The Home Office is launching a consultation on three new proposals which aim to tackle the threat of ransomware and cyber-crime.
The most radical of the proposals sets out a ban on all public sectors bodies and critical national infrastructure from making ransomware payments, aiming to make them unattractive targets for criminals.
Government bodies are already banned from making any ransomware payments – extending this ban to critical infrastructure and the public sector hopes to further deter cyber-criminals from targeting these essential bodies.
The second proposal would set out a ransomware payment prevent regime, increasing the National Crime Agency’s (NCA) awareness of live attacks and criminal ransom demands.
This would provide victims with advice and guidance before they decide how to respond, and block the payments of ransoms to known criminal groups and sanctioned entities.
Essentially, this proposal would require that organisations not already banned from paying a ransom would first have to consult a government agency and gain their permission before paying a ransom.
A mandatory reporting regime for ransomware incidents rounds out the final proposal, which aims to maximise the intelligence used by UK law enforcement agencies to warn of emerging ransomware threats, and target their investigations on the most prolific and damaging organised ransomware groups.
This final proposal would likely not require the first two – the ban and the regime – to go through, but will still provide cyber defence specialists with vital information
Both the second and third proposal will be assessed to see if they will be inputted as a blanket regime or if they will be applied on a case-by-case basis.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- Comment | Cybersecurity Ethics in an Age of Evolving Cyber Risk
- Cyber Leaders Reveal Compliance and Boardroom Struggles
“This consultation marks a vital step in our efforts to protect the UK from the crippling effects of ransomware attacks and the associated economic and societal costs,” Richard Horne, National Cyber Security Centre (NCSC) CEO said.
“Organisations of all sizes need to build their defences against cyber attacks such as ransomware, and our website contains a wealth of advice tailored to different organisations.
“In addition, using proven frameworks like Cyber Essentials, and free services like NCSC’s Early Warning, will help to strengthen their overall security posture.
“And organisations across the country need to strengthen their ability to continue operations in the face of the disruption caused by successful ransomware attacks.
“This isn’t just about having backups in place: organisations need to make sure they have tested plans to continue their operations in the extended absence of IT should an attack be successful, and have a tested plan to rebuild their systems from backups.”





