Some groups will hack you AND also uninstall viruses emanating from other groups, or they will hack you and patch other flaws so that other malwares cannot take their spot. It's all game theory.
"SCHWIRTZ: What DarkSide does is they're a ransomware creator. So they create the program that is uploaded into a victim's computer system that locks down their data. But what they do is they basically contract out to these affiliates who are other hackers. And these are the people that are responsible for actually penetrating the victim's computer services. And what they do is operate basically on a subscription service. You, as an affiliate, can sign on to DarkSide services, in which case you get access to their malware, their ransomware to use for a fee that operates on a sliding scale depending upon the size of the ransom."
https://www.npr.org/2021/06/10/1005093802/inner-workings-of-...
I think these negotiations are fine, if you're just buying time to gather your backups; I've assumed the payouts were made by insurance companies, so go ahead - buy a zero-value promise from a gang of crooks, if you want.
But your org has been rooted (at best, you can't prove it hasn't). Compromised systems can't be really be cleaned, they have to be reinstalled from scratch, if you want to have confidence in them.
And an attack can be stored in data - which you're about to restore from backup. That's a problem I have faced, and I chose to ignore that threat. No choice - I didn't know how to address it then, and I still don't now.
My half-baked opinions about ransomware are largely based on watching this documentary: https://www.bbc.co.uk/programmes/w172wx9056p6bd6
I'm curious how one would enforce that. From the fact that the ransom got paid in the first place, we can establish that there's no legal body that's able and willing to exercise any authority over the ransomware group. So it's not like you can sue them for breach of contract.
Perhaps you can rely on the honor system? Though, given this is a group of professional extortionists we're talking about, if you choose to go that route, you may be at elevated risk of getting what you deserve.
If a ransomware group has a reputation of not actually delivering the unlock upon payment, or of re-infection shortly afterwards, the decision to pay them becomes harder to defend.
All the good guys shut up, and so you're left with the criminals who then exploit the flaws instead.