Site navigation

75% of Firms Would Still Pay Cyber-ransom Under Proposed Ban

Graham Turner

,

ransomware payment ban
The proposed ban would legally prohibit ransom payments by public sector organisations and operators of critical national infrastructure (CNI), including schools, NHS trusts, local authorities, and transport, energy, and telecoms providers.

Cyber resilience firm Commvault has published new research revealing a sharp divide between principle and practice around the proposed ban on ransomware payments.

While 96% of surveyed UK business leaders from £100 million+ companies believe payments should be banned across both public and private sectors, 75% admit that if a ban was extended to the private sector, they would still pay a ransom if it were the only way to save their organisation, regardless of whether civil or criminal penalties applied.

The proposed ban would legally prohibit ransom payments by public sector organisations and operators of critical national infrastructure (CNI), including schools, NHS trusts, local authorities, and transport, energy, and telecoms providers. All other businesses, including the private sector not covered by the ban, would be required to notify the government of any intent to pay a ransom.

Support for a ban is strong in both sectors, as is shown in the survey: 94% support limiting ransom payments for public entities and 99% for private organisations.

However, the survey found that in real-world situations within the private sector, if a ban were to take hold, only 10% said they would comply if they were attacked. 

A further 15% said they would be neither likely nor unlikely to comply. This suggests that while respondents think the ban is a good idea on paper and makes sense for government agencies, if their own company’s survival is at stake, all bets are off.

Of those who support a proposed payment ban, more than a third (34%) believe it would lead to increased government support and intervention to safeguard cyber resilience. Another third (33%) believe that it would decrease the prevalence of attacks by reducing the incentive for attackers – this is one of the central aims of the ban. 

The latest Cyber Security Breaches Survey 2025 from the UK Government stated that over four in ten (43%) UK businesses (equating to approximately 612,000 UK businesses) reported having experienced any kind of cybersecurity breach or attack in the last 12 months.

Given the proliferation of attacks, almost all respondents (98%) said cyber readiness and recovery will be a top spending priority. This reflects growing recognition that the best way to beat ransomware is to focus on resilience and technologies that can enable rapid recoveries, rather than relying on reactive payments, which may or may not help enterprises get their data back. 

Recovery from a cyber-attack takes 24 days on average. For large organisations this means financial losses, but for smaller organisations this can lead to bankruptcy, underlining the urgency for greater investment in recovery readiness.

“Paying a ransom rarely guarantees recovery and often increases the likelihood of being targeted again,” said Darren Thomson, Field CTO EMEAI, Commvault.


Recommended reading


“A well-enforced ban could help take the profit out of ransomware, but it must be matched by greater investment in prevention, detection, and recovery-testing. Without that, more organisations could find themselves exposed at the worst possible moment, with no viable path to recovery.”

“Ransomware and cyber-attacks will be a concern for a long time, as international cyber gangs make huge profits from them and use these resources to continually develop their attack tools,” says Jane Frankland, MBE, CEO, Knewstart.

“To break this cycle, companies must better prepare for emergencies and strengthen their cyber resilience. This will allow them to maintain operations and continue to serve customers during a cyber incident.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data