Skip to content
TrackPodcasts
businessJan 29, 2026

The Case for a Ransom Payment Ban and When It Might Happen

About this episode

Britain will likely ban at least some types of ransom payments as it revamps the nation's cybersecurity laws, but many open questions remain, including sectors and the organizational sizes to be covered, and if all payments might be required to pass sanctions checks, said policy expert Jen Ellis.

Get every episode summarized

Each time Credit Union Information Security Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

316 searchable segments. Every word is indexed and playable.

The Case for a Ransom Payment Ban and When It Might Happen

Credit Union Information Security Podcast

0:00
0:00

Full transcript

Credit Union Information Security PodcastThe Case for a Ransom Payment Ban and When It Might Happen. Machine-transcribed; use the interactive transcript above to jump the player to any line.

Hi, I'm Matthew Schwartz with Information Security Media Group. It is my pleasure to be sitting down again with Jen Ellis, the founder of Next Jen Security Jen. Welcome. Hey, Matthew. Thank you for having me. Really happy to have you. We're in London. Are we looking to river? Overlooking the river. It's a beautiful day. What could be better? Except also talking about cyber security. Right. So on that front. Have we solved it? Is that why it's such a beautiful day? Exactly. Yes. The future of TV is well in hand. No more legislation is required. And there's never been any trouble anymore with this thing called ransomware. Right. No, absolutely. Speaking of, we're here in the UK. And they're grappling with ransomware. They've seen a couple of attacks over the last 5, 10, 12, 6. We've had an issue for the last 5, 10, 12, 6 months. Yeah, yeah. Anyone who isn't a Jaguar Land Rover, it's maybe been a little personal for them. And when it starts to get personal, we start to see the government get pretty involved, personal on the economy front.

I should say for the government and for the rest of us then well over a billion in fallout estimated from just that Jaguar Land Rover attack. And if you choose supply chain and price, yeah. Exactly. So very topical, very top of mind, especially for a lot of lawmakers. One of the responses, not just to that attack, because it was already in the wind, is what to do about ransomware? Yes. Possibly. Possibly, I emphasize, outlawing the payment of ransoms, at least by things like hospitals or public bodies, or maybe anybody. Yeah, so the consultationally UK government put out actually gave options of who it would apply to. So it's unclear which direction we'll go and because they haven't come out with something to say publicly where they're going. So it's possible that it would just be an economy wide ban. It's possible that it would be companies above some size or that it would be specific sectors, as you said, a critical infrastructure and government, et cetera. I think it'll be broader than that. It's my guess, but it's purely speculative.

And I think there is a debate here on how impactful a ban will be. I mean, for sure, it will have impact, whether it will stop attacks, I'm less convinced by. Well, you often see lawmakers saying, this is a problem we've passed the law. Yeah. And there's no magic wand of work that they can win. And the attackers, wherever they're located, say, teenagers, in the London area, teenagers, or older and Russia, they're not necessarily going to go to the UK's off or targeting these now. And I mean, also, it's not really how the internet works, is it? I mean, you know, when we saw, for example, a mere scum and a muck getting caught up in, not pettia, they weren't really, not that not pettia, it was around the maritime body before anyone writes in. But they weren't really targeting those specific companies. And yes, they got hit because they did business in Ukraine, but nonetheless, it does show how these things spread, right? So I'm not wildly convinced.

I think the bottom line here is that UK companies will continue to be appealing targets because we're relatively wealth and nation. We have a high degree of reliance on digital infrastructure. And we have an adversarial relationship with a number of governments that provide safe harbors. And then on top of that, we also have homegrown attackers who have their own axe grind, or who want to make a name for themselves at home by targeting big brands here. And so I think none of that goes away. I think all that happens is it becomes much harder for victims. On the flip side, I think there is a view that some people have where they would like to be able to say, we cannot pay because the government won't let us, right? It does enable them to say that not only to the attackers, but also to their shareholders, to their customers, right? Like, it's not our fault that we haven't done this, right? I think that is an important thing. And I also think there is, this is one of those situations where there is an ethical implication here of funding crime that you do have to take into consideration. So the fact that it won't necessarily stop the crime

isn't necessarily reason not to have the ban, right? Like, there is still an element there. But then you also have to think about the fact that what you're doing is mandating the behavior of victims rather than mandating the behavior of the attackers. That's not great. No, I mean, you see in the States, for example, the FBI has been really good about getting agents on site for organizations that have gotten hit. And I've heard from my answer to the responders that this has helped, I think, drive the thinking of the board or the CEO in a direction that isn't just, let's pay just in case. And so that's been really useful. I don't know if there are analogs elsewhere. I mean, the FBI as an institution and entities, obviously very American, you know, you don't hear about the NCA necessarily deploying always to victims. But you hear less about that, I think. A lot of organizations say we are working with the CSE. I mean, I think it depends, right? I think so. One, I think the NCA gets involved whenever it makes sense to, they can't do everything, right? We are a resource constrained. And I, and by the way, the FBI do not get involved

in everything, but they are also a much larger force and they have more regional representation, right? There are field officers of the FBI across the US. I think NCA is a little bit more limited in what it's able to do, but I think for sure, I mean, you know, the fact that we have seen very quick arrests around TFL, around MNS, and around JLR, is a sign that they are very engaged. They are, they are working on this. They're working with regional police around the UK. It's not just NCA. And I think NCA does get involved, but they're really specifically to focus as much as they can on critical national structure and government. So they're not necessarily going to be involved with everything, but they also do get involved in the ones that have the greatest impact on the economy. So you can bet that they've been involved with the big ones we've seen in the UK. So I don't think it's a lack of getting involved. I will say I think a lot of the decision making over whether or not to pay is more readily influenced by both insurance companies if you have cyber insurance, which you may not, you know, market adoption

in the UK is still relatively low. Or your law firm, you know, they will also be advising you on what you can't do and what you should continue to do. So I think companies in these situations will look to a lot of different sources to get advice. And I think ultimately they'll also try and figure out like what is the most practical thing for their particular situation based on the customer climate, their shareholder climate, you know, basically what the tolerance is for not paying or what the clients are surveying because lots of people will have an ethical problem with it. But likewise, a lot of people want to see a business up and running as quickly as possible. Well, I've also spoken to victims where the data that got exposed was especially sensitive, maybe you know, maybe an involved children, and they maybe don't want to pay it, but they did because there were children involved and it's very hard to fault them for that. Yeah, and we also are seeing now a bit of a rise of a more the tigious environment here. So we've seen class actions around co-op of MNSs.

And I think, you know, this is one of those things where if people have suffered real tangible harm, then absolutely they should have an opportunity for recourse, particularly to cover whatever, you know, expenses they in themselves have incurred through no fault or own. However, I think we do need to think about what harm really looks like and what we mean by that. Simply having your PII exposed is not the same as experiencing harm in my view. Now, if something happens because of that and you can prove that that relationship has occurred, that's a different thing. But I think we have to think about whether this rise of class action suits is likely to limit how much people want to then be upfront and transparent about what's going on, which doesn't, you know, security by obscurity doesn't really benefit anybody, let's be honest, other than the attackers who love it. Well, there's still a real dearth of information about what happened, when it happened, and we see. And that's one of the other parts of the government proposal. So there are three elements to it. The first is a payments ban.

The second is absolutely that they call a payments reductions. I can't remember. Basically, it's that if you get hit, even if you're not in the category that has a ban, you have to go to the government and ask permission. I'm vetting, basically. Yeah, and it's, you know, is designed to basically figure out whether like the people that you'll be paying a sanction to that kind of thing. And then the third category, as you were saying, wait, it's the incident reporting requirement. And I think the incident reporting requirement will be broad. Again, they've not confirmed that they gave options in the consultation, but I suspect it will be very broad. I think it will be for organizations of other certain sizes. I doubt it will be sector-specific. And that hopefully will start to uplevel the amount of information and visibility we have into what's really going on. So some of that sounds like a slam dunk from a defensive standpoint about the information sharing, for example. Do you think there is a chance the ban will or won't happen? Still, I mean, it seems pretty contentious. I think it will happen. I think we will probably hear more about it

in the early-ish part of this year. That feels like approximately the right time frame from when they came out with their response to the consultation and said, this is what we heard. I think really the UK government, so there's three major things, really, that they're working on. I mean, there's lots of things they're working on, but for cyber, there's, there's the, the cyber security resilience bill, which has had its first reading in the House of Commons. There is the new National Cyber Security Action Plan. And then there's this. And the timeline on CSRB and the Action Plan means that they're sort of higher up in the, they're further along in the lifecycle process. So I suspect what will happen is on the ransomware stuff, they will let those things clear through before they kind of come through with the ransomware thing. I think it's just a bit of a cleaner message if they do it that way, rather than having everything come at once. When arguably better to, I mean, ransomware does, it has been evolving quite a bit lately. We've seen a real change in focus. I mean, you and I were speaking before about how

it was much more of a national security threat before. And there's been a shift toward more data exfiltration, which changes the equation, perhaps, slightly. I don't know that it is true everywhere. I think, I mean, I think if you look at, for example, the rise of drag and force, it's, you know, demonstrably in the other direction, right? It is based on, it's still disruption-based attacks. I think it is true in certain places. So we see it in the US. There's been a real swing away from disruption-based attacks and towards, towards data exfiltration-based attacks. And we did see that in the UK. We saw that over the past couple of years. But then we've gone back to disruption-based attacks. And I think a part of that is the nature of who the attackers are and what their goal is. The thing that people need to remember is that it's catastrophic spider are anomalous. They are not the norm that we see. We've heard a lot about them. And therefore, it's easy to think that they're the new normal, but they are still in a anomaly. A very important anomaly that we should totally pay attention to, but they aren't representative of the whole. And if you're trying to craft policy,

you need to be able to get this craftful about signal versus noise. Absolutely. And I think in reality, it's actually quite a hard craft policy that would deal with the situation like a scatter spider. I think actually the best thing you can do in that situation is exactly what they're doing, which is make arrests quickly and move those arrests through the, through the duty of your process, which they are doing. And I think we have to hope that that will do its job as a deterrent over time. So I think it remains to be seen whether the UK's, I think they will move forward with their proposals. I'm not. I'm less confident on what impact the proposals will have. Well, it'll be interesting to see them move their way through. It sounds like it's going to be a fun 2026. Oh, it'll be an interesting one, for sure. Well, Jen, always a pleasure to sit down with you. Thank you for bringing me up to date on just a few of the things you're going on. Yes, from someone who's going on now. I'm a security front. Look forward to catching up again soon. Yeah, likewise. Thanks very much. I've been speaking with Jen Ellis, founder of Next Jen

Security. I'm Matthew Schwartz with ISMG. Thanks for joining us.

More episodes

More from Credit Union Information Security Podcast

View all episodes →