Once upon a time, victims of ransomware kept quiet about their misfortunes, with petrified leaders nervously improvising a way to get past the extortion. Now, two new large-scale studies have compiled many of those miserable experiences for collective lessons, examining 786 ransom negotiation transcripts and 253 companies’ recovery experiences. In this second article in a two-part series, with insight from the studies’ co-authors, we distill the findings into 10 steps to plan for and steer through the payment decision. In part one, we examined the common factors that helped companies avoid paying ransoms, with commentary from the researchers at NCC Group and Booz Allen Hamilton. See “A Look Inside Businesses’ Private Disputes Over Ransomware Costs” (Aug. 18, 2021).