UK IT Channel News | IT Channel Oxygen
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
Members
Must-Know Distributors
Oxygen 250
No Result
View All Result
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
No Result
View All Result
UK IT Channel News | IT Channel Oxygen
No Result
View All Result
Home Cybersecurity

‘Impossible to enforce’ – 5 MSSPs weigh in on UK ransomware payment ban

Leaders of partners including Softcat and SEP2 disagree on effectiveness of government ban unveiled this week

Oxygen staff by Oxygen staff
25 July 2025
in Cybersecurity, Indepth
‘Impossible to enforce’ – 5 MSSPs weigh in on UK ransomware payment ban
Share on LinkedinShare on Twitter

“It’s easy to say that no one should ever pay a ransom”

Juliette Hudson, Cybaverse
Juliette Hudson, Cybaverse

Juliette Hudson, CTO, Cybaverse

The government is clearly hoping these actions will have an impact on the ransomware economy and make it harder for threat actors to monetise from the UK.

By introducing a formal payment ban on government-linked organisations, this should in theory make them less attractive to money-motivated attackers. However, given that this is only on a subset of the types of threat actors targeting these organisations, it will never diminish the threat entirely.

In the current geopolitical landscape, it’s safe to say that not all ransomware attacks are directly motivated by money. In some cases, nation state actors are targeting critical infrastructure motivated purely by gathering intelligence or cause societal harm. A payment ban will do nothing to thwart these attacks.

The movement to mandate private organisations to report payments is interesting, as it also should in theory put organisations off paying.

Paying demands is bad PR. It doesn’t reflect well on an organisation’s reputation, so making organisations report payments to governments could put them off paying in the first place out of the fear of negative publicity.

Now that this data will be held by the government, it will be likely be covered by Freedom of Information requests. While the government won’t ever disclose individual names of businesses, it could still make organisations nervous about getting caught up in such requests.

The information that will be provided to private sector organisations intending to pay will also be helpful, as it will better educate them on the impacts of paying, and how it could expose them to more attacks in the future.”

It’s easy to say that no one should ever pay a ransom, and while that’s much harder to put into practice during a real-world incident, especially under pressure, it remains the stance we should strive for if we want the best chance at disrupting these groups long term. 

However, in practice, the decision to pay a ransom is rarely black and white. For many organisations, particularly in critical services like healthcare, transport, or utilities, downtime can have life-threatening consequences. When all recovery options are exhausted and systems are offline, leadership may be faced with the grim reality that paying is the fastest, or only, way to restore essential services.

In those scenarios, the government’s payment ban on public-sector entities can be both a safeguard and a constraint. It prevents public money from funding criminal enterprises, but it also demands that these organisations have extremely robust resilience and recovery plans in place. This policy shift will only succeed if it’s supported by increased funding, stronger incident response capabilities, and mandatory testing of business continuity plans across government-affiliated entities.

Softcat’s Paul Fleming warned the move could have “unintended consequences”. See final page for more…

Page 4 of 5
Prev1...345Next
Tags: CybaVersefeaturedmemberPerformantaRed HelixSEP2SoftcatTrending
Previous Post

Retail bigwig invests £2.5m in Tactus successor Chillblast Group

Next Post

Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they’re winning on AI

Related Posts

James Napp, Bechtle
Big Interview

‘£1bn is the ultimate goal’ – Bechtle open to more UK acquisitions

3 December 2025
Ian Brown, Integrity360
M&A

South Africa’s special nearshore status cemented by Integrity360 triple acquisition

2 December 2025
AWS Marketplace’s $1bn-selling ISVs revealed
Tech trends

AWS Marketplace’s $1bn-selling ISVs revealed

1 December 2025
Neil Hall, Channel Chat
Big Interview

‘You’ll see us accelerate again’ – Neil Hall on plans to ‘3X’ Focus Group

26 November 2025
Adrian Saint, SCC
Sustainability

‘I dare to dream’: Can SCC become the king of refurbished IT?

20 November 2025
Vince Mignacca, Co-Founder, Sohin Raithatha, CEO and Co-Founder, Redsquid
M&A

Redsquid hits £25m with deal that ‘changes everything’

19 November 2025
‘Having its CrowdStrike moment’ – Cloudflare recovers from outage
Cybersecurity

‘Having its CrowdStrike moment’ – Cloudflare recovers from outage

18 November 2025
Should ‘every’ UK firm have cyber insurance? 6 MSSPs agree, but with provisos…
Cybersecurity

Should ‘every’ UK firm have cyber insurance? 6 MSSPs agree, but with provisos…

18 November 2025
Next Post
Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they’re winning on AI

Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they're winning on AI

Follow Us

IT Channel Oxygen keeps you informed on the UK IT channel and its sustainable transformation. Learn more

  • About
  • Our Team
  • Partner with us
  • Privacy Policy
  • Terms & Conditions
  • News
  • Cookie Policy (UK)

© 2025 IT Channel Oxygen

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Oxygen 250
  • Must-Know Distributors
  • Member area
  • Big Interview
  • Pulsant Zone
  • News
  • Indepth
  • About
  • Partner with us

© 2025 IT Channel Oxygen