Sources: UK companies tell the UK that a planned ban on paying ransoms to ransomware gangs is unlikely to stop attacks and could result in services collapsing
Kieran Smith / Financial Times : LinkedIn: Greg Palmer . Mastodon: @GossiTheDog@cyberplace.social LinkedIn: Greg Palmer : Georgina Kon and I spoke with Kieran Smith from the Financial Times about the UK's proposed ban on ransomware payments for critical infrastructure. … Mastodon: Kevin Beaumont / @GossiTheDog@cyberplace.social : These companies are self interested morons who just want to pay organised crime gangs to save their own skin rather than do cybersecurity well. https://www.ft.com/...
Context & Ripple Effects
The UK’s planned restrictions on ransom payments for public-sector and key-infrastructure organizations were already set out in the government’s proposed ransomware-payment ban. This report adds operational resistance from affected companies, centered on continuity of essential services rather than disagreement over the threat itself.
The dispute sits against a longer policy problem: ransomware groups have been described as operating at global scale with substantial resources, complicating prescriptions that organizations can simply harden themselves out of the risk.
First-order effects
- The government faces a sharper implementation trade-off: a payment ban may deny attackers revenue, but covered operators warn that it could remove a last-resort option during a disruptive incident.
- Critical-service organizations would need clearer recovery, incident-response, and escalation plans if payment is no longer available; the report indicates they do not regard the ban alone as a deterrent to attacks.
Second-order effects
- The argument shifts the policy debate from whether to prohibit payments to whether resilience requirements and state support can prevent service failure when victims cannot pay.
- A ban confined to UK critical infrastructure could redirect pressure onto suppliers and other organizations outside the covered category, while leaving attackers’ targeting incentives unresolved unless enforcement and defenses change together.
Third-order effects
- If payment restrictions advance, ransomware policy is likely to be judged less by the number of payments blocked than by whether essential operators can sustain and restore services without capitulating.
- The broader direction is toward treating ransom payments as a systemic-finance and national-resilience issue, though the corpus does not establish that a UK-only ban would materially reduce attacks.
The trend: Governments are moving from discouraging ransomware payments toward constraining them, forcing critical operators to substitute operational resilience for ransom-funded recovery.