UK IT Channel News | IT Channel Oxygen
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Sustainability
  • About Us
  • Partner with us
Members
Must-Know Distributors
Oxygen 250
No Result
View All Result
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Sustainability
  • About Us
  • Partner with us
No Result
View All Result
UK IT Channel News | IT Channel Oxygen
No Result
View All Result
Home Cybersecurity

‘Impossible to enforce’ – 5 MSSPs weigh in on UK ransomware payment ban

Leaders of partners including Softcat and SEP2 disagree on effectiveness of government ban unveiled this week

Oxygen staff by Oxygen staff
25 July 2025
in Cybersecurity, Indepth
‘Impossible to enforce’ – 5 MSSPs weigh in on UK ransomware payment ban
Share on LinkedinShare on Twitter

“It’s easy to say that no one should ever pay a ransom”

Juliette Hudson, Cybaverse
Juliette Hudson, Cybaverse

Juliette Hudson, CTO, Cybaverse

The government is clearly hoping these actions will have an impact on the ransomware economy and make it harder for threat actors to monetise from the UK.

By introducing a formal payment ban on government-linked organisations, this should in theory make them less attractive to money-motivated attackers. However, given that this is only on a subset of the types of threat actors targeting these organisations, it will never diminish the threat entirely.

In the current geopolitical landscape, it’s safe to say that not all ransomware attacks are directly motivated by money. In some cases, nation state actors are targeting critical infrastructure motivated purely by gathering intelligence or cause societal harm. A payment ban will do nothing to thwart these attacks.

The movement to mandate private organisations to report payments is interesting, as it also should in theory put organisations off paying.

Paying demands is bad PR. It doesn’t reflect well on an organisation’s reputation, so making organisations report payments to governments could put them off paying in the first place out of the fear of negative publicity.

Now that this data will be held by the government, it will be likely be covered by Freedom of Information requests. While the government won’t ever disclose individual names of businesses, it could still make organisations nervous about getting caught up in such requests.

The information that will be provided to private sector organisations intending to pay will also be helpful, as it will better educate them on the impacts of paying, and how it could expose them to more attacks in the future.”

It’s easy to say that no one should ever pay a ransom, and while that’s much harder to put into practice during a real-world incident, especially under pressure, it remains the stance we should strive for if we want the best chance at disrupting these groups long term. 

However, in practice, the decision to pay a ransom is rarely black and white. For many organisations, particularly in critical services like healthcare, transport, or utilities, downtime can have life-threatening consequences. When all recovery options are exhausted and systems are offline, leadership may be faced with the grim reality that paying is the fastest, or only, way to restore essential services.

In those scenarios, the government’s payment ban on public-sector entities can be both a safeguard and a constraint. It prevents public money from funding criminal enterprises, but it also demands that these organisations have extremely robust resilience and recovery plans in place. This policy shift will only succeed if it’s supported by increased funding, stronger incident response capabilities, and mandatory testing of business continuity plans across government-affiliated entities.

Softcat’s Paul Fleming warned the move could have “unintended consequences”. See final page for more…

Page 4 of 5
Prev1...345Next
Tags: CybaVersefeaturedmemberPerformantaRed HelixSEP2SoftcatTrending
Previous Post

Retail bigwig invests £2.5m in Tactus successor Chillblast Group

Next Post

Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they’re winning on AI

Related Posts

5 key takeaways from Adarma administrator’s report
Cybersecurity

5 key takeaways from Adarma administrator’s report

28 August 2025
Marion Stewart, CEO, Red Helix
M&A

Red Helix met over 20 firms in maiden acquisition hunt, CEO reveals

27 August 2025
Sanjay Beri, Netskope
Cybersecurity

Netskope generates 95% of its business from partners, IPO filing reveals

25 August 2025
Top 10 biggest distribution stories of 2025 so far
Distributor

Top 10 biggest distribution stories of 2025 so far

20 August 2025
Oxygen Influencers 2025 – have your say…
Indepth

Oxygen Influencers 2025 – have your say…

14 August 2025
Top 10 biggest channel partner stories of 2025 so far…
Partner

Top 10 biggest channel partner stories of 2025 so far…

11 August 2025
Martin Neale, ICS.AI
AI

UK can ‘lead the world’ on AI adoption, CEO of ambitious Microsoft AI partner claims

8 August 2025
Bluecube acquires legal-focused MSP crippled by cyber incident
Cybersecurity

‘Companies are waking up to the risks’ – European cyber growth hits 13%

7 August 2025
Next Post
Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they’re winning on AI

Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they're winning on AI

Follow Us

IT Channel Oxygen keeps you informed on the UK IT channel and its sustainable transformation. Learn more

  • About
  • Our Team
  • Partner with us
  • Privacy Policy
  • Terms & Conditions
  • News
  • Cookie Policy (UK)

© 2025 IT Channel Oxygen

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
No Result
View All Result
  • Oxygen 250
  • Must-Know Distributors
  • Member area
  • KOcycle Zone
  • Big Interview
  • News
  • Indepth
  • About
  • Partner with us

© 2025 IT Channel Oxygen