New UK rules proposed for Ransomware payments
On 14 January 2025 the UK government opened a consultation – which closes on 8 April 2025 about making ransom payments in the UK. The consultation contains three proposals:
On 14 January 2025 the UK government opened a consultation – which closes on 8 April 2025 about making ransom payments in the UK. The consultation contains three proposals:
Central government departments currently cannot make ransom payments, but the proposal expands that principle by prohibiting all entities in the UK public sector from doing so. The proposal also covers owners and operators of critical national infrastructure and, potentially, critical suppliers to those organisations.
This would require any ransomware victim to report their intention to make a ransomware payment to the National Crime Agency before making any payment. They would then receive support and guidance, and the National Crime Agency review the proposed payment and consider if there is a reason to block it.
Regulators in the UK advise companies not to make ransom payments — and lawyers have been told by the ICO and the Law Society that they should do the same with their clients. The consultation acknowledges the commercial reality of ransom payments, and confirms that if the proposed payment is not blocked, it is for the victim to decide whether to proceed.
Lastly, the Government is seeking views on whether an incident reporting regime should be economy-wide or only impact organisations and individuals meeting a certain threshold (e.g., turnover, number of employees, sector, amount of ransom sought). The reporting requirement will mean that organisations will be obligated to notify the National Crime Agency with 72 hours of becoming aware of the ransom demand and would apply regardless of the victim’s intention to pay the ransom.
The government’s thinking is that if cyber criminals know that hospitals cannot legally pay a ransom, they will stop targeting those entities. Whether that is correct remains to be seen. What is clear is that we can likely expect a highly significant change to the status quo in the UK regarding ransom payments.