/ 1 min read / Data Centre Solutions

New Ransomware Legislation: Implications for UK Data Centres

At present, making ransom payments in the case of a ransomware attack is not unlawful unless funds are directed to sanctioned or terrorist-linked groups, although making ransom payments is discouraged by UK authorities. As a result, many organisations still weigh the option of paying to mitigate disruption.

In January 2025, however, the UK government proposed prohibiting ransomware payments by public sector bodies and Critical National Infrastructure sectors, which includes Data Infrastructure as a sub-sector of Communications (a September 2024 development). This measure aims to deter attacks and clarify obligations for organisations and insurers, while removing the need for complex forensic checks on payment sources and destinations that would currently need to be made to avoid the risk of breaching sanctions law. Whilst there is currently no timeline imposed by the government for the implementation of these proposals, the government published its response to the public consultation in July 2025 and is giving every indication that it will continue to make progress with these reforms.

Read the full article at datacentre.solutions.

Related Insights