Backups aren't necessarily enough. Sure, a lot of companies don't backup. And sure, a lot of companies backup but keep the backups on network shares that the ransomware can reach and encrypt. And sure, a lot of companies keep isolated backups which aren't encrypted, but which are missing the past few days of production data.
But even if you have a perfect backup solution up to the minute before the attack occurred, you'll still be coerced to pay. These ransomware operators are general extortionists - they manually target specific companies and come up with the most impactful threats to pressure you to pay.
They screenshot all of the sensitive documents, emails, IMs, trade secrets, and PII they've gathered and say they'll post it online and mail it to every local, regional, and national press outlet, every company you partner with, and every customer email they've harvested. (And they do indeed make good on this threat if you don't pay by a deadline.) They call all your executives every hour of every day and target their personal devices. They might SWAT your executives' houses.
If you don't have backups, the overall, reputational, and financial cost is probably way higher than the ransom payment. But even if you do, it still might be higher than the ransom payment. Even if you really want to take the moral high ground and inform your customers, partners, and the media of your choice and that you won't negotiate with terrorists or whatever, all of the damage (especially to your reputation and trust) may still be so extreme that you have to shutter your company.
I don't think you can fault someone for paying the ransom when they're being explicitly targeted by sophisticated attackers and when so much is at stake.