Most companies hit by ransomware go quiet and quietly pay. Hydro did the opposite of both — and the applause obscured how uneven the recovery underneath actually was.
Pairs with the Crisis Response Playbook — a ready-to-use strategy tool. Included in the Crisis Response Casebook →
Around midnight in Oslo on March 19, 2019, files started locking themselves. According to Bloomberg Businessweek's reconstruction, it took staff at Norsk Hydro's operations center in Hungary roughly two hours to grasp what was happening, and by the time the network was pulled fully offline, 500 servers and 2,700 PCs had been turned into paperweights.7 A Bitcoin ransom note sat on the screens.5 What Hydro did next is now taught as the textbook response: refuse the ransom, run the plants by hand, and tell the whole world in real time. Most of that is true. All of it is more complicated than the poster version.
The official story is that Hydro dramatically rejected a ransom demand mid-negotiation, flipped its aluminium plants to manual operation, and emerged the industry gold standard. The more precise version is quieter and stranger. Hydro never opened negotiations at all. Only part of the company could run by hand. And the recovery cost was not a number — it was a number that kept moving for months.
“There was never any intention of paying the ransom — attackers who are paid will likely just come back for more.”8
The decision that was made before there was a decision to make: not a ransom rejected mid-call, but a door that was never opened
The most retold beat of this story — the bold executive slamming down the phone on the hackers — did not happen. Hydro's own security officer has been plain about it: there was never any intention of paying, because the logic of paying is a trap. Pay once and you have advertised yourself as a company that pays, and the attackers, or the next ones, come back.8 The distinction matters more than it looks. A rejected offer is a negotiation you win; a refusal to negotiate is a policy you had before the attack ever started. The day after the breach, CFO Eivind Kallevik called it 'quite severe' and said flatly the company had no plans to pay, pointing to its backup systems as the route out.2 The confidence in that press conference was not improvised bravado. It was the sound of a firm that had already decided the shape of its answer, and now only had to survive the question.
Why 'ran its plants by hand' is a half-truth: some of the company never needed to go manual, and some of it couldn't
Here is the part the gold-standard framing sands off. Hydro is not one machine; it is five very different businesses, and LockerGoga hit them unevenly. On the day, Hydro's own operational update showed Energy and Bauxite & Alumina running normally and largely untouched. Primary Metal — the smelters that cannot simply be switched off without ruining the pots — kept going, but with a higher degree of manual operation. And Extruded Solutions and Rolled Products, the more IT-dependent downstream businesses, suffered production challenges and temporary stoppages at several plants.1 So the celebrated 'manual operations' fix was concentrated where the process is continuous and the muscle memory exists. Where the work depended on the very systems the malware ate, there was no manual mode to fall back to — those plants did not go analog, they just stopped. The heroic image of the whole company reverting to clipboards and hand-signals is really the story of one division doing so while another simply went dark.
| Business | State during the attack | Could it fall back to manual? |
|---|---|---|
| Energy | Running normally, largely unaffected | Didn't need to |
| Bauxite & Alumina | Running normally, largely unaffected | Didn't need to |
| Primary Metal | Running with a higher degree of manual operation | Yes — this is the 'ran it by hand' story |
| Extruded Solutions | Production challenges, temporary stoppages | No — plants stopped |
| Rolled Products | Production challenges, temporary stoppages | No — plants stopped |
The real move was refusing to control the story: webcasts, open control rooms, and a bill Hydro kept revising upward in public
If the operational recovery was patchy, the communications strategy was the genuinely radical decision — and it was made in the same crisis meeting as the no-pay call. Hydro chose to bring in Microsoft's incident-response team and, crucially, to communicate openly. Then it did the thing almost no breached company does: it held daily press conferences at its Oslo headquarters, ran regular webcasts, posted updates to Facebook, stood up a new website mid-crisis, and let journalists physically into its operations control rooms.3 The insight buried here is that transparency was not softness — it was leverage. A company that has already refused to pay has nothing left to protect by hiding, and everything to gain by controlling the narrative before the attackers or the rumor mill can. Every daily update was a small act of denying the hackers the one thing ransomware actually sells: not stolen data, but fear and confusion. Hydro turned its own worst week into a public demonstration that a well-backed-up company can say no.
And this is where the transparency cuts both ways, honestly. The same openness that earned Hydro its reputation also meant the public watched the bill inflate in slow motion. Per Reinsurance News's tally of Hydro's own shifting disclosures, the estimate started at roughly $41 million for the first quarter, rose to about $52 million in April, hit some $69 million by early June, and settled into a revised $64-75 million range for the first half of 2019 alone.4 Nearly all of the deepest damage sat in one place — Extruded Solutions carried $29-35 million of the Q1 hit by itself.4 Articles that quote '$40 million' or '$75 million' as the cost of the attack aren't necessarily contradicting each other — they may simply be different snapshots of the same rising estimate, tallied at different points by different outlets with different scopes. There was never one settled total, only a company reporting the truth as fast as it learned it — which is exactly what transparency looks like when the news keeps getting worse.
Wasn't it just a company with good backups getting lucky?: the honest objection is that policy and preparation aren't the same as performance
The fair objection is that Hydro's playbook only worked because it had the backups to make it work — refuse the ransom by all means, but a company without recoverable systems is refusing to survive. True, and Kallevik said as much: the backups were the plan.2 But that concedes the actual lesson rather than undercutting it. The 'gold standard' label itself is worth reading skeptically — it's a phrase that stuck through trade-press retellings of the response, not a certification any law-enforcement or regulatory body ever issued. What Hydro deserves credit for is narrower and more durable than the myth: it had decided its ransom policy before the attack, it had the backups to honor that policy, and it had the nerve to broadcast the whole ugly recovery instead of managing it in the dark. The attack forced Hydro's plants on two continents to halt production for almost a week and cost it more than $50 million; the attackers were later identified in a coordinated law-enforcement action.6 Hydro did not escape the damage. It escaped the second attack — the loss of control that comes from paying, hiding, and hoping.
The strongest thing about Hydro's response happened in the calm before the alarm: the no-ransom stance was a standing policy, not a heroic in-the-moment choice, and the backups that made refusal survivable were already in place. When the attack came, leadership only had to execute a decision, not agonize over one. The lesson generalizes past ransomware. The crises that break companies are rarely the ones nobody imagined; they're the ones where the answer had to be invented under maximum stress. Pre-commit to the hard call — no ransom, full disclosure, no cover-up — while you can still think clearly, and back it with the capability that makes the commitment real. A policy without backups is a bluff, and attackers, like everyone else, can smell a bluff. Just don't confuse a clean policy with a clean recovery: parts of Hydro still went dark for a week, and the bill still climbed for months.
Norsk Hydro's real innovation was not that it ran aluminium plants by hand — some divisions couldn't, and some never had to. It was that it treated the attack as something to be witnessed rather than survived in silence. Ransomware is a business built on darkness: the darkness of a locked screen, a hushed boardroom, a quiet wire transfer. Hydro turned on every light in the building, invited the press into the control room, and let the whole world watch it refuse. The ransom note asked for Bitcoin. What the attackers actually wanted was the silence — and that was the one thing Hydro decided, in advance, never to give them.
When a company chooses how to be seen under fire
Crisis Response Playbook
A playbook for a crisis already in motion: who decides, which plays fire on which trigger, and what gets said to whom. It replaces panic and the all-hands meeting with a pre-agreed sequence each person can run alone. Blank to pre-load before a crisis hits; filled as the worked example reconstructing the plays the story's team ran — and the ones they should have.
Included, filled and blank, in the Crisis Response Casebook. See the set → · Preview the blank →
Sources
Where this comes from — the filings, records, and reporting behind it.
- 1Norsk Hydro's own March 19, 2019 statement: the company was hit by an extensive cyber-attack, isolated all plants and operations and switched to manual operations 'as far as possible,' with Energy and Bauxite & Alumina running normally, Primary Metal running with a higher degree of manual operation, and Extruded Solutions/Rolled Products experiencing production challenges and temporary stoppages at several plants.
- 2At a press conference the day after the attack, Norsk Hydro CFO Eivind Kallevik said the attack was 'quite severe' but that the company had no plans to pay any ransom, citing good backup systems as its planned route to recovery; this was confirmed to Reuters the same week.
- 3Hydro executives made three swift decisions in the crisis meeting — pay no ransom, bring in Microsoft's DART incident-response team, and communicate openly — and then held daily press conferences at Oslo headquarters, hosted regular webcasts, posted updates to Facebook, launched a new company website mid-crisis, and let journalists into operations control rooms.
- 4Financial-impact series as disclosed by Norsk Hydro in its own quarterly reports: Q1 2019 overall impact $35-41m (NOK 300-350m), of which $29-35m (NOK 250-300m) was in Extruded Solutions; Q2 2019 impact $29-35m (NOK 250-300m), of which $17-23m (NOK 150-200m) was Extruded Solutions — bringing the total expected H1 2019 hit to roughly $64-75m (NOK 550-650m), up from an initial $41m estimate, a $52m estimate in April, and a $69m estimate in early June.
- 5The LockerGoga ransomware infection, which encrypted files on desktops, laptops and servers and posted a Bitcoin ransom note, affected all roughly 35,000 Norsk Hydro employees across the 40 countries in which the company operates.
- 6Norway's National Criminal Investigation Service (Kripos) and Europol confirmed that individuals arrested in a coordinated law-enforcement action were responsible for the Norsk Hydro attack, which forced the company's plants across two continents to halt production for almost a week and cost Norsk Hydro more than $50 million; the ransomware ring also deployed MegaCortex and Dharma alongside TrickBot and post-exploitation tools.
- 7Per Bloomberg Businessweek's reconstruction, the infection began around midnight Oslo time on March 19, 2019, took roughly two hours for staff at Hydro's Hungary operations center to recognize, and by the time the network was taken fully offline, 500 of Hydro's servers and 2,700 of its PCs had been rendered useless.
- 8Norsk Hydro's corporate information security officer said there was never any intention of paying the ransom, on the reasoning that the attackers would likely return for more if paid; the company instead relied on cybersecurity experts and its backup systems.
More like this — beyond Norsk Hydro
New Strategically analyses as they publish: the defining moves in business, checked against the record. No noise, and one click to leave.