Negotiation in the DARK!

Negotiation in the DARK!

A Core Focus at Next IT Security | Stockholm 2026

Introduction

Cyber incidents do not always end when an attacker gains access to an organisation’s systems. In many high-impact incidents, organisations may also face a complex and highly pressured negotiation with cybercriminals, particularly during ransomware and extortion attacks. When critical systems are unavailable, sensitive information is at risk, and business operations are under pressure, every decision can have significant operational, financial, legal, and reputational consequences.

Cybercrime negotiation sits at the intersection of cybersecurity, crisis management, psychology, intelligence, communication, and business decision-making. Negotiators must operate in an environment where information is incomplete, time is limited, trust cannot be assumed, and the opposing party may deliberately manipulate emotions and create pressure.

Recognising the growing importance of human decision-making during major cyber incidents, Negotiation in the DARK!, presented by Geert Baudewijns, Cybercrime Negotiator, has been identified as a compelling focus at Next IT Security | Stockholm 2026. The session will explore what happens when organisations are forced to communicate with cybercriminals, how negotiation dynamics work during ransomware incidents, and how preparation can help organisations make better decisions when operating under extreme pressure.


Why this matters now

Ransomware and extortion attacks have evolved into complex criminal operations designed not only to disrupt systems but also to create maximum pressure on their victims. Attackers may combine encryption, data theft, public exposure threats, operational disruption, and carefully timed communications to force organisations into making rapid decisions.

For security leaders, this creates a difficult situation. Technical teams may be working to contain an intrusion and restore systems while executives must simultaneously assess business continuity, legal obligations, communications, financial exposure, and the potential consequences of engaging with an attacker.

Negotiation can therefore become part of a broader incident-response strategy. It requires organisations to understand who they are communicating with, what leverage the attacker may have, what information should or should not be disclosed, and how to avoid making decisions based solely on fear or urgency.

Preparation is critical. Organisations that establish clear roles, escalation procedures, decision-making frameworks, and crisis-management processes before an incident are better positioned to respond calmly when an attack occurs.

For these reasons, Next IT Security | Stockholm 2026 will examine the human and strategic dimensions of cybercrime negotiation and explore how organisations can prepare for the difficult decisions that may arise during a major cyber incident.


Understanding the Psychology Behind Cybercrime Negotiation

Cybercriminals understand that ransomware attacks are not purely technical events. They are also psychological operations. Attackers seek to create uncertainty, urgency, fear, and financial pressure, often attempting to influence how victims make decisions.

A negotiation may therefore involve more than simply discussing a ransom demand. Organisations may need to interpret the attacker’s communication style, assess credibility, understand the incentives of the criminal group, and determine whether claims about stolen or encrypted data can be verified.

The negotiating environment is inherently asymmetric. Attackers may know what they have compromised while the victim organisation is still investigating the incident. This information imbalance can make it difficult to determine what is genuine, what is exaggerated, and what is deliberately designed to manipulate the victim.

Understanding these dynamics can help organisations avoid reacting impulsively. A structured negotiation process can create time to gather intelligence, validate claims, coordinate internal stakeholders, and evaluate available options.

Impact on Next-Generation IT Security

Organisations are increasingly recognising the importance of:

  • Understanding the psychology and tactics used by cybercriminals.
  • Separating emotional pressure from objective decision-making.
  • Validating attacker claims wherever technically possible.
  • Establishing clear internal roles during negotiations.
  • Coordinating negotiation activity with incident-response teams.

At Next IT Security | Stockholm 2026, Geert Baudewijns will explore the realities of communicating with cybercriminals and examine how organisations can approach negotiations with greater structure, awareness, and strategic discipline.


Making Decisions When Every Minute Matters

During a ransomware incident, time can become one of the most powerful sources of pressure. Critical systems may be unavailable, employees may be unable to work, customers may be affected, and leadership teams may be waiting for answers that security teams do not yet have.

Attackers can exploit this uncertainty by imposing deadlines or threatening additional consequences. Under these conditions, organisations can be tempted to make decisions before they have enough information to understand the situation fully.

Effective crisis decision-making requires a balance between urgency and discipline. Organisations need to understand which decisions must be made immediately, which can wait, and which require input from legal, executive, technical, insurance, communications, or law-enforcement stakeholders.

Negotiation can also generate valuable time. Rather than viewing communication with attackers as a simple yes-or-no decision, organisations can use a structured approach to gather information, assess credibility, and understand the attacker’s objectives while continuing their broader response activities.

Impact on Next-Generation IT Security

Organisations are strengthening crisis decision-making by:

  • Establishing predefined escalation and decision-making processes.
  • Identifying who has authority to make critical incident decisions.
  • Coordinating cybersecurity, executive, legal, and communications teams.
  • Developing clear procedures for high-pressure communications.
  • Using intelligence and technical evidence to support negotiation decisions.

At Next IT Security | Stockholm 2026, the discussion will examine how organisations can maintain control over decision-making even when attackers attempt to dictate the pace and terms of an incident.


Separating Fact, Bluff, and Manipulation

One of the most difficult elements of cybercrime negotiation is determining whether an attacker’s statements are accurate. Criminal groups may claim to have stolen vast quantities of data, obtained privileged access, or compromised additional systems. Organisations must assess these claims while investigations are still developing.

This makes intelligence gathering a central component of negotiation. Technical teams can investigate affected systems, review logs, identify compromised accounts, examine data exposure, and determine what attackers may realistically have accessed. At the same time, negotiators can analyse the information provided by the attacker and look for inconsistencies or evidence that can be independently verified.

The objective is not simply to challenge an attacker. It is to establish a reliable picture of the situation so that decision-makers can understand their actual exposure rather than responding to unverified threats.

This distinction is particularly important when attackers use pressure tactics. A deadline or threat can create an emotional reaction, but effective crisis management requires decisions to be based on evidence, risk, and clearly defined objectives.

Impact on Next-Generation IT Security

Security teams are increasingly focusing on:

  • Verifying claims made by attackers.
  • Combining technical investigation with threat intelligence.
  • Identifying what information has actually been compromised.
  • Assessing the credibility of criminal communications.
  • Maintaining objective decision-making under psychological pressure.

The session at Next IT Security | Stockholm 2026 will highlight how intelligence and structured analysis can help organisations distinguish between genuine risk, uncertainty, and deliberate manipulation during cybercrime negotiations.


Negotiation as Part of a Wider Incident-Response Strategy

Cybercrime negotiation cannot operate independently from the rest of an incident response. While communication with an attacker may be taking place, security teams still need to contain the compromise, preserve evidence, investigate the intrusion, protect unaffected systems, and begin recovery planning.

This creates a need for close coordination between negotiators and technical response teams. Information gathered during negotiations may influence investigative priorities, while technical findings may affect the strategy used during communications with the attacker.

Leadership must also consider wider organisational consequences. Customers, employees, partners, regulators, insurers, legal advisers, and other stakeholders may all have an interest in how an incident is handled.

A coordinated approach helps prevent negotiation from becoming an isolated activity. Instead, it becomes one component of a broader crisis-management strategy designed to protect the organisation’s interests while supporting containment, investigation, recovery, and continuity.

Impact on Next-Generation IT Security

Organisations are strengthening incident response by:

  • Integrating negotiation into broader cyber incident-response planning.
  • Establishing communication between negotiators and technical responders.
  • Coordinating executive, legal, security, and communications functions.
  • Preserving evidence and investigative integrity during an incident.
  • Aligning negotiation decisions with business continuity and recovery objectives.

At Next IT Security | Stockholm 2026, experts will examine how negotiation can fit into a coordinated response model and how organisations can avoid treating communication with attackers as a standalone activity.


Preparing Before the Ransomware Incident Happens

The most effective time to prepare for cybercrime negotiation is before an organisation is under attack. Waiting until systems are encrypted and executive teams are facing a ransom deadline leaves little opportunity to establish processes, responsibilities, and decision-making structures.

Preparation can include developing ransomware response plans, defining escalation paths, identifying internal and external experts, establishing communication procedures, and conducting realistic exercises. Organisations can also consider how they would evaluate operational impact, data exposure, recovery options, and different response scenarios.

Tabletop exercises can be particularly valuable because they allow leadership teams to experience the uncertainty and pressure of a major cyber incident without the consequences of a real attack. These exercises can expose gaps in authority, communication, information sharing, and crisis decision-making.

Preparation does not guarantee that an organisation will avoid difficult decisions. It does, however, provide a stronger foundation for making those decisions deliberately rather than reacting to pressure.

Impact on Next-Generation IT Security

Organisations are increasingly preparing for cybercrime negotiations by:

  • Including ransomware scenarios in incident-response exercises.
  • Defining roles and decision-making authority in advance.
  • Establishing relationships with relevant external specialists.
  • Developing crisis communication procedures.
  • Testing executive decision-making under realistic conditions.

Next IT Security | Stockholm 2026 will explore how preparation and realistic exercises can help organisations build confidence and maintain control when faced with the uncertainty of a live cybercrime negotiation.


Learning from Real-World Cybercrime Negotiations

Every major ransomware incident provides lessons about attacker behaviour, organisational decision-making, communication, and crisis response. Examining these situations can help security leaders understand how negotiations develop and where organisations commonly encounter difficulties.

Real-world cases can demonstrate how attackers attempt to establish credibility, create urgency, exploit uncertainty, and influence the victim’s perception of available options. They can also reveal how organisations respond when technical investigations, business pressures, legal considerations, and executive expectations collide.

The most valuable lessons often extend beyond the negotiation itself. An incident can reveal weaknesses in identity management, segmentation, backup strategies, monitoring, incident response, crisis communication, or executive preparedness.

Analysing these experiences allows organisations to turn individual incidents into broader improvements in resilience. The objective is not simply to understand how a negotiation was handled, but to identify what could have been done differently before, during, and after the attack.

Impact on Next-Generation IT Security

Organisations can use real-world cases to:

  • Understand common cybercriminal negotiation tactics.
  • Identify weaknesses in crisis decision-making.
  • Improve ransomware and extortion response plans.
  • Strengthen collaboration between technical and executive teams.
  • Translate incident lessons into measurable security improvements.

At Next IT Security | Stockholm 2026, Geert Baudewijns will bring practical insight into the realities of cybercrime negotiation, helping attendees understand the human dynamics behind some of the most challenging moments in cybersecurity.


Building Confidence in the Face of Uncertainty

Cybersecurity leaders cannot always control when an attack occurs, what attackers demand, or how an incident develops. They can, however, control how prepared their organisation is to respond.

Confidence during a cybercrime negotiation does not come from having every answer. It comes from having a process for finding those answers, understanding available options, communicating clearly, and making decisions based on evidence rather than panic.

This requires a combination of technical capability, crisis leadership, intelligence, communication, and organisational preparation. It also requires recognising that cyber incidents affect people as much as systems. Under pressure, decision-makers need reliable information, clear responsibilities, and the confidence to challenge assumptions.

By developing these capabilities before an incident, organisations can reduce the risk that attackers will dictate the terms of the crisis.

Impact on Next-Generation IT Security

A resilient approach to cybercrime negotiation focuses on:

  • Building decision-making confidence before an incident.
  • Creating clear processes for managing uncertainty.
  • Combining technical intelligence with human expertise.
  • Maintaining control over internal communications and escalation.
  • Preparing leadership teams for high-pressure cyber events.

At Next IT Security | Stockholm 2026, the focus will be on the practical realities of managing cybercrime negotiations and developing the capabilities required to make sound decisions when conventional security processes are under extreme pressure.


Looking Ahead

As ransomware, extortion, and cybercrime continue to evolve, organisations must prepare not only for technical attacks but also for the human and strategic challenges that follow them. A successful response may require security teams to investigate an intrusion while executives make high-impact decisions and negotiators communicate with an adversary operating under very different incentives.

The future of cyber resilience will therefore depend on more than stronger technology. Organisations will need effective preparation, intelligence-driven decision-making, crisis leadership, tested response procedures, and a clear understanding of how attackers attempt to influence their victims.

Negotiation in the DARK!, presented by Geert Baudewijns, Cybercrime Negotiator, will provide attendees at Next IT Security | Stockholm 2026 with a closer look at what happens when cybersecurity moves beyond firewalls, detection systems, and incident-response playbooks and enters the uncertain world of direct communication with cybercriminals.

The session will offer valuable perspectives on the psychology of cybercrime, decision-making under pressure, attacker manipulation, intelligence gathering, and the importance of preparation. Ultimately, effective cybercrime negotiation is not about having a perfect answer in an impossible situation. It is about creating enough clarity, structure, and control to make the best possible decision when the organisation is operating in the dark.

APPLY FOR ACCESS

Next IT Security

Apply for access to Europe’s leading conference for c-suite cybersecurity executives.

Session reserved
05:00
Your registration session is active. Complete your application within the reserved time.
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Attendance by invitation only
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. October 22, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 12, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · DACH
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. November 26, Frankfurt.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Nordics
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. March 11, Stockholm.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials
Next IT Security is funded by the partners of each edition. By taking part you accept that the confirmed partners of the edition you attend receive your name, job title, company, company switchboard number, business email address and LinkedIn profile, so that they can follow up on the subjects on the agenda. Your direct telephone number and your private email address are never shared. If you would rather not appear on the partner list, write to [email protected] and we will take you off it — you can still attend.
The box is not a condition of attending. How we handle your data is set out in our Privacy Policy and in our GDPR and Data Protection statement.
Next IT Security · Benelux
C-Suite Edition
€990 €0
Promo Code Applied ✓
/ Ticket
Tickets are exclusively reserved for C-level executives from end-user companies of IT security services. April 15, Amsterdam.
  • Full-day access
  • 1:1 executive meetings
  • Roundtable sessions
  • Networking dinner
  • All speaker sessions
  • Post-event materials