The UK government has launched a consultation on proposals to protect hospitals, public services, and critical infrastructure such as railways from the cyber-criminals behind ransomware attacks.
Ransomware is malicious software that infects a victim’s computer and demands a ransom in order to give back access to their system, for their data to be restored, and often for the hackers not to publish the victim’s data on the web.
The government says its proposals aim to “strike at the heart” of the cybercriminal business model by deterring threats. It will do so by – among other proposals – banning public sector bodies and critical national infrastructure from making ransomware payments.
As the theory goes, this will make them less attractive targets for criminals. The proposal is an expansion of the current ban on payments by government departments.
Security Minister Dan Jarvis said: “Driving down cybercrime is central to this government’s missions to reduce crime, deliver growth, and keep the British people safe.
“With an estimated $1bn flowing to ransomware criminals globally in 2023, it is vital we act to protect national security as a key foundation upon which this government’s Plan for Change is built.
“These proposals help us meet the scale of the ransomware threat, hitting these criminal networks in their wallets and cutting off the key financial pipeline they rely upon to operate.”
The Home Office-led consultation will consider three proposals:
- A targeted ban on ransomware payments for all public sector bodies and critical national infrastructure – expanding the existing ban on ransomware payments by government departments, and making the essential services the country relies on the most unattractive targets for ransomware crime
- A ransomware payment prevention regime – increasing the National Crime Agency’s (NCA) awareness of live attacks and criminal ransom demands, providing victims with advice and guidance before they decide how to respond, and enabling payments to known criminal groups and sanctioned entities to be blocked
- A mandatory reporting regime for ransomware incidents – bringing ransomware out of the shadows and maximising the intelligence used by UK law enforcement agencies to warn of emerging ransomware threats, and target their investigations on the most prolific and damaging organised ransomware groups
According to the Home Office, ransomware attacks are largely carried out by Russian-affiliated criminal gangs.
They are said to continue to pose the “most immediate and disruptive threat” to the UK’s critical national infrastructure, according to the National Cyber Security Centre’s (NCSC) Annual Review 2024. They also cause more disruption and pose a greater risk than other cybercrimes.
Recent cyberattacks have included a key supplier to London Hospitals and Royal Mail.
The NCSC managed 430 cyber incidents between September 2023 and August 2024, including 13 ransomware incidents which were deemed to be nationally significant and posed serious harm to essential services or the wider economy.
Reporting to the NCA indicates the number of UK victims appearing on ransomware data leak sites has also doubled since 2022.
Richard Horne, chief executive of the National Cyber Security Centre, said: “This consultation marks a vital step in our efforts to protect the UK from the crippling effects of ransomware attacks and the associated economic and societal costs.
“Organisations of all sizes need to build their defences against cyber attacks such as ransomware, and our website contains a wealth of advice tailored to different organisations. In addition, using proven frameworks like Cyber Essentials, and free services like NCSC’s Early Warning, will help to strengthen their overall security posture.
“And organisations across the country need to strengthen their ability to continue operations in the face of the disruption caused by successful ransomware attacks. This isn’t just about having backups in place: Organisations need to make sure they have tested plans to continue their operations in the extended absence of IT should an attack be successful, and have a tested plan to rebuild their systems from backups.”
Read next: Sweden’s climate minister breaks ground on nuclear waste facility
Are you a building professional? Sign up for a FREE MEMBERSHIP to upload news stories, post job vacancies, and connect with colleagues on our secure social feed.

