Skip to content

Government presses on with plans to address ransomware threat

23 July 20254 min read
News
Government presses on with plans to address ransomware threat

The Government has published their response to the consultation on proposed ransomware legislation aimed at reducing payments to cyber criminals and increasing incident reporting.

The consultation, which ran for 12 weeks from January 2025, sought views on three proposals:

  1. A targeted ban on ransomware payments for owners and operators of regulated-critical national infrastructure and the public sector.

  2. A ransomware payment prevention regime.

  3. A mandatory incident reporting regime.

Key themes

  1. Strong Support for a Targeted Ban on Ransomware Payments.

Nearly 72% of respondents supported a targeted ban on ransomware payments for public sector bodies and critical national infrastructure (CNI) operators. Respondents broadly agreed that a ban would reduce criminals and deter attacks.

However, concerns were raised around the scope of the ban – particularly whether supply chains would be included. Respondents also highlighted the need for clear guidance, financial support and incident response mechanisms to ensure the measure is effectively implemented. There were also calls for carefully defined exemptions in life-threatening or critical scenarios.

These concerns reflect many of the points raised in techUK’s consultation response.

  1. Mixed Views on a Wider Ransomware Payment Prevention Regime.

The proposal for a broader, economy-wide ransomware payment prevention regime received mixed feedback. The introduction of an economy-wide payment prevention regime for organisations and individuals not covered by the targeted ban received marginally more support than other measures, with 47% in favour.

Respondents again echoed issues highlighted by techUK, including the potential for displacing attacks to those not covered, robust support which is upheld by consistent and coordinated information with well-defined timelines for reporting incidents. There was also scepticism about the effectiveness of the regime in enabling law enforcement to intervene and investigate ransomware threats.

  1. Strong Support for Mandatory Incident Reporting

There was clear support for a mandatory incident reporting regime, with 63% of respondents backing economy-wide mandatory reporting within 72 hours (with a follow-up within 28 days). In contrast, fewer than half of respondents supported maintaining the existing voluntary system.

Concerns focused on potential administrative burdens, particularly for SMEs and the need for alignment with existing regulatory frameworks. There were also calls for clarification on the inclusions of individuals within the regime.

Cross-Cutting Themes

Several issues emerged across all three proposals, reinforcing the importance of ongoing engagement between government and industry. Key themes include:

Scope of the proposals: Respondents called for further clarity on the scope of the measures, including how CNI operators are defined, the role of supply chains and the extraterritorial application of the legislation. Responses also called for clarity on the threshold requirements for compliance.

Penalties: While there was broad support for the use of penalties, respondents urged caution around proportionality and warned against criminalising or revictimizing ransomware victims. There was also discussion on whether penalties should be civil, criminal or tailored.

Guidance and support: Respondents emphasised the need for sector-specific, accessible guidance to support implementation, especially for smaller organisations.

Cyber awareness and resilience: The consultation highlighted a broader need to address the UK’s cyber resilience through improved awareness, modernised IT infrastructure, effective backup strategies and strengthened incident response.

Next Steps:

The government plans to move forward with the proposed measures to tackle the threat of ransomware and is continuing to explore their development. The immediate priorities will include refining the scope of the proposals, clarifying the legal definitions and considering how they will impose appropriate penalties. Additional guidance will be developed in parallel with the Cyber Security and Resilience Bill. 

Government has also confirmed it will continue to work with industry with a focus on the implementation and resource requirements that these proposals will need.

techUK Reaction:

techUK commends the government’s ambition to ensure the UK is better protected against ransomware threats, however, there is continued concern about the practical application of the Home Office’s proposals. In particular, there is still concern that the proposed ban on ransomware payments for the public sector and CNI, and the payment prevention regime, do not take account of the nuance present in this area and could have unintended consequences, as outlined in our response to the original consultation.

techUK is eager to work with government to close the gap between cyber threats like ransomware and the UK’s exposure to it. We look forward to further engagement with the Home Office as it continues to develop these proposals and ensures that the right support mechanisms are in place to allow organisations to understand, implement and comply with the new measures.

You can read Government’s full response to the Call for Views here.

You can read techUK’s response to the consultation here.