Commvault has published new research revealing a sharp divide between principle and practice around the proposed UK ban on ransomware payments. While 96% of surveyed UK business leaders from £100 million+ companies believe payments should be banned across both public and private sectors, 75% admit that if a ban was extended to the private sector, they would still pay a ransom if it were the only way to save their organization, regardless of whether civil or criminal penalties applied.
The proposed ban would legally prohibit ransom payments by public sector organizations and operators of critical national infrastructure (CNI), including schools, NHS trusts, local authorities, and transport, energy, and telecoms providers. All other businesses, including the private sector not covered by the ban, would be required to notify the Government of any intent to pay a ransom.
Support for a ban is strong in both sectors, as is shown in the survey: 94% support limiting ransom payments for public entities and 99% for private organizations. However, the survey found that in real-world situations within the private sector, if a ban were to take hold, only 10% said they would comply if they were attacked. A further 15% said they would be neither likely nor unlikely to comply. This suggests that while respondents think the ban is a good idea on paper and makes sense for government agencies, if their own company’s survival is at stake, all bets are off.
Of those who support a proposed payment ban, more than a third (34%) believe it would lead to increased government support and intervention to safeguard cyber resilience. Another third (33%) believe that it would decrease the prevalence of attacks by reducing the incentive for attackers – this is one of the central aims of the ban.
Given the proliferation of attacks, almost all respondents (98%) said cyber readiness and recovery are a top future spending priority. This reflects growing recognition that the best way to beat ransomware is to focus on resilience and technologies that can enable rapid recoveries, rather than relying on reactive payments, which may or may not help enterprises get their data back. “Paying a ransom rarely guarantees recovery and often increases the likelihood of being targeted again,” said Darren Thomson, Field CTO EMEAI, Commvault. “A well-enforced ban could help take the profit out of ransomware, but it must be matched by greater investment in prevention, detection, and recovery-testing. Without that, more organizations could find themselves exposed at the worst possible moment, with no viable path to recovery.”
Research methodology
This survey was conducted independently and exclusively for Commvault by Censuswide. It reveals the views of 1,000 UK business leaders, from companies with revenue of over £100 million. Data was collected between June 4 and June 6, 2025.






