The UK Government recently conducted a public consultation on proposals to reduce ransomware threats by stopping some organizations from paying ransoms to cyber criminals and requiring ransomware reporting. The consultation drew 273 written responses and input from 36 stakeholder engagement sessions. Respondents included public bodies, private businesses, industry groups, cyber security experts, and legal professionals.
Three core proposals were presented, with feedback as follows:
Targeted ban on ransom payments for the public sector and CNI
There was broad support for banning ransom payments by public sector bodies and operators of critical national infrastructure (CNI). Many respondents agreed that public money should not fund criminal activity and that a ban could reduce the profitability of ransomware attacks. However, several stakeholders raised concerns about unintended consequences, such as increased data leakage or prolonged operational disruption if payments were banned. There was also debate about extending the ban to essential service suppliers. Overall, 72% of respondents agreed that the Government should implement a targeted ban on ransomware payments for CNI owners and operators and the public sector, including local government.
A new ransomware payment prevention regime to cover all potential ransomware payments from the UK
This proposal received a mixed response, with more limited support. Of several suggestions in this area, a measure to implement an economy-wide payment prevention regime for all organisations and individuals not covered by the targeted ban had the most support, but this came from only 47% of respondents.
Some industry bodies supported the move as a way to improve intelligence sharing and disrupt criminal revenue streams. However, concerns were raised about how such a requirement would affect the speed and confidentiality of incident response, especially during high-pressure ransomware events. Respondents stressed the need for rapid and clear Government guidance in such cases.
Mandatory ransomware incident reporting
A proposal for an economy-wide mandatory reporting requirement for all organizations and individuals received the strongest support, with 63% of respondents in favour of introducing a legal duty to report ransomware incidents across the UK economy.
Next steps
The UK Government has committed to further engagement with stakeholders before finalising any legislation. These measures will form part of a broader cyber resilience strategy, underpinned by the forthcoming Cyber Security and Resilience Bill.






