Joint guidance from the UK NCSC with the Association of British Insurers (ABI), British Insurance Brokers’ Association (BIBA) and International Underwriting Association (IUA) aims to help organizations faced with ransomware demands.
The joint guidance aims to ‘thwart cyber criminals’ profits by improving market-wide ransom discipline and reducing the number of ransoms being paid by UK ransomware victims’.
Developed from a NCSC-sponsored research paper by the Royal United Services Institute (RUSI), the best practice guidance sets out recommendations that aim to help organizations and associated third parties to make informed decisions when faced with ransomware, and ultimately help minimise the disruption and cost of an incident.
Key points highlighted in the guidance include:
- Don’t panic: ransomware actors pressure organizations into making quick decisions. But slowing down to review the options will improve decision making and lead to a better outcome.
- Review alternatives, including not paying: decisions about payment should be informed by a comprehensive understanding of the impact of the incident.
- Record your decision-making
- Investigate the root cause of the incident to avoid a repeat attack
- Be aware that payment does not guarantee access to your devices or data
- Consider the correct legal and regulatory practice around payment
- Know that paying a ransom does not fulfil your regulatory obligations.






