{"id":85647,"date":"2025-07-23T10:09:07","date_gmt":"2025-07-23T10:09:07","guid":{"rendered":"https:\/\/www.europesays.com\/us\/85647\/"},"modified":"2025-07-23T10:09:07","modified_gmt":"2025-07-23T10:09:07","slug":"government-to-ban-public-sector-from-paying-ransoms-in-cybercrime-crackdown","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/85647\/","title":{"rendered":"Government to ban public sector from paying ransoms in cybercrime crackdown"},"content":{"rendered":"<p>        Aims to dismantle hacker business models<\/p>\n<p>            <img decoding=\"async\" loading=\"lazy\" alt=\"the hand sign of men a stop, caution.\" src=\".\/media_1e349c63950ef52738f24ff45b4444c116202ce89.jpg?width=750&amp;format=jpg&amp;optimize=medium\" width=\"700\" height=\"418\"\/><\/p>\n<p><strong>The UK government has unveiled a new policy to \u201csmash the cybercriminal business model\u201d by banning public sector organisations from paying ransoms.<\/strong><\/p>\n<p>The measure, announced on Tuesday by Home Office Security Minister Dan Jarvis, forms a central part of the country&#8217;s escalated <a href=\"https:\/\/www.computing.co.uk\/news\/2025\/security\/government-could-ban-ransom-payments\" target=\"_blank\" rel=\"noopener\">cybersecurity strategy<\/a> and comes amid mounting concerns over repeated and increasingly damaging <a href=\"https:\/\/www.computing.co.uk\/news\/2025\/security\/ransomware-attack-hit-11-uk-schools\" target=\"_blank\" rel=\"noopener\">cyberattacks<\/a> on British infrastructure.<\/p>\n<p>Under the proposed rules, public bodies including the NHS, local councils and schools, will be explicitly prohibited from making ransom payments to cybercriminals.<\/p>\n<p>In parallel, private companies will be legally required to inform government authorities if they intend to pay up, allowing officials to intervene, offer support and ensure that potential transactions do not breach laws surrounding sanctions.<\/p>\n<p>The government&#8217;s objective, Jarvis said, is to &#8220;smash the cybercriminal business model&#8221; and send a unified message that &#8220;the UK is united in the fight against ransomware.&#8221;<\/p>\n<p>Ransomware, malicious software that locks victims out of their own systems until they pay up, has become a leading form of cybercrime globally.<\/p>\n<p>Criminals received <a href=\"https:\/\/www.chainalysis.com\/blog\/ransomware-2024\/\" target=\"_blank\" rel=\"noopener\">over $1 billion in ransom payments in 2023 alone<\/a>, according to industry estimates.<\/p>\n<p>The UK has been no stranger to these assaults. The 2017 <a href=\"https:\/\/www.computing.co.uk\/news\/3023477\/there-have-been-almost-1-billion-wannacry-infections-and-theyre-still-growing\" target=\"_blank\" rel=\"noopener\">WannaCry<\/a> ransomware outbreak disrupted hospitals across the NHS, delaying critical surgeries and treatments.<\/p>\n<p>In 2023, the <a href=\"https:\/\/www.computing.co.uk\/news\/4149233\/rhysida-threatens-dark-web-auction-british-library\" target=\"_blank\" rel=\"noopener\">British Library<\/a> refused to pay a ransom and suffered prolonged operational downtime.<\/p>\n<p>A ransomware attack on NHS systems earlier this year was cited as a contributing factor in the death of a patient.<\/p>\n<p>Retail giants such as <a href=\"https:\/\/www.computing.co.uk\/news\/2025\/security\/m-s-had-no-plans-for-cyberattack\" target=\"_blank\" rel=\"noopener\">Marks &amp; Spencer<\/a> and Co-op Group have also been targeted in a wave of attacks throughout 2025, further amplifying public alarm.<\/p>\n<p>        Strong support<\/p>\n<p>The Home Office revealed that nearly 75% of responses to a <a href=\"https:\/\/www.gov.uk\/government\/consultations\/ransomware-proposals-to-increase-incident-reporting-and-reduce-payments-to-criminals\/ransomware-legislative-proposals-reducing-payments-to-cyber-criminals-and-increasing-incident-reporting-accessible\" target=\"_blank\" rel=\"noopener\">public consultation<\/a> backed the ban on public sector ransom payments.<\/p>\n<p>The government has pledged to implement the measure across all operators of critical national infrastructure, ensuring that vital services are less susceptible to coercion.<\/p>\n<p>Alongside the ban, officials are urging all UK organisations to prepare for the possibility of an attack by strengthening digital defences and operational resilience.<\/p>\n<p>The government recommends that organisations maintain offline data backups, develop tested contingency plans for operating without IT systems and rehearse the process of restoring services from backup systems.<\/p>\n<p>While the UK cannot legislate against cybercriminals operating overseas, particularly those sheltered by hostile regimes, the government hopes the new policy will make the country a less lucrative target.<\/p>\n<p>Commenting on the proposed policy, Adenike (Nikki) Cosgrove, CMO and security strategist at Mimecast, said the move &#8220;sends a strong signal,\u201d but is &#8220;only one piece of the puzzle.\u201d<\/p>\n<p>\u201cThe uncomfortable truth is that most ransomware attacks start with a human action: clicking a link, trusting the wrong source, or bypassing security controls.<\/p>\n<p>Nikki urged a shift-left mindset to prevent compromise in the first place, which is of course the goal for everyone.<\/p>\n<p>Alex Laurie, SVP of global sales engineering and go-to-market programmes at Ping Identity, said the government\u2019s move is \u201cwell-intentioned but complex.\u201d<\/p>\n<p>He added, \u201cWhile it\u2019s clear paying ransoms offers no guarantee of data recovery and may encourage future attacks, outright bans risk leaving under-resourced sectors dangerously exposed with few alternatives.&#8221;<\/p>\n<p>However, Jonathan Wright, partner in the UK Data Privacy and Cybersecurity practice at law firm Hunton Andrews Kurth LLP, said making ransom payments illegal punishes the wrong people:<\/p>\n<p>\u201cWhile making ransom payments illegal removes the motive and in theory takes away the incentive for threat actors to launch ransomware attacks, you are also punishing the victims. It is also worth noting, of course, that threat actors have other means available to them and there will always be hacktivists and those acting for reasons other than money, so cyberattacks will continue.<\/p>\n<p>\u201cIt is difficult to see how any law against paying ransom demands would be enforced. It doesn\u2019t seem right that an organisation, victim of a ransomware attack having had files stolen, should then face sanctions (whether financial or administrative) for paying a ransom demand that may not even have resulted in it retrieving the stolen data!\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"Aims to dismantle hacker business models The UK government has unveiled a new policy to \u201csmash the cybercriminal&hellip;\n","protected":false},"author":3,"featured_media":85648,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22],"tags":[745,734,3228,22356,126,158,57881,67,132,68],"class_list":{"0":"post-85647","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-computing","8":"tag-computing","9":"tag-cybersecurity","10":"tag-law","11":"tag-ransomware","12":"tag-sanctions","13":"tag-technology","14":"tag-uk-government","15":"tag-united-states","16":"tag-unitedstates","17":"tag-us"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/114902005525770670","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/85647","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=85647"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/85647\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/85648"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=85647"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=85647"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=85647"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}