Overview
- Home Office proposals would bar the NHS, local councils, schools and other state-funded entities from paying ransom demands.
- Private organizations must notify government agencies before paying any ransom demands to receive advice and avoid funding sanctioned criminal groups.
- A mandatory incident-reporting regime would require all ransomware victims to disclose breaches to law enforcement and intelligence services.
- Companies that flout notification rules or pay sanctioned groups could face fines of up to £1 million or half the breach’s value.
- Nearly 75 percent of respondents to a January public consultation backed the measures, which build on lessons from WannaCry in 2017 and recent attacks on retail and library systems.