UK Ransomware Laws: What Your Business Must Do

The UK government has confirmed it will legislate three new measures specifically targeting ransomware attacks. The announcements followed a formal public consultation, and the parliamentary process is well underway: the Cyber Security and Resilience Bill completed its Commons stages on 10 June 2026 and has moved to the House of Lords, while a separate Cyber Extortion and Ransomware (Reporting) Bill is also progressing through Parliament. Royal Assent on the main bill is expected later in 2026, with phased implementation likely to extend into 2027 and 2028.

The direction of travel is clear. Businesses that start preparing now will be in a much stronger position than those who wait for the deadline to arrive.

The three new ransomware measures

1. A payment ban for public sector organisations

NHS trusts, local councils, schools, and organisations operating critical national infrastructure – utilities, transport, financial services – will be prohibited from paying ransomware demands. The rationale is straightforward: if those targets cannot pay, criminal groups have less financial incentive to attack them.

2. A payment notification regime for private businesses

Private sector businesses not covered by the ban above will retain the legal right to pay a ransom, but they will be required to notify the government before doing so. This creates a window for the National Cyber Security Centre (NCSC) and law enforcement to advise against payment, investigate the threat actor, or potentially assist with data recovery by other means. Paying without notifying is expected to be a breach of the new rules.

3. Mandatory incident reporting for all organisations

Any organisation – regardless of size or sector – that suffers a ransomware attack will be required to report it to the relevant authority, most likely the NCSC, within 72 hours of becoming aware of it. A more detailed follow-up report will then be due within 28 days. This mirrors the existing requirement under UK GDPR to report personal data breaches to the Information Commissioner’s Office (ICO) within 72 hours, but applies to ransomware incidents regardless of whether personal data is involved.

Why it matters to your business

Ransomware – where attackers encrypt your files and demand payment to restore access – is one of the most damaging cyber threats facing UK small and medium-sized businesses. Many smaller organisations have quietly paid ransoms in the past, reasoning it was faster and cheaper than the alternative. These new laws change that calculation significantly.

The practical impact on SMBs breaks down like this:

  • Paying quietly is no longer an option. Even if the outright ban does not apply to your organisation, the payment notification requirement means any ransom you pay will be on record with government authorities. Your insurer, your regulator, and the NCSC will be informed.
  • 72 hours is very little time. In the immediate aftermath of a ransomware attack, your team will be scrambling to contain damage, understand what happened, and work out what data has been affected. Having 72 hours to also file a formal report with the government requires preparation in advance – you cannot improvise this under pressure.
  • Not reporting is likely to be treated as a compliance failure. The legislation is expected to include enforcement powers. The government’s stated aim is universal incident reporting so it can build a complete national picture of the ransomware threat. Businesses that fail to report are likely to face regulatory consequences, much as those who fail to report data breaches to the ICO do today.

None of this changes the fundamental guidance: the best outcome is to never be hit by ransomware in the first place, and the second-best outcome is to restore from clean, tested backups without paying anything. But these laws mean you also need a documented incident response process ready before an attack happens – not just technical defences.

What we have already done for managed clients

Clients on our managed IT services have ransomware defences in place as standard: ESET endpoint protection with behavioural detection to catch ransomware before it spreads, email filtering to block the phishing messages that most ransomware arrives via, and regular backups stored in a location isolated from the main network. We also maintain documented incident response processes – so if the worst does happen, we know immediately who to contact, what steps to follow, and how to meet reporting obligations within the required window.

What to check if no one is managing this for you

If your IT is self-managed, now is the time to act:

  1. Test your backups. Are they genuinely isolated from your main network? When did you last test a full restore? Backups that cannot be restored in practice are not backups.
  2. Review your endpoint security. Standard antivirus is not sufficient – you need behavioural protection that can detect and stop ransomware before it encrypts your files.
  3. Write a basic incident response plan. Even a single page that says “isolate affected machines, call your IT provider, notify your insurer, contact the NCSC” is far better than improvising in the middle of a crisis.
  4. Get familiar with the ICO reporting process. Under UK GDPR, you are already required to report personal data breaches within 72 hours. The ransomware reporting requirement will follow a similar model – understanding the existing process is a good starting point.

Our IT security team can review your current protections and help you build an incident response plan that will satisfy what the new legislation requires. We also help businesses work towards Cyber Essentials certification, which provides a strong technical baseline and demonstrates to clients, insurers, and regulators that you take security seriously.

The best time to prepare for a ransomware attack is well before one happens. If you would like to talk through where you currently stand, get in touch with the team and we will take it from there.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name