In 2024, the debate over ransomware payment bans intensified. The US, UK, and several EU member states are considering legislation that would make it illegal to pay ransomware demands. The arguments on both sides are strong. The implications for SMEs are significant.
At Metaluxo we advise SMEs on incident response, including the legal and business considerations around ransom payments. This post outlines the debate and what it means for smaller companies.
The case for a ban
Prohibition reduces funding. Ransomware is a business model. If payments are illegal, the revenue dries up and the attacks become less profitable.
Payment does not guarantee recovery. Studies suggest that 20–30% of victims who pay do not receive working decryption keys. The payment may be wasted.
Payment funds crime. Ransom payments are laundered through cryptocurrency exchanges and used to fund other criminal activity, including human trafficking and terrorism.
Payment encourages more attacks. Successful ransom payments are publicised by attackers as proof that the model works, encouraging copycat attacks.
The case against a ban
Bans do not stop payments. They drive payments underground. Victims pay through intermediaries in jurisdictions without bans. The attackers still get paid, but the victim has no legal recourse if the decryption key does not work.
SMEs need recovery options. For a small company with no backups and no cyber insurance, a ransomware attack can be fatal. A ban removes the last option for recovery.
Law enforcement cannot help quickly. The time to investigate and trace a ransomware payment is months. An SME needs to recover in days.
Bans shift liability. If paying is illegal, victims may fear reporting attacks to law enforcement, reducing intelligence sharing and making it harder to track attackers.
The middle ground: regulation, not prohibition
Most cybersecurity professionals advocate regulation rather than an outright ban:
- Mandatory reporting. Every ransom payment must be reported to law enforcement within 24 hours.
- Insurance restrictions. Cyber insurance policies should not cover ransom payments without law enforcement consultation.
- Licence requirements. Only licensed incident response firms should be permitted to negotiate with attackers.
- Sanctions checks. Payments must be screened against sanctions lists before execution.
This approach preserves the recovery option for SMEs while making payments less attractive to attackers and ensuring law enforcement visibility.
What SMEs should do now
Regardless of whether bans are enacted, SMEs should:
- Eliminate the need to pay. Tested backups, incident response plans, and business continuity arrangements make payment unnecessary.
- Review insurance policies. Know whether your policy covers ransom payments and under what conditions.
- Engage legal counsel. If you are attacked, legal advice on payment should be sought before any decision is made.
- Report to law enforcement. Even if you pay, report the incident. It helps law enforcement track attackers and may support a future insurance claim.
At Metaluxo we help SMEs prepare for ransomware incidents without relying on payment as a strategy. If your incident response plan assumes you might pay, book a free 30-minute consultation and we will build a plan that does not need to.