DFIR Tech Blog – an AI playground

Deutsch English
Foto von History in HD auf Unsplash.com

Ransom by Resolution: When IR Needs a Council Vote

01.10.2026 ransomwareincident responseregulatory compliancepublic sector

While European IR teams wrestle with NIS2 reporting deadlines, a different problem is emerging in the United States: in a growing number of states, the decision to pay a ransom is no longer purely an operational call made by the IR team—it is a political act requiring a public vote. What sounds like an administrative footnote is forcing public-sector IR playbooks to rebuild their decision chains from scratch.

When a Council Vote Becomes the Bottleneck

Ohio’s House Bill 96 established a middle path between an outright ban and unrestricted payment: a political subdivision experiencing a ransomware incident shall not pay or otherwise comply with a ransom demand unless the political subdivision’s legislative authority formally approves the payment or compliance in a resolution or ordinance that specifically states why the payment is in the best interest of the subdivision. The law does provide that emergency meeting rules allow timely sessions to approve a ransom payment, so the legislative authority can be convened quickly if needed—but in municipal practice, “quickly” often means hours or days, not minutes. Meanwhile, the attacker’s negotiation countdown keeps running.

For the incident commander, this means building not just a technical escalation chain but a pre-wired communication path to a mayor, city council, or school board—including a legally defensible justification template that can be populated with facts from the live investigation within hours. Public-sector tabletop exercises now need to explicitly rehearse this governance session, not just the technical containment workflow.

Ban vs. Approval: A Growing Patchwork

Ohio is actually the moderate approach. Late in 2022, North Carolina became the first U.S. jurisdiction to prohibit state agencies and local government entities from making a ransom payment or communicating with a threat actor following a ransomware attack, and the prohibition covers all state agencies, the University of North Carolina, cities, counties, local schools, community colleges and more. Florida followed with its own ban. Other states are experimenting with yet different models: Pennsylvania’s SB 726 would prohibit using taxpayer money for ransomware payments and require MSPs to notify an appropriate official within one hour, Arizona’s HB 2145 would prohibit any payment to remove or decrypt ransomware, and Texas’s HB 3892 contains a similar payment prohibition. An IR team covering multiple jurisdictions—a state-level SOC or an MSSP serving several municipalities—must now apply a different decision regime depending on which entity is affected: full ban, conditional approval, or no restriction at all.

Whether these laws actually deter attackers remains doubtful: early evidence from North Carolina suggests the deterrent effect may be limited, as the number of reported attacks on public entities did not notably decrease after the ban. In practice, the payment question doesn’t disappear—it just shifts who gets to decide, and how fast.

CIRCIA Adds a Third Clock

Layered on top of local governance hurdles is a federal reporting clock. CISA is targeting September 2026 for the final CIRCIA rule, which would impose strict 72-hour cyber incident and 24-hour ransomware payment reporting windows. While publishing the final rule is not the same as reporting becoming mandatory that day—the effective date will be set separately, and analysts expect enforceable obligations to begin sometime between late 2026 and 2027, public-sector IR teams are now staring down three parallel clocks: the attacker’s negotiation deadline, the council’s approval timeline, and the federal reporting window to CISA.

Playbooks need to reconcile all three now—with pre-defined escalation thresholds, draft resolution language ready to populate, and a clear division of labor between technical response, legal counsel, and elected leadership. Building this during a live incident costs hours that neither the attacker nor the regulator is willing to grant.

← Back to overview