UK IT Channel News | IT Channel Oxygen
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
Members
Must-Know Distributors
Oxygen 250
No Result
View All Result
  • News
  • Topics
    • Vendor
    • Distributor
    • Partner
    • Indepth
    • Sustainability
    • M&A
    • People Moves
    • AI
    • Tech trends
  • Pulsant Zone
  • About Us
  • Partner with us
No Result
View All Result
UK IT Channel News | IT Channel Oxygen
No Result
View All Result
Home Cybersecurity

‘Impossible to enforce’ – 5 MSSPs weigh in on UK ransomware payment ban

Leaders of partners including Softcat and SEP2 disagree on effectiveness of government ban unveiled this week

Oxygen staff by Oxygen staff
25 July 2025
in Cybersecurity, Indepth
‘Impossible to enforce’ – 5 MSSPs weigh in on UK ransomware payment ban
Share on LinkedinShare on Twitter

“It’s easy to say that no one should ever pay a ransom”

Juliette Hudson, Cybaverse
Juliette Hudson, Cybaverse

Juliette Hudson, CTO, Cybaverse

The government is clearly hoping these actions will have an impact on the ransomware economy and make it harder for threat actors to monetise from the UK.

By introducing a formal payment ban on government-linked organisations, this should in theory make them less attractive to money-motivated attackers. However, given that this is only on a subset of the types of threat actors targeting these organisations, it will never diminish the threat entirely.

In the current geopolitical landscape, it’s safe to say that not all ransomware attacks are directly motivated by money. In some cases, nation state actors are targeting critical infrastructure motivated purely by gathering intelligence or cause societal harm. A payment ban will do nothing to thwart these attacks.

The movement to mandate private organisations to report payments is interesting, as it also should in theory put organisations off paying.

Paying demands is bad PR. It doesn’t reflect well on an organisation’s reputation, so making organisations report payments to governments could put them off paying in the first place out of the fear of negative publicity.

Now that this data will be held by the government, it will be likely be covered by Freedom of Information requests. While the government won’t ever disclose individual names of businesses, it could still make organisations nervous about getting caught up in such requests.

The information that will be provided to private sector organisations intending to pay will also be helpful, as it will better educate them on the impacts of paying, and how it could expose them to more attacks in the future.”

It’s easy to say that no one should ever pay a ransom, and while that’s much harder to put into practice during a real-world incident, especially under pressure, it remains the stance we should strive for if we want the best chance at disrupting these groups long term. 

However, in practice, the decision to pay a ransom is rarely black and white. For many organisations, particularly in critical services like healthcare, transport, or utilities, downtime can have life-threatening consequences. When all recovery options are exhausted and systems are offline, leadership may be faced with the grim reality that paying is the fastest, or only, way to restore essential services.

In those scenarios, the government’s payment ban on public-sector entities can be both a safeguard and a constraint. It prevents public money from funding criminal enterprises, but it also demands that these organisations have extremely robust resilience and recovery plans in place. This policy shift will only succeed if it’s supported by increased funding, stronger incident response capabilities, and mandatory testing of business continuity plans across government-affiliated entities.

Softcat’s Paul Fleming warned the move could have “unintended consequences”. See final page for more…

Page 4 of 5
Prev1...345Next
Tags: CybaVersefeaturedmemberPerformantaRed HelixSEP2SoftcatTrending
Previous Post

Retail bigwig invests £2.5m in Tactus successor Chillblast Group

Next Post

Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they’re winning on AI

Related Posts

Ingram Micro HQ
Cybersecurity

Ingram Micro says July ransomware attack hit 42,000 people

20 January 2026
Matthew Parker, Xypher
Big Interview

Parker to build ‘really big’ cyber business with Xypher

19 January 2026
Max Harper and Ben Konipinski, Koncise 2026
M&A

Koncise brings techie nous in-house with first acquisition

15 January 2026
Hayley Roberts, Distology 2026
Big Interview

‘Every part of the engine is super tight’ – Distology CEO gears up for growth after Tenable signing

13 January 2026
Patrick Zammit, TD Synnex
Big Interview

TD Synnex CEO on European portfolio gaps, Exertis rightsizing and kit shortages

12 January 2026
Rob Davies, BCN
Big Interview

BCN to ‘get more cerebral’ on M&A amid agentic AI push

12 January 2026
Ian Brown, Integrity360
M&A

Integrity360’s M&A spree reaches North America

6 January 2026
The 10 most acquisitive IT resellers and MSPs of 2025
M&A

The 10 most acquisitive IT resellers and MSPs of 2025

5 January 2026
Next Post
Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they’re winning on AI

Oxygen 250 leaders on what channel partners should call themselves in 2025, and where they're winning on AI

Follow Us

IT Channel Oxygen keeps you informed on the UK IT channel and its sustainable transformation. Learn more

  • About
  • Our Team
  • Partner with us
  • Privacy Policy
  • Terms & Conditions
  • News
  • Cookie Policy (UK)

© 2025 IT Channel Oxygen

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Oxygen 250
  • Must-Know Distributors
  • Member area
  • Big Interview
  • Pulsant Zone
  • News
  • Indepth
  • About
  • Partner with us

© 2025 IT Channel Oxygen