Block the payout, brace for impact: navigating the potential ransomware payment ban



The UK Government put forward a consultation to ban public sector organizations from paying ransomware demands. An enacted ban would prohibit central and local government organizations, as well as other bodies considered Critical National Infrastructure (CNI), from making payments to a threat actor in the event of a ransomware attack.

One pro-ban theory is that this kind of restriction would remove an attacker’s justification or desire to attack. Knowing they won’t get paid, an attack is a waste of time, right? But would this actually work? To the credit of pro-ban believers, there’s also no guarantee that payment to an attacker will result in the promised decryption or safe return of stolen information – attackers may just take the money and run.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *