The UK Government has published its plans for a cyber-crime crackdown, with new measures to tackle ransomware, protect businesses, and safeguard critical services being taken forward following public consultation.
Under the Home Office’s proposals, public sector bodies and operators of critical national infrastructure, like the NHS, local councils and even schools, would be banned from paying ransom demands, with the government saying nearly three-quarters (72%) of consultation respondents were in support of such a move.
Around two-thirds of respondents (68%) agreed that a targeted ban could help cut the flow of funds to ransomware gangs, hitting their income directly, while six in ten (60%) reckoned it could also put cyber-criminals off targeting organisations covered by the ban.
The government hopes that such a ban might disrupt the business model that fuels cyber-criminals’ activities and make vital services a less attractive target for ransomware groups.
Under the plans, businesses not covered by the ban would be required to notify authorities of any intent to pay a ransom, a particularly striking move following the recent disclosure of the M&S chairman in parliament that multiple attacks against major businesses have gone unreported.
The government said that once notified, it could provide at-risk businesses with advice and support, including telling them if any ransom payment breaks the law by sending money to sanctioned cyber-criminal groups, many of which are based in Russia.
Mandatory reporting is also being developed, which would equip law enforcement with essential intelligence to hunt down perpetrators and disrupt their activities. The recent consultation showed strong support for a mandatory reporting regime that could better protect British organisations and industry.
“Ransomware is a predatory crime that puts the public at risk, wrecks livelihoods and threatens the services we depend on,” said security minister Dan Jarvis.
“By working in partnership with industry to advance these measures, we are sending a clear signal that the UK is united in the fight against ransomware.”
In addition to the proposed new measures, the government is continuing to urge organisations across the country to strengthen their resilience in the event of a successful ransomware attack.
Advice includes having offline backups, maintaining tested plans to operate without IT for an extended period, and a well-rehearsed strategy for restoring systems from backups.
The government’s renewed focus on tackling cyber-crime, and particularly ransomware, follows a series a devastating attacks on British high-street chains M&S and Co-op, which have resulted in hundreds of millions in lost profit.
Recommended reading
- NCSC Launches Vulnerability Research Initiative
- Record 7.3 Tbps DDoS Attack Blocked
- Why Are Young People Becoming Cyber-criminals?
Last week, Co-op confirmed that all 6.5 million of its members were affected by the cyber-attack against the retailer in April, with chief executive Shirine Khoury-Haq saying that customers ‘should be concerned’ after millions of names, addresses and contact information were lost to the hackers.
“We know first-hand the damage and disruption cyber-attacks cause to businesses and communities. That’s why we welcome the government’s focus on cybercrime,” said Khoury-Haq on the government proposals.
“What matters most is learning, building resilience, and supporting each other to prevent future harm. This is a step in the right direction for building a safer digital future.”





