Overview
- Under the proposals public sector and critical infrastructure organizations including the NHS, local councils and schools would be prohibited from making ransomware payments.
- Private companies planning to pay ransoms would have to notify the Home Office in advance to receive guidance on legal and security risks.
- A mandatory incident-reporting regime is being developed to give law enforcement timely intelligence on ransomware attacks.
- Organizations that pay ransoms to sanctioned criminal groups could face fines of up to £1 million or half the value of the breach.
- The measures have strong public backing from a January consultation and are set to be included in the forthcoming Cyber Resilience Bill.