Banning Ransomware Payments? The Most Dangerous Idea in Cyber Policy
Politicians worldwide are calling for a ban on ransomware ransom payments. The logic sounds compelling: If no one pays, the business model collapses. In practice, a ban would criminalize victims, endanger hospitals, and drive payments underground. Why good intentions here are particularly poorly executed.
TL;DR
- Several governments – including Australia, the UK, and parts of US politics – are discussing or planning a ban on ransomware payments
- A ban would put victims in double jeopardy: data encrypted AND prosecuted if they pay
- Hospitals, utilities, and critical infrastructures face existential decisions – “payment or lives” becomes “payment, lives OR prison”
- Past experiences show: payments do not disappear with bans; they just become more opaque
The Compelling Logic – and Its Weakness
The argument for banning payments is simple: Ransomware is a business model. Without income, it collapses. Therefore: ban payments, solve the problem.
In the theory of deterrence, this works. In practice, it ignores three fundamental realities: First, the asymmetric power position of the victim at the moment of the attack. Second, the existential threat posed by permanent data loss. Third, the moral dimension when human lives are at stake.
The Hospital Scenario
A hospital is hit by ransomware. Patient administration is encrypted. Surgery plans are unavailable. Medication dosages cannot be retrieved. Patients must be transferred – but the emergency rooms of neighboring hospitals are already full.
The attackers demand 2 million Euros. IT estimates the recovery time at three to four weeks. The crisis team faces the decision: pay and operate again in hours – or not pay and risk patients for weeks in emergency mode.
A ban on payments adds a third dimension to this already impossible situation: The manager who pays to protect patients is prosecuted. This is not only impractical – it is cynical.
Why Bans Don’t Work
Payments become invisible, not impossible: Companies will pay through intermediaries, offshore structures, or “consulting fees.” Payment flows become more opaque, prosecution more difficult, and transparency zero. Exactly the opposite of the intended effect.
Asymmetric punishment: A ban punishes the victim, not the perpetrator. It criminalizes the act of self-defense, while the actual attack is already illegal. It’s like punishing hostage victims if they pay the ransom.
No transitional solution: A ban on payments without simultaneous, massive investment in prevention, detection, and recovery punishes companies for security gaps they cannot close with existing resources. Especially small and medium-sized enterprises (SMEs) and public institutions would have no alternative.
What Would Work Instead
Mandatory reporting before payment: Companies that want to pay must report the incident to an authority first. This enables prosecution, statistics, and possibly alternative support – without criminalizing the victim.
Non-deductibility of payments: Ransom payments should not be tax-deductible. This increases the economic cost of payment without banning it. A softer control mechanism that sets incentives rather than criminalizing.
Massive investment in resilience: Instead of banning payments, the state should ensure that companies do not need them: subsidized backup solutions, free incident response teams for SMEs, decryption tools via Europol/No More Ransom.
Conclusion: Protect Victims, Don’t Punish Them
A ban on payments is a political gesture that ignores operational realities. The right response to ransomware lies in prevention, resilience, and international prosecution – not in the criminalization of victims. Those who truly want to combat ransomware must pursue the perpetrators and strengthen the victims. A ban does the opposite.
Key Facts
Willingness to Pay: 46 percent of affected companies pay the ransom – in hospitals and critical infrastructure, the rate is over 60 percent (Sophos State of Ransomware, 2024).
Recovery Costs: The average total cost of a ransomware incident is 4.5 million Euros – regardless of whether ransom is paid or not. Payment only shortens the downtime.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
Should you pay at all?
The recommendation from BSI (Federal Office for Information Security), FBI, and Europol is: No. Reality shows: In existential threats, companies still pay. The decision must lie with the victim, not the legislator who does not know the concrete situation.
Does No More Ransom work as an alternative?
Partially. The platform offers free decryption tools for known ransomware variants. For new or adapted variants, there is often no solution. No More Ransom is an important building block but not a complete replacement for the payment option.
What are other countries doing?
Australia has introduced a mandatory reporting requirement. The USA is discussing a ban for federal agencies, not for the private sector. The EU is focusing on transparency and prosecution rather than bans. There is no global consensus.
Related Articles
- The Digital Geneva Convention: Why International Law Fails in Cyberspace
- AI Weapons Are in Use – And No One Is Controlling Them
- Germany’s Cybersecurity Is an Illusion – Why BSI Reports and NIS2 Lull Us into False Security
More from the MBF Media Network