Who was responsible for the decision to pay/not pay?

Conduct Internet research and identify a company that was recently held for Cyber-ransom, of any kind.
Identify the company, why it was held ransom & what could/should have prevented it?
Did the company pay a ransom?
Who was responsible for the decision to pay/not pay?
Was the decision to pay ethical? (To pay or not to pay)