Which is why you wouldn't pay it in the first place and which is why you would actually try to make your system secure instead of having an insurance pay for your gross negligence.
Currently, ransomware operators could just decrypt half your files upon 50% payment, and demand yet another payment for the rest. But they don't. Why? Because they seem to have naturally converged upon honoring their decryption payments in order to maximize total profit. I think if paying the ransom was made more explicitly illegal, the ransomware operators would probably converge on not outing their clients. At least for now.
Or they can threaten to release your information and demand more ransom to keep your information a secret. If you stop paying they'll make it public making what you did illegal.