The UK government has unveiled proposals that could require businesses to notify authorities if they intend to pay a ransom to cyber criminals, a move prompted by high-profile attacks on major firms—including the recent Marks & Spencer (M&S) cyber incident—in a crackdown aimed at undermining the effectiveness of ransomware.
Government Response to Growing Ransomware Threat
In a detailed plan published by the Home Office, the government outlines a two-pronged approach: a total ban on public sector bodies and operators of critical national infrastructure (CNI) making ransom payments, and a new notification regime for all other businesses considering such payments.
A Home Office spokesperson said, “The new package of measures will lead the way in tackling ransomware and are designed to strike against cyber criminals’ business model, bolstering our national security and protecting key services and businesses from disruption.”
The government consultation showed almost three-quarters of responses supported these reforms. Businesses covered by the new requirements will be expected to make an initial report within 72 hours if they intend to pay a ransom, with authorities offering guidance and reviewing the payment to ensure it doesn’t breach sanctions or terrorism financing laws.
.
The Marks & Spencer Hack: Silence Fuels Reform
The proposals come in the aftermath of the major ransomware attack on M&S earlier this year, which forced the closure of its website and disrupted customer services for weeks at an estimated cost of £300 million to the retailer. Hackers linked to the DragonForce ransomware group reportedly demanded a ransom, but M&S has steadfastly refused to confirm if payment was made.
During a parliamentary hearing, M&S chairman Archie Norman stated: “We took an early decision that nobody at M&S would deal with the threat actors directly. We felt that the right thing would be to leave this to the professionals who have experience in the matter,” adding that further disclosure was “not in the interest of the public.”
Cybersecurity experts note that the company’s refusal to discuss the ransom publicly has helped drive momentum for government intervention, with speculation mounting due to the absence of leaked data and ongoing silence from the attackers.
Ellie Ludlam of Pinsent Masons, a cyber risk lawyer, commented: “There remains a lack of clarity on the scope of the new mandatory reporting regime planned, including what the consequences and penalties might be for non-compliance.” She added that organisations are eagerly awaiting detailed guidance from the government before new obligations come into force.
Ransomware investigators welcomed the move, emphasising its potential value for law enforcement. Allan Liska of Recorded Future said: “Mandatory reporting is… a tacit acknowledgment of what we’ve known for a while: Ransomware operators and their enablers are not confined to Russia and many of those involved are very catchable and, more importantly, prosecutable. I think it’s super important.”
What Happens Next?
The Home Office promises more detailed guidance as the proposed rules are finalised. Unresolved questions remain around which companies will be affected and the potential penalties for non-compliance, as the government works to balance business burden and cyber resilience.