When paying fails: why UK firms need an alternative ransomware playbook

New UK rules restrict ransom payments and require attacks to be reported within 72 hours. Firms that once quietly paid now need backup and recovery plans that work without the attacker's key.

6 min read
Read with AI

Open in

ChatGPT Claude Perplexity

This page

Copied to clipboard
When paying fails: why UK firms need an alternative ransomware playbook

Despite research indicating a trend that ransom payments are on the decline, reports have shown that close to 50% of CISOs would still consider paying the ransom. With ransomware remaining a primary threat to organisations, new UK legislation is forcing many businesses (previously prepared to quietly settle extortion demands to minimise operational downtime) to rethink their response to ransomware attacks.

If your company were affected by ransomware tomorrow, would you consider paying to recover your data? The data on this paints a mixed picture: some research* shows that ransomware payments are steadily declining as a result of organisations making a stand against ransomware attacks. However, other reports suggest that for certain organisations the reality is quite different, with some citing that the majority of CISOs would consider paying the ransom. The 2025 Hiscox Cyber Readiness Report✢ reveals that of the 27% of small businesses that experienced a ransomware attack, 80% of those paid a ransom. According to the latest global data from Sophos' State of Ransomware 2026 report✢✢ , 48% of organisations whose files were encrypted capitulated to cybercriminal demands. So although research responses vary according to region, organisation size, and industry, the results highlight that while it’s not a clear majority, there is hesitation among some businesses to trust that refusing to pay the ransom is the right decision.

The fact is, that in the midst of a crisis such as a ransomware attack, businesses are faced with several critical factors, often leading them to opt for paying the ransom. Firms will do everything they can to avoid customer data breaches, exposure of intellectual property or regulatory penalties. What drives organisations into paying the ransom is the uncertainty of these potential outcomes. Once an attack hits, companies will typically weigh up the financial consequences of downtime, taking into account derailed operations, disrupted supply chains, inoperative staff and potential damage to company reputation. If backup systems proved to be inadequate, whether offline backups were corrupted, untested or even non-existent, recovering operations can take anywhere from weeks to months. These concerns can appear to outweigh the cost of a ransom demand, which may appear to be the most practical option if there’s even a small chance that business continuity can be restored quickly.

When paying the ransom fails

Of course, there’s no guarantee that ransomware victims who pay the ransom will get their data back. If paying a ransom fails to bring the desired results, organisations can face a number of serious consequences. For instance, just because a hacker provides an organisation with a decryption key upon payment of the ransom, there is no certainty that it’s going to work. These tools are often ineffective, corrupted or inoperable with systems in a complex IT infrastructure. Should this be the case, organisations have no choice but to rebuild the IT environment from scratch.

Decryption tools provided by attackers can cause delays in recovery times, leaving businesses with protracted periods of downtime. The cost of the ransom payment, combined with the expense of downtime and recovery, can make the total payout overwhelming for organisations.

Cybercriminals also use “Double Extortion” tactics, where they encrypt data and threaten to publish companies’ confidential information on the dark web. This can result in serious damage to the company’s reputation, and the possibility of regulatory fines.

In a “Wiper Attack”, paying the ransom is completely useless. This attack pretends to be ransomware but is really “wiper” malware. Instead of encrypting the data, it completely destroys it. In this situation, data recovery is impossible.

Another problem with paying the ransom is that it can lead to repeat attacks down the line, as organisations can then be perceived by attackers as “proven payers”, which can act as a beacon for other threat actors.

Paying ransoms can also lead to potential legal and regulatory repercussions. Submitting to attackers’ demands by paying could violate anti-money laundering and security laws, leading to severe penalties. In regulated industries, poor protection of stolen data can result in hefty fines for non-compliance. Organisations such as the UK’s National Cyber Security Centre (NCSC) therefore advise against paying ransoms and stress the importance of having robust cyber-resilience and offline backups.

There are occasions where cyber insurance providers approve ransom payments. Though this tends to occur in situations where the financial implications (such as legal fees, lawsuits, reputational damage) are seen to outweigh the ransom amount.

The impact of new UK regulations on ransom payments

As the UK introduces new regulations to tackle ransomware by restricting ransom payments across public, critical and private sectors, this will no longer be an option. The surge in high-profile cyberattacks affecting essential UK public services and critical infrastructure providers, like the disruption on NHS operations caused by Synnovis, has prompted the government to take decisive action against ransomware threats, leveraging the use of financial sanctions by implementing a legal ban on ransom payments. These sanctions can freeze assets, thereby prohibiting individuals or entities from receiving funds in the form of ransomware payments. Violation of these sanctions is a serious offence which can lead to a sentence or hefty fines. In theory, by removing the financial incentives for cybercriminals, the effectiveness of ransomware attacks should be substantially diminished.

The regulations framework consists of three main pillars:

1. Targeted Payment Bans - These now apply to public sector organisations, such as the NHS, local authorities and operators of Critical National Infrastructure (CNI), meaning they are now prohibited from paying ransoms under any circumstances.

2. Payment Prevention Regime - For private businesses not subject to the complete prohibition, a "notify-before-pay" system has been introduced. Under this framework, organisations are required to disclose their intention to make a ransom payment prior to proceeding with the transaction. Authorities will review these notifications to block any payments that violate financial sanctions or anti-terrorism financing regulations, placing particular emphasis on transactions connected to cybercriminal groups linked to Russia.

3. Mandatory Incident Reporting - all organisations are now required to report ransomware attacks within 72 hours to enable law enforcement efforts in tracking threats and analysing attack patterns.

So before the ban is implemented and companies can no longer opt out of paying the ransom, businesses will need to reconsider their data protection strategies.

The alternative ransomware playbook

When it comes to ransomware, a small measure of prevention far outweighs the cost of a cure, which in many cases takes the form of a steep ransom demand. Instead of resorting to paying exorbitant ransoms, organisations should focus on implementing robust ransomware protection strategies. These measures include adopting multi-factor authentication (MFA), deploying firewalls, utilising intrusion prevention systems (IPS), leveraging endpoint detection and response (EDR) solutions, and educating employees to enhance awareness. Just as important, if not more so, is maintaining regular backups of critical data to enable seamless and rapid recovery after a ransomware attack. Backups can be rendered tamper-proof by threat actors by making them “immutable”, preventing the data from being altered in any way or deleted.

And while no security measure can provide absolute protection, organisations can significantly mitigate ransomware risks by implementing a multi-layered defensive strategy. Here are some best practices to keep in mind:

• Install updates and patches to mitigate known vulnerabilities that ransomware groups often exploit.

• Conduct regular employee training on cybersecurity hygiene, including using strong passwords, recognising suspicious emails and reporting potential security incidents.

• Use reliable backup software with support for immutable backups for cloud or on-site, flexible storage options, strong security controls and instant full/granular recovery.

• Implement multi-factor authentication (MFA) to add a layer of security beyond passwords and prevent unauthorised access.

• Limit employee access levels to the bare minimum necessary to perform their job functions, which reduces the attack surface and helps contain the impact of successful attacks.

• Deploy robust endpoint protection to prevent, detect and contain ransomware infections.

Ransomware attacks will continue to pose a significant threat to businesses across all sizes and sectors. Organisations can mitigate risks and avoid devastating consequences by developing a comprehensive data protection strategy, including investing in robust data protection and security solutions that can address vulnerabilities, and fostering a culture of cybersecurity awareness.

* According to an IDC Survey (September 2025) exactly 37% of victims ultimately paid a ransom.

✢The Hiscox Cyber Readiness Report is based on research between 29 July and 8 August 2025 of 5,750 businesses with 50-249 employees, where the individuals responsible for their organisation’s cyber security strategy were interviewed. Respondents by geography: 1,000 respondents in the USA, UK, France, Germany and Spain respectively, 500 respondents in Ireland and 250 in Portugal.

✢✢ The Sophos State of Ransomware report 2026 reveals insights from 2,158 IT and cybersecurity leaders across 17 countries whose organisations were hit by ransomware in the past year.