One of the defining things I’ve seen at every org I’ve talked to about ransomware preparedness is they’ve spent more time deciding if and how they would pay a ransom - who gets the call, the CEO, the board etc - than actually preparing cyber resilience.
Orgs are discussing the wrong thing first because it’s seen as completely normal to pay. That’s all our fault.