Most of these "ransomware" attacks have to do with holding data hostage in the sense that the owner of the data can't get to it because it has been encrypted by the attacker, not because it is necessarily damaging if exposed (though of course it could be). Ransom is generally paid when the cost to recover the data is more than the ransom. Perhaps because they have a poor backup strategy in place or the time lost would be more costly. I would assume most companies hit by this type of attack would take precautions so that it wouldn't happen again or that they could at least recover quickly (better security, more frequent back-ups, etc.). Obviously, it is a different story if the release of the data would be damaging. In that case a ransom does no good for the reasons you say.
But again, executives don't have to worry about going to jail if the method of payment in untraceable. Good luck proving a particular executive was responsible for executing a bitcoin transaction. I still vote for punishing the people actually committing the crime. Not those who are being extorted.
RE: Paying Ransomware Should be Illegal