Ransomware is malicious software that encrypts an organization's data and demands payment for its return. For employers the distinctive problem is not just that systems stop working — it is that payroll stops working, and the obligation to pay employees does not pause while the systems are down.

Modern attacks also steal data before encrypting it, which turns an operational outage into a breach notification event involving the entire workforce's personal information.

Why payroll makes this worse for employers

Wage payment obligations are governed by law, not by system availability. An employer whose payroll platform is encrypted three days before payday still owes wages on the scheduled date, and in states with strict timing rules — California among them — late payment carries its own penalties.

That creates a specific planning requirement most incident response plans miss: a documented method of paying employees without the primary payroll system. Options include the payroll provider's own continuity arrangements, a manual run using the last known-good register, or advance payments trued up afterward. What matters is that the method exists on paper before it is needed, because working it out during an outage costs days the employer does not have.

Double extortion

Attackers now routinely exfiltrate data before encryption and threaten to publish it. For an employer that data is Social Security numbers, bank details, compensation, and often medical information for every employee.

This changes the calculus substantially. Even an organization with flawless backups that restores without paying still has a data breach: notification obligations, credit monitoring, regulatory exposure, and a workforce whose identifiers are in criminal hands. Backups solve the availability problem, not the confidentiality one.

It also means the decision about payment is not really about recovering files. It is about whether to pay for a promise not to publish — a promise from someone who has already lied.

How it gets in

The common entry points are unglamorous: a phishing message that captures credentials or delivers a loader, remote access exposed to the internet with weak or reused credentials, unpatched systems, and compromise at a vendor with network access.

Credential-based entry is the most frequent, which is why MFA on email and remote access does more to prevent ransomware than most dedicated security tooling.

Backups that actually work

Most organizations have backups. Far fewer have backups that survive a ransomware attack, because attackers specifically target them — they know that encrypting backups is what forces payment.

The properties that matter:

  • Offline or immutable copies that cannot be altered or deleted even with administrative credentials
  • Separate credentials from the production environment, so one compromised admin account cannot reach both
  • Tested restores, not just successful backup jobs. A backup nobody has restored from is a hypothesis.
  • Documented restore time, because "we have backups" means little if full recovery takes three weeks
  • Coverage of vendor-hosted data, which is frequently assumed to be someone else's problem

That last point matters for employers specifically. If the payroll and HRIS data sits with a vendor, the employer should know what the vendor's own continuity commitments are and what happens if the vendor is the one attacked.

The employment-law dimension

Beyond wages, an extended outage raises questions employers should think through in advance. Time records may be unavailable, which interacts with the obligation to maintain accurate records and to pay for all hours worked — where records are missing, disputes tend to resolve in the employee's favor. Exempt and non-exempt employees may need different treatment if work is unavailable. And communication to a workforce whose personal data was stolen has to be handled carefully and promptly.

Preparation that changes the outcome

  • MFA on email, remote access, and administrative accounts
  • Offline or immutable backups with tested restores
  • A documented method of paying employees without the primary system
  • A current inventory of what employee data exists and where, so the breach analysis can start immediately
  • An incident response plan naming individuals, with counsel and forensic support identified in advance
  • Encryption of employee data at rest, which affects notification exposure
  • Vendor continuity and notification commitments in contract

The decision about whether to pay should be made with counsel and law enforcement, not under pressure in the first hours — and there are sanctions considerations that make the question genuinely legal rather than purely commercial.

Employer's Guardian helps employers plan for payroll continuity and workforce communication around disruptive events through payroll management services.

This article provides general educational information, not legal, tax, or insurance advice. Engage qualified counsel immediately in the event of a ransomware incident.

Let's Talk! Schedule a Conversation

For additional information, pricing, and/or free consultation, contact us. We'd be happy to discuss your situation.

Contact Us Today!

Want a professional to walk you through your HR needs shopping list?

At Employer’s Guardian, our experts are here to help. We are happy to work with you to understand your HR needs. Get in touch—give us a call or fill out our online contact form and we’ll promptly get back to you!

Contact Us Today!