These proposals would significantly change the incident response landscape.
The UK Government has confirmed it will press ahead with legislative reforms designed to reshape how organisations respond to ransomware attacks (UK to lead crackdown on cyber criminals with ransomware measures – GOV.UK).
There are three central themes:
1. A Targeted Ban on Ransom Payments
Public sector bodies and critical national infrastructure (CNI) operators would be prohibited from paying ransoms.
2. A Pre-Payment Notification Regime
All organisations impacted by ransomware may be required to notify the Government in advance of making ransom payments. Where sanctions, anti-money laundering, or terrorism financing laws apply, the payment could be blocked.
3. Mandatory Incident Reporting
Ransomware attacks would need to be reported within 72 hours, even if no personal data is compromised, with a full incident report required within 28 days.
Legal Response vs Operational Reality
These proposals would significantly change the incident response landscape.
The implications are huge, particularly for public authorities, CNI operators and incident responders.
Removing payment as an option in ransomware playbooks raises a series of critical challenges:
- What happens if backups are encrypted?
- How do you notify data subjects if you don’t know who they are?
- Can organisations continue to operate following a complete systems failure?
Time to Rehearse the Unthinkable
While these legislative reforms are in progress, it’s key for organisations to go back to basics.
Revisiting playbooks and ransomware-specific response protocols is the crucial start point to comply with the increasing regulatory trend of attaining provable levels of resilience. Equally as critical is working to establish how recovery is possible in circumstances where the payment of a ransom isn’t an option.
Key priorities will include:
- Updating incident response and crisis communication plans to reflect payment restrictions, notification requirements, and regulator engagement
- Validating business continuity and disaster recovery capabilities to ensure recovery is possible following a complete system failure
- Conducting realistic cyber exercises to rehearse decision-making under pressure, including stakeholder management and data recovery scenarios
Conclusion
The proposed reforms will not eliminate ransomware. But they will profoundly change how organisations, particularly those in regulated sectors, are allowed to respond to it.
This reinforces the need for rigorous preparation, the testing of realistic incident response plans and establishing a failsafe way for the organisation to recover from a catastrophic cyber attack.
In a world where payment is no longer an option, impacted businesses will live or die by the measures they have implemented before an attack. The time to act is now. For advice, resilience planning and training, business continuity strategy and legal response to cyber incidents, contact Craig Kennedy at craig.kennedy@h-f.co.uk.
Related Insights
The Wrong Cyber Story Is Making Headlines
A recent striking headline reported that AI belonging to a major technology company had hacked into another company's systems during...
Ten Things Every Board Needs to Know About Cyber Risk
Recent developments in artificial intelligence have underlined how quickly the cyber risk landscape is evolving. The recent controlled release of...
Wiping the Slate Clean… As An Act of Cyber Warfare
A recent cyberattack on US medical technology company Stryker with bases in Ireland, highlights a dangerous trend in modern cyber...
How the Escalating Iran Crisis Is Impacting Marine, Aviation and Cyber Risk for Clients
The Middle East has entered a period of severe instability, with the Strait of Hormuz experiencing a rapid escalation in...




