for review, and each of those steps touches systems a security team can watch. Unusual access to finance and risk repositories, large outbound transfers ahead of any ransom note, and a spike in reads against document stores that hold contracts and policies are the kinds of signals that precede the demand rather than follow it. None of that is a guarantee, and a determined crew will try to stay quiet. But the same specialization that makes these groups efficient also makes their pre-encryption activity look different from ordinary business, and a defender who has decided in advance what those repositories should look like on a quiet day is better placed to notice when they do not. The point is not a single magic alert. It is that treating the reconnaissance as part of the attack, rather than as background noise, moves the detection opportunity earlier, when there is still time to contain.
Why This Is a Pre-Incident Business Decision
Here is the part that should change how a security program is run. If the adversary treats extortion as a business, it wins the moment the victim is improvising. Every advantage in Ross's account, the research, the staffing, the pricing, the proof step, the flexible clock, is a preparation advantage. The crew rehearsed; the victim usually has not. That gap is the real product being sold.
The fix is not a better in-crisis playbook alone. It is moving the hardest decisions out of the crisis entirely. The reconnaissance an attacker does on your revenue and insurance should be matched by decisions you have already made about who can see those numbers, who is authorized to speak, and whether payment is even on the table. Ross himself frames the preparation as pre-incident work: deciding in advance who is authorized to speak and which stakeholders to involve. For a full framework on staging that response before an incident, see our complete guide to incident response.
|
● Pre-Incident Readiness
Five decisions to settle before a ransom note lands, not during the crisis.
|
|
1. Set the Payment Policy First
Decide with legal and leadership, in advance, whether and when paying is even on the table. A live incident is the worst moment to have that debate for the first time.
|
|
2. Control Who Can See Revenue and Insurance
These are the two numbers a crew prices against. Limit how many mailboxes and shares hold policy limits and financial detail, and treat a compromised finance or risk inbox as a leverage leak, not just a data one.
|
|
3. Pre-Select IR and Negotiation Counsel
Retain incident-response and specialized counsel before you need them. Finding, vetting, and contracting a firm mid-incident burns the hours the deadline is designed to pressure.
|
|
4. Keep Tested, Offline Backups
A verified, restorable backup means a criminal's test decryption is never your only evidence that recovery is possible. Test restores on a schedule, and keep at least one copy the attacker cannot reach.
|
|
5. Rehearse the Decision in Tabletops
Run the pay-or-not call as a drill, with legal, leadership, and communications in the room, so the authority chain and the flexing deadline are familiar before they are real.
|
|
Source: The CyberSignal analysis of Intel 471 process intelligence, via Help Net Security, September 8, 2026. Defender preparation, not negotiation guidance.
|
Pre-incident readiness checklist. The five decisions a security team should settle before a ransom note arrives, drawn from Intel 471's account of how crews prepare. Defender preparation only.
None of that is a script for negotiating. It is the opposite: it is the set of decisions that make a negotiation shorter, calmer, and less coerced because the panic-driven questions already have answers. Whether an organization ever pays is a legal and leadership call this piece takes no position on. The point is that the call should be made by people who saw it coming, not by whoever is holding the incident bridge at 2 a.m. with a countdown on the screen.
My Read
My read: if the adversary treats extortion as a business, defenders should treat negotiation readiness as a pre-incident business decision, not an in-crisis scramble. The most valuable thing in Ross's account is not any single tactic. It is the confirmation that the crew's edge is preparation, and preparation is the one advantage a defender can take back for free, months before an incident, by deciding the hard questions while no one is under a clock. Assessment, not reported fact: the 1-to-5-percent pricing tells me the fastest way to shrink an attacker's leverage is to shrink what they can learn about your money, and that is a data-governance problem as much as a security one.
Two limits worth stating plainly. Intel 471's account describes the process in general terms; it does not name specific victim organizations, and The CyberSignal has not confirmed any. It also does not claim that particular ransomware groups follow these tactics more rigorously than others, nor that the 1-to-5-percent range shifts by sector. Those remain open questions rather than established findings, and we have not seen them confirmed. For a sense of how disciplined the top-tier crews have become, our coverage of the Medusa ransomware advisory shows the operational scale on the other side of these negotiations.
Primary Documents
- Help Net Security: "Ransomware negotiation tactics have turned into a business process", video interview with Dave Ross, Intel 471, September 8, 2026.
- Intel 471, Intelligence Fusion Team.