On January 14, 2025, the UK government unveiled a proposed framework aimed at combating the rise of ransomware attacks by implementing a payment prevention and reporting regime. This would require companies to not only report all ransomware incidents, but also to declare whether they intend to pay a ransom. The government also announced that it proposes to ban public bodies and infrastructure providers from making ransom payments to cyber attackers. A public consultation is open until April 8, 2025.
The move reflects rising concerns about ransomware attacks and their use to cause widespread disruption to public services. The consultation cites estimates that cybercriminals received more than $1 billion from their victims globally in 2023, and notes that a record number of ransomware cases were reported to the UK Information Commissioner’s Office in that year.
The Proposals
The key proposals subject to public consultation include:
The consultation does not specify what the reporting periods under the proposed new legislation would be. However, it does note that work is ongoing with the Department for Science, Innovation, and Technology to ensure that the proposals are aligned with the upcoming Cyber Security and Resilience Bill. It will also work with other government departments to ensure there is no conflict with the NIS Regulations.
Similar Developments in the EU
There are signs that ransomware is also being treated as a priority across the EU, with several recent developments addressing the topic:
Next Steps
The UK government is accepting comments on the proposal until April 8, 2025. We encourage businesses interested in the proposed initiative to submit comments. Wilson Sonsini routinely advises companies on submitting public comments on policy and legislative initiatives in the area of data, privacy, and cybersecurity. In addition, Wilson Sonsini clients who believe they may be experiencing any kind of cybersecurity incident anywhere in the world can contact our experts 24/7 at our incident response hotline, which can be reached at either 32-2-2745777 or 1-650-849-3030.
For more information, please contact Demian Ahn, Cédric Burton, Nikolaos Theodorakis, Tom Evans, Laura Brodahl, or another member of the firm’s data, privacy, and cybersecurity practice.
Claudia Chan contributed to the preparation of this Wilson Sonsini Alert.