The UK government has confirmed it will proceed with all three proposals from its 2025 ransomware consultation — and the most operationally significant one for UK businesses is mandatory pre-payment notification. If your business is hit by ransomware and you intend to pay the ransom, you will soon be legally required to tell the government first. No payment without notification.
This is a significant shift. Currently, UK businesses that pay ransoms do so quietly. The government estimates that only a fraction of ransomware incidents are ever reported, which means law enforcement and the National Cyber Security Centre are operating with an incomplete picture of the threat. The new regime aims to change that — and creates new legal obligations for businesses that get caught in an attack.
The three confirmed measures
Mandatory incident reporting. Any organisation that suffers a ransomware attack will be required to report it to the government within a defined window — the current proposals suggest 72 hours — with parallel notification to the NCSC. This is separate from, and additional to, the 24-hour initial incident notification required under the Cyber Security and Resilience Bill for in-scope organisations. For most SMEs, this will be the first time ransomware incidents carry a mandatory reporting obligation.
Pre-payment notification. Before making any ransom payment, organisations must notify the government. This is not a requirement for approval — you are not asking permission — but the government needs to know that a payment is being made, to whom, and in what amount. The purpose is twofold: to improve intelligence on ransomware groups receiving UK payments, and to allow authorities to check whether the recipient is a sanctioned entity. Paying a sanctioned group is already a criminal offence; this notification step is partly designed to protect businesses from accidentally doing so.
Ban on public sector ransom payments. Public sector bodies and operators of critical national infrastructure will be prohibited entirely from paying ransoms. This does not directly affect most SMEs, but it shapes the threat landscape — if public sector targets become non-paying, ransomware groups are likely to focus more attention on private sector organisations where payment remains legal.
Why this matters now even though the law isn’t passed yet
The Cyber Security and Resilience Bill — the legislation that will underpin most of these measures — has completed all Commons stages and is progressing toward Royal Assent. Even where specific ransomware provisions come via secondary legislation, the direction is settled. The government has confirmed all three proposals will proceed.
The practical implication for SMEs is that the window to prepare is now. The most common reason organisations fail to report promptly is that they have no documented incident response process. When ransomware hits, the first hours are chaotic. Knowing in advance who to call, what to log, and what regulatory notifications are required is the difference between a managed incident and a compliance failure layered on top of an operational crisis.
What your business needs in place before this becomes law
An incident response plan that includes ransomware scenarios. This does not need to be complex — a one-page document covering who leads the response, who communicates externally, and which regulators need to be notified covers the basics. The NCSC’s free incident response guidance is a useful starting point.
A sanctioned entities check in your payment decision process. If ransomware hits and the temptation to pay quickly and move on is strong, someone in your organisation needs to be the person who asks: have we checked whether this recipient is on a sanctions list? The Office of Financial Sanctions Implementation (OFSI) maintains the UK Consolidated List.
Cyber insurance review. Many cyber insurance policies already require notification of the insurer before any ransom payment. Check whether your policy conditions align with the incoming legal requirements — there may now be a legal obligation where previously there was only a contractual one.
Documented evidence of your security posture. In any post-incident investigation or enforcement action, having evidence that your organisation had reasonable security controls in place matters. Cyber Essentials certification, recent vulnerability assessments, and MFA enforcement across your systems all support a credible defence.
KeepSafe.Report monitors the cyber incident and regulatory landscape for UK businesses, surfacing the obligations that are coming before they become urgent. For businesses that need help building incident response capability from scratch, CoolCoding.co.uk works with SMEs on the technical infrastructure that makes incident detection and response faster and more reliable.
The bottom line
Ransomware is now a regulatory event, not just a business continuity one. The government’s confirmed measures create new legal obligations around disclosure and pre-payment notification that most UK businesses have never had to consider before. Getting your incident response process documented and tested now — before you need it — costs far less in time and money than building it under pressure while attackers wait for a decision.