For large companies "paying in secret" is pretty difficult given public accounts. The typical CFO would rather get a new job elsewhere rather than risk prison because his CTO colleague did a poor job securing the IT. They just work there.
A ban on ransomware payment also has the nice side effect of banning ransomware insurance, which has been making the problem worse so far.