Particle.news

Download on the App Store

UK Unveils Plan to Ban Ransom Payments and Mandate Reporting Under Cyber Resilience Bill

Officials say the measures aim to cut criminal funding for ransomware gangs ahead of parliamentary approval.

Officers from the National Crime Agency arrive at a property of a man who is accused of being a member of a group arranging small boat crossings and HGV journeys for migrants, in Grays , Essex. (Photo by Aaron Chown/PA Images via Getty Images)
blank
Clouds hang above the Houses of Parliament in central London, Britain, June 24, 2017. REUTERS/Marko Djurica/File Photo
Image

Overview

  • Under the proposals public sector and critical infrastructure organizations including the NHS, local councils and schools would be prohibited from making ransomware payments.
  • Private companies planning to pay ransoms would have to notify the Home Office in advance to receive guidance on legal and security risks.
  • A mandatory incident-reporting regime is being developed to give law enforcement timely intelligence on ransomware attacks.
  • Organizations that pay ransoms to sanctioned criminal groups could face fines of up to £1 million or half the value of the breach.
  • The measures have strong public backing from a January consultation and are set to be included in the forthcoming Cyber Resilience Bill.