This article is part of a three-part Trustwave series examining the efficacy of recently implemented and proposed government regulations requiring organizations victimized by ransomware to report if they make a ransom payment.