Coveware vs. GroupSense vs. Arete: Ransomware Negotiation Firms Compared

Proactive Security for the AI Era
NodeZero continuously and autonomously pentests infrastructure, identity, cloud, and now web applications, chaining weaknesses across every domain the way real attackers do. Every finding ships with replayable proof showing exploitable business impact, not theoretical risk.
A generic incident response retainer usually names a forensics firm as the lead vendor and treats ransomware negotiation as a line item somewhere inside that contract. Specialized negotiation firms flip that emphasis: negotiating with the threat actor, screening for sanctions exposure, and managing the payment logistics is the core service, not an add-on. Coveware, GroupSense, and Arete are three firms that show up repeatedly in this specialized category, and incident response leads and legal counsel researching a pre-incident retainer need to understand how they actually differ before a live extortion event forces the choice. This is not a question with a single right answer. It depends on whether an organization already has a DFIR firm on retainer, how much in-house sanctions and OFAC-screening rigor legal counsel wants documented, and whether leadership wants access to a firm's own payment-trend data or prefers a threat-intelligence-first read on the specific actor at the keyboard.
At a Glance: How the Three Firms Compare
Public information on all three firms is uneven. None of them publish a rate card, and case-level outcome statistics are not independently audited by a third party. The comparison below reflects what is publicly documented about each firm's model, not a claim about which negotiates better outcomes.
Coveware (Westport, Connecticut; founded 2018; acquired by Veeam Software in 2024)
A negotiation-and-recovery specialist that pairs with a separate forensics firm rather than performing forensics itself. Best known publicly for its own quarterly ransomware marketplace report, which tracks average and median ransom demands, payment rates, and data-exfiltration-only trends. Now operates as part of Veeam's ransomware resilience and recovery portfolio, which changes its referral relationships with backup and recovery vendors going forward.
GroupSense (Arlington, Virginia; digital risk protection and threat intelligence vendor)
A threat-intelligence firm whose ransomware negotiation service is built on its own dark web and closed-source monitoring rather than a standalone negotiation desk. The pitch is that intelligence on a specific threat actor group's identity, prior victim behavior, and decryption reliability should inform the negotiation strategy directly, not sit in a separate report.
Arete (multiple US offices; full-scope digital forensics and incident response firm)
The largest and most vertically integrated of the three. Arete performs forensics, negotiation, and recovery under one engagement rather than requiring a client to bring a separate DFIR firm, and it has a long-standing presence on major cyber insurance carrier panels. That integration is the tradeoff: clients get a single vendor relationship instead of a specialist paired with their existing IR firm.
How Each Firm's Negotiation Model Actually Works
The surface-level service, talking to the threat actor and trying to bring the demand down, looks similar across all three firms. The mechanics behind that conversation differ in ways that matter once an incident is live.
Coveware's process centers on threat-actor profiling built from its own case history: because the firm has handled a large volume of ransomware cases across many different operator groups, it can often tell a client early whether a specific group has a track record of honoring payment (providing a working decryptor and not re-extorting) or a track record of taking payment and disappearing or leaking data anyway. That case-history angle is the same asset that feeds its public quarterly report.
GroupSense's process leans on its threat-intelligence platform first. Because the firm already runs dark web and closed-source monitoring as its primary business line, it can often identify which specific criminal group or affiliate is behind an attack, cross-reference that group against known sanctions designations and prior extortion behavior, and build the negotiation posture around that intelligence rather than around negotiation case volume alone.
Arete's process is the one most likely to happen inside a single, unified engagement: the same firm that is doing memory forensics and log analysis to scope the intrusion is also the one at the negotiating table, which can shorten the handoff between scoping and negotiation but also means a client is trusting one vendor for both jobs instead of a specialist plus a forensics firm checking each other's work.
Briefings like this, every morning before 9am.
Threat intel, active CVEs, and campaign alerts, distilled for practitioners. 50,000+ subscribers. No noise.
Also compare in incident response
OFAC and Sanctions-Screening Exposure: The Differentiator That Actually Matters
This is the point legal counsel should press hardest on, and it is the reason a specialized negotiation firm is not interchangeable with a general IR retainer. The Treasury Department's Office of Foreign Assets Control has advised for years that facilitating a ransomware payment to a sanctioned person or entity, or to a group operating out of a comprehensively sanctioned jurisdiction, can itself create civil liability under a strict-liability sanctions regime, regardless of whether the victim organization knew the counterparty was sanctioned. OFAC's advisory explicitly calls out incident response and cyber insurance firms as parties whose due diligence practices factor into that liability exposure, and it treats a documented, good-faith compliance program (reporting to law enforcement, engaging OFAC before payment when a match is suspected) as a mitigating factor in any enforcement decision.
What this means in practice is that a negotiation firm's sanctions-screening process is not a compliance footnote, it is close to the core product. Coveware and GroupSense both describe screening the threat actor or their wallet infrastructure against sanctions lists and known-actor intelligence before facilitating any payment, though neither publishes the specifics of that screening methodology, its false-negative rate, or how it is documented for a client's legal file. Arete's due diligence approach has historically included direct engagement with federal law enforcement, cross-checking threat-actor identity and infrastructure with the FBI as part of building the record, according to public statements from the firm's leadership in earlier ransomware negotiation coverage.
The honest takeaway: all three firms claim to perform sanctions due diligence, none of them publish an auditable methodology, and legal counsel should treat the specifics of that screening process, not the marketing language around it, as a required discovery item during vendor selection. Ask each firm directly how a sanctions match is identified, who signs off before a payment is made despite ambiguity, and what documentation the client receives afterward for their own OFAC compliance file.
Data and Analytics: Coveware's Public Reporting Is a Real Differentiator
Coveware's quarterly ransomware marketplace report is the one place among these three firms where a genuinely public, recurring data product exists. The report tracks metrics like average and median ransom payment, the share of victims who pay at all, and the split between encryption-only, data-exfiltration-only, and combined extortion cases, drawing on the firm's own negotiation case volume. That gives a prospective client something concrete to evaluate before signing a retainer: years of published trend data that can be checked against other public sources (law enforcement reporting, cyber insurance claims data) for directional consistency, even though the underlying case-level data is proprietary and not independently audited.
GroupSense's public data output leans toward threat-actor and victim-count tracking tied to its dark web monitoring rather than payment-outcome statistics, which is a different kind of usefulness: it tells a prospective client more about which ransomware groups are currently active and targeting which sectors than about typical payment amounts or negotiation outcomes.
Arete does not appear to publish a comparable recurring public dataset. Its data advantage, to the extent one exists, is internal to the firm's own case history and is not offered as a standalone public research product the way Coveware's report is. That does not make Arete's negotiation experience less real, but it does mean a prospective client cannot independently sample Arete's track record the way they can skim several quarters of Coveware's published numbers before ever picking up the phone.
Pricing and Fee Structure: Stated Plainly
None of these three firms publish a rate card, and that is worth saying directly rather than guessing at numbers. What is publicly documented is the general shape of the fee model rather than specific rates.
Coveware is described in third-party reporting as charging a project or success-based fee for negotiation and recovery work rather than a published hourly rate, with actual pricing quoted per engagement. Public information does not specify whether that success fee is structured as a flat amount, a percentage of the ransom reduction achieved, or a percentage of the final payment amount, and prospective clients should get that structure in writing before an incident rather than assuming a percentage-of-ransom model applies by default.
GroupSense and Arete do not have similarly documented public fee structures available from the sources reviewed for this piece. Both firms, like most incident response vendors, appear to negotiate engagement terms directly with each client, and neither publishes example pricing. Any specific percentage or flat-fee figure attributed to either firm without a citable public source should be treated as unverified. The practical fix is the same for all three: get a written fee-structure term sheet during the pre-incident retainer conversation, not during an active extortion event when negotiating leverage over the vendor's own fee is at its weakest.
Strengths and Limits, Firm by Firm
No single firm wins this comparison outright. Each has a strength that maps to a specific buying scenario, and a corresponding limit worth weighing against it.
Coveware strengths and limits
Strength: the deepest public data trail of the three, which makes it easier to evaluate before ever engaging, plus a case-history base broad enough to speak to many different ransomware operator groups' payment reliability. Limit: it is not a forensics firm, so it needs to be paired with a separate DFIR vendor, adding a second vendor relationship to manage during an incident. The Veeam acquisition also means its long-term positioning may shift toward backup and recovery bundling rather than standing alone as a neutral negotiation specialist.
GroupSense strengths and limits
Strength: negotiation strategy grounded in the firm's own threat-intelligence platform, which can be genuinely useful for correctly identifying the actor behind an attack and assessing sanctions and reliability risk from an intelligence angle rather than a case-volume angle alone. Limit: negotiation is one service line within a broader digital risk protection business rather than the firm's sole focus, and like Coveware it typically needs a separate forensics partner for full incident scoping.
Arete strengths and limits
Strength: a single vendor for forensics, negotiation, and recovery, which can reduce handoff friction and is a natural fit for organizations that want one incident response retainer rather than a lead IR firm plus a negotiation specialist. Broad presence on cyber insurance carrier panels also makes it a common default when a policy already names an approved vendor list. Limit: less independently verifiable public data on negotiation outcomes specifically, since its published presence emphasizes full-scope IR rather than a standalone negotiation research product.
Best-Fit Guidance by Organization Profile
The right choice depends heavily on what an organization already has in place and how it weighs vendor consolidation against specialist depth.
Already has a DFIR firm or MSSP retainer and just needs a negotiation specialist
Coveware or GroupSense both fit this profile better than Arete, since neither requires displacing an existing forensics relationship. Choose Coveware if the published payment-trend data and broad case-history angle matter most to legal and finance stakeholders; choose GroupSense if the organization values a threat-intelligence-led read on the specific actor group over aggregate payment statistics.
Wants a single vendor for the entire incident lifecycle
Arete's integrated forensics-plus-negotiation model is the more natural fit here, particularly for organizations whose cyber insurance policy already names Arete on an approved panel, since using a panel vendor can simplify claims reimbursement.
Public-sector or regulated entity with jurisdiction-specific payment restrictions
Any of the three firms needs to be briefed explicitly on jurisdiction-specific legal constraints before an incident, not during one. States that have enacted public-sector ransomware payment bans change what a negotiation firm can legally do on a client's behalf, in some cases restricting negotiation communication itself, not just the payment. See our related coverage on [the state-by-state ransomware payment ban patchwork](/blog/ransomware-payment-ban-state-legislation-2026) for which statutes actually restrict payment versus communication today.
High risk tolerance for sanctioned-actor exposure is low (regulated industry, public company, government contractor)
Push hardest on the OFAC screening question with all three firms before signing anything. An organization with heightened sanctions exposure sensitivity should ask for the screening methodology in writing and involve outside sanctions counsel in reviewing it, rather than relying on any firm's general assurance that screening happens.
A Pre-Incident Retainer Checklist
Selecting a negotiation firm before an incident, rather than during one, is the entire point of this comparison. The checklist below is what to work through during that calmer pre-incident window.
Confirm how the firm's sanctions-screening process works and get it in writing
Ask specifically how a threat actor or wallet is checked against OFAC's Specially Designated Nationals list, what happens when the result is ambiguous, and what documentation the client receives for their own compliance file.
Get the fee structure in writing before an incident, not during one
Confirm whether the model is a flat project fee, a success fee tied to ransom reduction, or another structure, and confirm it in the master services agreement rather than negotiating fee terms under incident pressure.
Decide whether this firm needs to be paired with a separate DFIR vendor
Coveware and GroupSense typically expect a companion forensics firm; confirm that pairing and the handoff process between the two vendors before an incident, including who owns communication with the threat actor.
Check the firm against your cyber insurance policy's approved vendor panel
A negotiation firm outside the policy's named panel may create reimbursement friction or require carrier pre-approval mid-incident. Confirm this with the broker during the retainer conversation.
Map the firm's process against any payment restrictions in your operating jurisdictions
Public-sector entities and their vendors and contractors need the negotiation firm briefed on jurisdiction-specific statutes that may restrict payment or communication with the threat actor entirely.
Run a tabletop exercise that actually includes the negotiation firm, not just internal IR
A negotiation firm's process is easiest to evaluate honestly in a low-stakes tabletop rather than for the first time during a live extortion event.
The bottom line
Coveware, GroupSense, and Arete are all credible specialized ransomware negotiation firms, but they are not interchangeable. Coveware offers the deepest public data trail and a case-history-driven negotiation approach, now inside Veeam's ownership. GroupSense builds negotiation strategy on its own threat-intelligence platform. Arete offers the most vertically integrated single-vendor model, spanning forensics through recovery. None of the three publishes an auditable sanctions-screening methodology or a public rate card, which means the real due diligence work, pinning down the screening process, the fee structure, and the DFIR pairing arrangement in writing, has to happen before an incident, during the calm of a pre-incident retainer conversation, not during a live extortion event when leverage over those terms is at its weakest.
Frequently asked questions
What is the difference between a ransomware negotiation firm and a general IR retainer?
A general incident response retainer usually leads with digital forensics, with negotiation as a smaller line item. A specialized negotiation firm like Coveware, GroupSense, or Arete makes negotiating with the threat actor, sanctions screening, and payment logistics its core service, and is often paired with a separate forensics vendor rather than replacing one.
Who owns Coveware now, and does that change its services?
Veeam Software acquired Coveware in 2024, folding its negotiation and recovery capabilities into Veeam's broader ransomware resilience portfolio. Coveware continues to publish its quarterly ransomware marketplace report, but organizations should expect its long-term positioning to lean toward integration with Veeam's backup and recovery products rather than staying a fully independent negotiation specialist.
Why does OFAC sanctions screening matter when choosing a negotiation firm?
OFAC has advised that facilitating a ransomware payment to a sanctioned person, entity, or comprehensively sanctioned jurisdiction can create civil liability under a strict-liability sanctions regime regardless of the victim's intent. A negotiation firm's screening process is close to the core product, not a compliance afterthought, so its methodology should be reviewed by counsel before an incident.
Do Coveware, GroupSense, or Arete publish their negotiation fees?
No. Coveware is described in third-party reporting as charging a project or success-based fee quoted per engagement rather than a published rate. GroupSense and Arete do not have a publicly documented fee structure from the sources reviewed. Organizations should get fee terms in writing during the pre-incident retainer conversation.
Does a state ransomware payment ban affect which negotiation firm I can use?
It can affect what any negotiation firm is legally permitted to do on a covered entity's behalf. Some enacted state statutes restrict not just payment but communication with the threat actor for public-sector entities, so the firm needs to be briefed on jurisdiction-specific restrictions before an incident.
Should I choose one firm for both forensics and negotiation, or use separate specialists?
Arete's integrated model handles both under one engagement, which can reduce handoff friction and fits organizations wanting a single vendor. Coveware and GroupSense are negotiation specialists that typically expect a companion DFIR firm, which suits organizations that already have a forensics vendor on retainer and want deeper negotiation-specific expertise layered on top.
Sources & references
- IncidentCost.com - Coveware Ransomware Cost 2026: Negotiation Fees & Payment Data
- urgentcomm / Dark Reading - Treasury Dept. Advisory Shines Spotlight on Ransomware Negotiators
- CB Insights - Compare Coveware vs CYPFER
- OFAC - Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments
- Veeam - Veeam Launches Most Complete Support for Ransomware with Acquisition of Coveware
Free resources
Critical CVE Reference Card 2025–2026
25 actively exploited vulnerabilities with CVSS scores, exploit status, and patch availability. Print it, pin it, share it with your SOC team.
Ransomware Incident Response Playbook
Step-by-step 24-hour IR checklist covering detection, containment, eradication, and recovery. Built for SOC teams, IR leads, and CISOs.
Get threat intel before your inbox does.
50,000+ security professionals read Decryption Digest for early warnings on zero-days, ransomware, and nation-state campaigns. Free, daily, no spam.
Unsubscribe anytime. We never sell your data.

Founder & Cybersecurity Evangelist, Decryption Digest
Cybersecurity professional with expertise in threat intelligence, vulnerability research, and enterprise security. Covers zero-days, ransomware, and nation-state operations for 50,000+ security professionals every morning.
