Security1 publisher2 min readPublished
Arctic Wolf's incident response lead wants the ransom ceiling signed before the intrusion
Kerri Shafer-Page of Arctic Wolf sets out four ransomware decisions in a Help Net Security video, each needing a named owner and, in the case of the payment ceiling, a number approved in advance.
The Watch · Security desk

What happened
- Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walked through a ransomware decision tree in a Help Net Security video, naming four areas where decisions need settling before an incident.
- Containment comes first, and it needs someone who knows the network well enough to judge what pulling a system offline does to client data, a manufacturing line, or a website.
- On the extortion demand itself, she reduces the problem to two questions: who is authorized to negotiate, and what the ceiling on a payment is.
- She argues law enforcement belongs in the playbook because agencies may already know the threat actor and can help a victim avoid sanctions problems.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision A negotiation stalls at the point where the responder has no approved limit, so the choice is to set a figure and a signatory now or to wake an executive who has never considered either.
- cost Priced against a retention and a renewal quote, a ransom payment lands in the insurance budget. Finance is a co-owner of the outcome.
- exposure A company that pays without knowing who it paid carries the sanctions risk itself, and the route to that identification runs through the agency many victims are slowest to call.
- constraint Until the plan names the person who understands downstream dependencies, isolation calls fall to whoever is on shift, and a production line can be stopped by someone with no view of the schedule.
The ceiling is the number most likely to be missing when the phone rings. Shafer-Page treats paying as a business decision, and her comparison is that a demand can cost less than an insurance retention and the higher renewal rates that follow [5]. That is three inputs: the demand, the retention, and the renewal quote. Help Net Security's summary puts a figure on none of them [11].
Authority is the other half of the same decision. A ceiling only works if a named person can approve a payment up to it without convening anyone, and the summary asks that question directly: who is authorized to negotiate, and what is the limit [4].
Count the areas the video names and you get four: containment, negotiation authority and its ceiling, law enforcement contact, and communications [9]. Containment is the only one decided mainly on technical facts. The rest need a signature, a legal read, or a script, and the communications track alone has three owners in her version of it, with cyber legal counsel on disclosure deadlines, a spokesperson, and a help desk prepared beforehand [7].
The summary names no threat actor, dates no intrusion, and attaches no case to any of the four decisions [10]. So the framework cannot be ranked by how often each item fails in real engagements, and the insurance argument cannot be checked against a policy schedule. What it does is put four owners into a document while the network is still up. Shafer-Page's advice, in Help Net Security's account, is to make these decisions on a Tuesday afternoon, not at 2 a.m. on a holiday weekend [8].
What to watch
- Any case data Arctic Wolf attaches to the four decision points, which would let the framework be tested against real engagements.
- Insurer language on retentions and renewal pricing after a paid ransom, since that is the arithmetic the payment decision rests on here.
- Whether the full video or transcript names a threat actor or a demand figure that the written summary leaves out.