- UK law has no blanket ban on ransomware payments, but paying a group designated under UK financial sanctions is potentially illegal regardless of the payment amount
- The ICO has stated that paying a ransom does not mitigate a GDPR fine and does not remove your obligation to report the breach
- Roughly 40% of victims who pay do not recover all their data; data leaked under double-extortion models is rarely deleted regardless of payment
- Paying raises the probability of a repeat attack, as criminal groups mark compliant victims and return within 12 months in a significant proportion of cases
- Make the payment decision before an attack happens, as a board-level policy, not under crisis pressure with systems down
The UK legal position
No UK law bans organisations from paying ransomware demands. The Computer Misuse Act 1990 makes the attack itself illegal but says nothing about victim behaviour. The Proceeds of Crime Act 2002 raises questions about whether ransom payment could constitute money laundering in certain circumstances, but no victim organisation has been prosecuted for paying.
The real legal risk runs through the UK's financial sanctions framework. OFSI (the Office of Financial Sanctions Implementation) prohibits making funds available, directly or indirectly, to designated individuals or entities. Several major ransomware groups and their operators have been designated under UK sanctions, including individuals connected to LockBit, Conti, and Evil Corp. Paying these groups, even under duress, is a potential breach of financial sanctions law. OFSI can impose civil penalties without requiring proof of intent.
Before any payment, establish which group carried out the attack. Incident response firms with ransomware expertise can attribute an attack to a known group within hours. Paying a sanctioned group carries legal risk even if you did not know they were sanctioned at the time, though OFSI treats cooperation and voluntary disclosure as mitigating factors.
The NCSC advises against paying ransoms on the grounds that it funds criminal activity and invites further attacks. It stops short of threatening regulatory consequences for organisations that pay. The National Crime Agency asks all victims to report attacks, paid or unpaid, to support attribution and disruption operations.
What payment does not buy you
Paying a ransom assumes you receive a working decryption key and the attacker deletes your data. Neither is reliable.
Decryption is not guaranteed
Decryptors provided after payment are slow, prone to failure on large or complex file systems, and sometimes corrupt files rather than recovering them. Some groups supply decryptors that cover only specific file types. Even when a decryptor works, restoring systems takes longer than recovering from clean backups.
Data deletion is unverifiable
Double-extortion attacks, where the attacker exfiltrates data before encrypting it and threatens to publish unless you pay, are now the dominant ransomware model. No technical mechanism exists to confirm that an attacker deleted what they stole. Researchers tracking dark web leak sites have documented cases where data surfaced months after victims paid, sold separately by the criminal group or used as leverage in a second extortion attempt.
The ICO is not influenced by payment decisions
The ICO has been explicit on this. If a ransomware attack caused unauthorised access to personal data, you have a reportable breach under UK GDPR whether you paid or not. The ICO's assessment turns on whether you had appropriate technical and organisational measures before the attack. Your security posture before the incident is what they examine, not what you paid during it.
Cyber insurance implications
Most UK cyber insurance policies include ransomware coverage, but the interaction between coverage and payment decisions is more complex than policyholders usually expect.
Insurers require notification before any payment. Policies with ransomware coverage typically require insurer approval of, or at least notification of, any payment before funds transfer. Paying before you notify your insurer can void ransomware coverage. Some policies also exclude payments to sanctioned groups, which creates overlap with the OFSI risk above.
Insurers hold intelligence on ransomware groups that most victim organisations lack. Bringing your insurer in early, even if you decide not to pay, gets you that intelligence and the incident response resources most policies cover.
When organisations consider payment
Despite the risks, organisations do pay ransoms. Knowing the circumstances that drive those decisions helps you set policy before an attack happens.
- Irreplaceable data. Where backups do not exist, are encrypted, or are too old to be useful, payment may be the only path to data recovery. The NCSC acknowledges this argument without endorsing it.
- Critical service continuity. A hospital with patient data and clinical systems both encrypted faces a different calculation than a business that can restore from backup within 48 hours. The risk changes when disruption directly affects patient safety.
- Group reputation on decryption. Some ransomware groups maintain a reputation for providing working decryptors because their business model depends on victims trusting that payment produces results. Incident response firms track this by group. A group with a reliable decryption record is a different risk from one known for taking payment and disappearing.
None of these factors override the sanctions check. You cannot answer "should we pay?" before you answer "who are we paying?"
What to do before this decision matters
The conditions that make payment a serious option (no usable backups, systems down, no recovery path) are the conditions preparation removes or reduces.
- Tested, isolated backups. Backups stored on systems reachable from your production environment get encrypted alongside production in most ransomware attacks. Keep backups offline or logically isolated, and test recovery time and completeness at least quarterly.
- An incident response plan that covers the payment decision. Decide in advance who can authorise a ransom payment, who assesses the sanctions position, and who notifies the insurer and the ICO. Name those individuals now, not during an active incident.
- Cyber insurance you have read. Read the ransomware clause before an incident. Know the notification requirement, the pre-payment approval requirement, and what exclusions apply.
- A pre-engaged incident response firm. A retainer agreement gives you ransomware attribution expertise within hours of an attack, before any payment decision.
For a step-by-step playbook covering the first 72 hours after a ransomware attack, see our ransomware response guide. For recovery steps once systems are down, see our ransomware recovery guide.
When Paying Voids Your Cyber Insurance
Many UK cyber insurance policies cover ransomware, but each comes with conditions attached to that coverage. If you discover those conditions after funds have moved, you have no room to act on them.
Prior approval is not optional
Most cyber policies with ransomware coverage require you to notify your insurer and obtain approval before any ransom payment. That notification is a contractual condition of your coverage. Paying before you call your broker, even if you plan to claim the cost back, can void your ransomware coverage. Call your insurer or broker before any other incident response step.
Sanctions screening creates a shared obligation
Most cyber policies exclude reimbursement for payments made to sanctioned entities, which gives your insurer a direct financial interest in identifying the threat actor before any funds move. Share all attribution intelligence your IR firm has gathered and allow time for the insurer to complete their sanctions screening. If you transfer funds to a sanctioned group before that process finishes, you lose the insurance claim and face OFSI civil penalties on top.
Approved incident response panels
Many UK insurers maintain a panel of approved incident response vendors. Retaining an IR firm outside that panel, even a well-regarded one, can void your response cost coverage. Check your policy's panel requirements before you sign an IR retainer, and again before you call any firm in during a live incident.
Cyber extortion sub-limits
A £2 million cyber policy does not provide £2 million in ransomware coverage. Most policies carry a separate cyber extortion sub-limit that sits below the main policy limit. A £250,000 sub-limit on a £2 million policy leaves you self-insuring the remaining exposure if the ransom demand runs higher. Check your sub-limit now. If you discover that gap during a live attack, you have no time to address it.
The Lloyd's war and cyber war exclusion
Since January 2023, Lloyd's of London has required all standalone cyber policies to exclude losses attributed to state-sponsored attacks. If your IR firm or the NCSC attributes the campaign to a nation-state actor, your insurer may decline to pay. The exclusion covers attacks "carried out or supported by" a state, which leaves room for dispute, but policy interpretation runs on a timeline that gives you no advantage during an active incident.
Call your broker first. Document every decision your team takes, every communication with the attacker, and all attribution evidence your IR firm provides. Consult a solicitor with financial sanctions experience. Do not transfer funds without written acknowledgement from your insurer.
A Framework for the Ransom Decision
During a ransomware attack you have incomplete information and an attacker pushing for a quick decision. The steps below test whether payment is legally viable and mark the points at which you lose the choice by law or by insurance terms. Work through each step in sequence and stop at the first that produces a definitive outcome.
Are your backups intact, isolated from the production network, and confirmed restorable to a recent clean state?
Backups unavailable or compromised. Continue to step 2.
Has the attacker demonstrated a working decryptor on a sample of your encrypted files?
Decryptor sample confirmed. Continue to step 3.
Is the attacker or their affiliated group designated on the OFAC list or the OFSI UK financial sanctions register?
No sanctions match confirmed. Continue to step 4.
Have you notified your cyber insurer or broker and received written acknowledgement?
Insurer notified and acknowledged. Continue to step 5.
Does the ransom demand fall within your policy's cyber extortion sub-limit?
Ransom is within your covered extortion sub-limit. Continue to step 6.
Weigh the estimated recovery time without payment against the ransom cost and residual risks of paying.
Your IR firm can advise on the attacker's known decryption track record and your realistic restoration timeline without paying. Your solicitor can confirm any remaining compliance exposure. Your board and legal counsel make the final decision together. Document the reasoning in writing before any payment is authorised.
At step 6, your board and legal counsel make the final call. Four factors feed into that judgment: the ransom amount, your recovery timeline without paying, the attacker's known decryption track record, and your residual legal exposure. The five prior steps either resolve the decision before step 6 or define the scope of what they must weigh at step 6.
This article provides general information and does not constitute legal advice. The sanctions position changes as designations are added or removed. Seek advice from a solicitor with sanctions and cybersecurity experience before making any payment decision during an active incident.