Despite this,
The proposed ban would legally prohibit ransom payments by public sector organizations and operators of critical national infrastructure (CNI), including schools, NHS trusts, local authorities, and transport, energy, and telecoms providers. All other businesses, including the private sector not covered by the ban, would be required to notify the government of any intent to pay a ransom.
Support for a ban is strong in both sectors, as is shown in the survey:
Of those who support a proposed payment ban, more than a third (
The latest Cyber Security Breaches Survey 2025 from the
Given the proliferation of attacks, almost all respondents (
Recovery from a cyberattack takes 24 days on average. For large organisations this means financial losses, but for smaller organisations this can lead to bankruptcy, underlining the urgency for greater investment in recovery readiness.
“Paying a ransom rarely guarantees recovery and often increases the likelihood of being targeted again,” said Darren Thomson, Field CTO (security), EMEA, at Commvault. “A well-enforced ban could help take the profit out of ransomware, but it must be matched by greater investment in prevention, detection, and recovery-testing. Without that, more organisations could find themselves exposed at the worst possible moment, with no viable path to recovery.”
“Ransomware and cyberattacks will be a concern for a long time, as international cyber gangs make huge profits from them and use these resources to continually develop their attack tools,” says Jane Frankland MBE, CEO of Knewstart. “To break this cycle, companies must better prepare for emergencies and strengthen their cyber resilience. This will allow them to maintain operations and continue to serve customers during a cyber incident.”
Research Methodology
This survey was conducted independently and exclusively for Commvault by Censuswide. It reveals the views of 1,000
The sample comprised of CEOs, COOs, CFOs, CTOs, CIOs, CISOs, CMOs, Chief People Officers (CPO), Chief Sustainability Officers (CSO), Chief Compliance Officers (CCO), Chief ESG Officers (CESGO) and Chief Trust Officers (CTrO). Data for this report was collected between June 4 and June 6, 2025.
Censuswide abides by and employs members of the Market Research Society, follows the MRS code of conduct and ESOMAR principles, and is also a member of the British Polling Council.
About Commvault
Commvault (NASDAQ: CVLT) is the gold standard in cyber resilience, helping more than 100,000 organisations keep data safe and businesses resilient and moving forward. Today, Commvault offers the only cyber resilience platform that combines the best data security and rapid recovery at enterprise scale across any workload, anywhere—at the lowest TCO.
View original content to download multimedia:https://www.prnewswire.com/news-releases/75-of-uk-businesses-would-break-a-ransomware-payment-ban-to-save-their-company-risking-criminal-charges-302516590.html
SOURCE COMMVAULT