Britain’s public sector ransomware payment ban aims to disrupt the criminal business model, but questions remain over its practicality and impact. Stephen Boyer of Bitsight examines what it means for government bodies and private firms alike.

When the UK announced it would be banning public sector organisations from paying ransom to cybercriminals last month, it was the latest development in a long-running and contentious debate. Should organisations ever pay ransom? On the one hand, payments risk rewarding criminals, funding corrupt activity and incentivising future attacks. On the other, paying may be the only way for a business to protect its data, restore systems and mitigate the financial and reputational fallout of an attack.
While ransomware payments have long been discouraged by authorities, outright bans remain rare and typically limited to the public sector. Yet ransomware continues to escalate regardless.
Bitsight’s latest State of the Underground 2025 research found that ransomware activity disclosed on the dark web rose by 25% year-on-year, with the UK ranking third globally for exposure. This raises the real question. Will the UK’s ban make any practical difference or does it risk limiting the options available to organisations when they most need them?
Why is the UK banning ransomware payments?
Banning ransomware payments in the public sector is a substantial move by the UK, intended to break the business model of ransomware groups. The rationale is clear. Ransom money inevitably flows to unethical sources and the government wants to disrupt this cycle.
Yet in practice, public sector organisations in the UK have rarely paid ransoms anyway. The British Library, for example, refused to pay during its 2023 cyberattack and was publicly commended by the National Cyber Security Centre. In that sense, the ban is more symbolic than transformative. A statement of principle, rather than a policy that fundamentally changes the threat landscape.
The UK is keen to set a precedent, which is positive in principle but lacking in practicality. Ransomware is still rising, fuelled largely through attacks on private organisations, often via third-party providers who are not bound by the new restrictions. For criminals, the financial incentive remains strong.
That said, the public sector has shifted its mindset. Cybersecurity was once seen as costly overhead; today, it is viewed as a strategic investment and even a national security imperative. Initiatives such as the UK’s Cyber Essentials (the government recommended minimum standards), the NHS’ ten year strategic plan with digitisation at its core and now the ransomware ban reflects that commitment.
Is a ban effective?
Everyone is wondering the same thing: will banning payments work to reduce ransomware attacks? As this is a relatively contemporary debate, there is very little evidence so far that a ban is effective. When previously discussed in the US, AON concluded that it was too soon to determine whether a ban would decrease attacks and even if it does, criminals would simply adapt their business models and other styles of attacks would take their place.
The risks of refusing to pay are real. Systems may be taken offline, which can have mass disruption in the public sector, or sensitive data may be made public. Meanwhile if a company pays the ransom, they are likely to get their data restored and systems returned online. While there is no guarantee and criminals may hold on to a copy of the data, it is typically in the ransomware groups’ best interests to follow through on their promises. An ‘’honour amongst thieves’ dynamic; if criminals did not give back control, no one would ever pay ransom again.
Complete prohibition removes the ability to make a rational business decision. In some cases, paying may be cheaper than the cost of recovery and reputational fallout. That’s why three quarters of UK business leaders surveyed by Commvault admitted they would pay a ransom if it was the best way to protect their business, regardless of a ban.
At the end of the day, businesses will take a rational risk approach, consider the trade off and pay ransom if it fits into their business model. While a ban may be feasible in the public sector, it is difficult to see how it can practically be applied across private, commercially driven companies.
The disclosure paradox
The most consequential element of the UK’s new legislation is not the ban itself, but the mandatory reporting requirement. All businesses (not just public sector organisations) must now disclose ransomware attacks.
In principle, this is a positive development. Greater visibility will help policymakers, industry and security experts build a clearer picture of the threat landscape and how it evolves.
But there is a catch. For many companies, the decision to pay ransom is motivated by discretion to contain reputational fallout and avoid shareholder panic. If disclosure is mandated, that discretion disappears. Unless the UK government offers incentives, such as additional support, intelligence sharing, or protection against liability, businesses may be reluctant to comply fully. Just as with choosing whether to pay ransom, companies will make a commercially driven decision on whether to report, based on what’s best for the business.
Alternative government initiatives
If the goal is to measurably reduce ransomware, bans alone are insufficient. A more pragmatic approach is to empower organisations with actionable intelligence.
The US Cybersecurity and Infrastructure Security Agency (CISA) maintains a catalogue of Known Exploited Vulnerabilities (KEVs). There are hundreds of thousands of vulnerabilities that exist in the global digital supply chain but only a fraction of those are targeted and exploited by criminals. By focusing on those that matter most, organisations can prioritise resources where they will have the greatest impact.
Bitsight’s research shows that organisations concentrating on KEVs measurably reduce their probability of incident. High-performing organisations limit the number of exploitable vulnerabilities they carry and remediate them quickly.
Knowing which vulnerabilities to prioritise is not only beneficial for resourcing but also a business’ best shot at staying one step ahead of ransomware groups. If the UK government wants to address rising ransomware attacks and offer pragmatic solutions that help protect public and private sector organisations, they should collect and share resources of vulnerabilities they know to be actively exploited by ransomware groups.
Providing this resource helps organisations to filter what can be an overwhelming threat intelligence landscape, identifying and addressing the most productive pain points.
A final word
The UK’s ransomware payment ban is well-intentioned and symbolically powerful, but unlikely to disrupt the economics of ransomware on its own. Attackers will continue to target private organisations and businesses will continue to act in their own commercial interests when faced with existential threats.
The real progress will come not from prohibition, but from prevention and pragmatic intelligence-sharing. Governments should focus on enabling organisations to harden their defences, prioritise the vulnerabilities most likely to be exploited and build resilience into their operations.
Symbolism may set the tone, but measurable, intelligence-driven action is what will truly shift the balance of power away from cybercriminals.


