Skip to main content

Cyber insurance industry unites to bear down on ransom payments

Joint guidance from the NCSC with the Association of British Insurers (ABI), British Insurance Brokers’ Association (BIBA) and International Underwriting Association (IUA) aims to help organisations faced with ransomware demands minimise disruption and the cost of an incident.
iStock.com/blackdovfx
  • Three major UK insurance associations unite with GCHQ’s National Cyber Security Centre to help reduce ransom payments made by victims of cyber crime
  • New guidance seeks to improve market-wide ransomware discipline and undermine the profitability of the ransom business model to reduce harm to victim organisations
  • Unprecedented cross-sector collaboration will strengthen UK-wide cyber resilience, offering a robust response to a 2023 parliamentary review into ransomware

THREE MAJOR UK INSURANCE ASSOCIATIONS have joined forces with the aim of toughening the sector’s approach to ransom payments in new guidance published today (Tuesday). 

The joint guidance, co-sponsored by the National Cyber Security Centre (NCSC) - a part of GCHQ, aims to thwart cyber criminals’ profits by improving market-wide ransom discipline and reducing the number of ransoms being paid by UK ransomware victims. 

NCSC CEO Felicity Oswald announced the initiative in a speech delivered on the first day of CYBERUK – the UK’s flagship cyber security conference which this year focuses on the theme of “Future tech, future threat, future ready”.

The cross-sector coalition comprising the Association of British Insurers (ABI), British Insurance Brokers’ Association (BIBA) and International Underwriting Association (IUA) is urging victim organisations to adhere to the steps outlined in Guidance for organisations considering payment in ransomware incidents

Developed from a NCSC-sponsored research paper by the Royal United Services Institute (RUSI), the best practice guidance sets out recommendations that aim to empower organisations and associated third parties to make informed decisions when faced with ransomware, and ultimately help minimise the disruption and cost of an incident. 

Considerations include the thorough assessment of business impact, reporting protocols, and where to access sources of support.

Ransomware remains the biggest day-to-day cyber security threat to UK organisations with attacks rising and the ransomware model continuing to evolve. The NCSC continues to strongly discourage the payment of ransoms, alongside law enforcement partners.

Paying a ransom does not guarantee the end of an incident nor the removal of malicious software from victims’ systems, but it does provide incentives for criminals to continue and expand their activities. Even following payments, cyber-criminal groups will lie about having deleted the data.

NCSC CEO Felicity Oswald said: 

“It’s really encouraging to see all corners of the insurance industry unite to support victim organisations with guidance that will help them to better understand their options and reduce harm and disruption to their businesses.

“The NCSC does not encourage, endorse or condone paying ransoms, and it’s a dangerous misconception that doing so will make an incident go away or free victims of any future headaches. In fact, every ransom that is paid signals to criminals that these attacks bear fruit and are worth doing.

“This cross-sector initiative is an excellent next step in foiling the ransom business model: we’re proud to support work that will see cyber criminals’ wallets emptier and UK organisations more resilient.” 

The joint guidance robustly addresses parliamentary recommendations made in December by the Joint Committee on the National Security Strategy (JCNSS) which called for “more detailed”, accessible guidance “on how best to avoid the payment of ransoms after an attack”.

In its report, JCNSS acknowledges that cyber insurance could provide “a vital lifeline for ransomware victims”, with this guidance deepening the important role the insurance industry can play as convenors of the incident response to help boost organisations’ resilience against ransomware.

ABI Director of General Insurance Policy Mervyn Skeet said: 

“We’re pleased to be working with NCSC, BIBA and the IUA on strengthening cyber resilience and supporting customers affected by ransomware attacks. Following the launch of our Cyber Safety Tool for SMEs last year, this collaborative guidance is another positive step towards tackling cyber crime across the UK, and we look forward to continuing to work with NCSC on this shared goal.”

BIBA Deputy Head of General Insurance Shaune Worrall said: 

“BIBA was proud to work with the ABI, IUA and the NCSC on this important guidance. It could help businesses form their response to one of the greatest risks to their organisation’s ability to trade: a ransomware attack.”

IUA Director of Public Policy Helen Dalziel said:

“The payment of ransoms in response to cyber attacks is on a downward trend globally. Businesses are realising that there are alternative options and this guidance further illustrates how firms can improve their operational resilience to resist criminal demands.”

The NCSC stood up the Cyber Insurance Industry Working Group (CIIWG) in 2023 to engage government, academia and the insurance industry on how to collectively strengthen UK online resilience and to encourage organisations to be transparent about their experience with cyber attacks – particularly ransomware.

The CIIWG and now this guidance build on the recent, world-first agreement by the Counter Ransomware Initiative (CRI) whose member nations jointly denounced ransomware attacks and committed to work to undermine the profitability of the ransomware business model.

Read the guidance in full