THREAT BRIEFING · 23.09.2026 DEENFRES

Strategy & Governance

Banning Ransomware Payments? The Most Dangerous Idea in Cyber Policy

By Tobias Massow · December 18, 2025 · 5 min read

Politicians worldwide are calling for a ban on ransomware ransom payments. The logic sounds compelling: If no one pays, the business model collapses. In practice, a ban would criminalize victims, endanger hospitals, and drive payments underground. Why good intentions here are particularly poorly executed.

TL;DR

The Compelling Logic – and Its Weakness

The argument for banning payments is simple: Ransomware is a business model. Without income, it collapses. Therefore: ban payments, solve the problem.

In the theory of deterrence, this works. In practice, it ignores three fundamental realities: First, the asymmetric power position of the victim at the moment of the attack. Second, the existential threat posed by permanent data loss. Third, the moral dimension when human lives are at stake.

The Hospital Scenario

A hospital is hit by ransomware. Patient administration is encrypted. Surgery plans are unavailable. Medication dosages cannot be retrieved. Patients must be transferred – but the emergency rooms of neighboring hospitals are already full.

The attackers demand 2 million Euros. IT estimates the recovery time at three to four weeks. The crisis team faces the decision: pay and operate again in hours – or not pay and risk patients for weeks in emergency mode.

A ban on payments adds a third dimension to this already impossible situation: The manager who pays to protect patients is prosecuted. This is not only impractical – it is cynical.

Why Bans Don’t Work

Payments become invisible, not impossible: Companies will pay through intermediaries, offshore structures, or “consulting fees.” Payment flows become more opaque, prosecution more difficult, and transparency zero. Exactly the opposite of the intended effect.

Asymmetric punishment: A ban punishes the victim, not the perpetrator. It criminalizes the act of self-defense, while the actual attack is already illegal. It’s like punishing hostage victims if they pay the ransom.

No transitional solution: A ban on payments without simultaneous, massive investment in prevention, detection, and recovery punishes companies for security gaps they cannot close with existing resources. Especially small and medium-sized enterprises (SMEs) and public institutions would have no alternative.

What Would Work Instead

Mandatory reporting before payment: Companies that want to pay must report the incident to an authority first. This enables prosecution, statistics, and possibly alternative support – without criminalizing the victim.

Non-deductibility of payments: Ransom payments should not be tax-deductible. This increases the economic cost of payment without banning it. A softer control mechanism that sets incentives rather than criminalizing.

Massive investment in resilience: Instead of banning payments, the state should ensure that companies do not need them: subsidized backup solutions, free incident response teams for SMEs, decryption tools via Europol/No More Ransom.

Conclusion: Protect Victims, Don’t Punish Them

A ban on payments is a political gesture that ignores operational realities. The right response to ransomware lies in prevention, resilience, and international prosecution – not in the criminalization of victims. Those who truly want to combat ransomware must pursue the perpetrators and strengthen the victims. A ban does the opposite.

Key Facts

Willingness to Pay: 46 percent of affected companies pay the ransom – in hospitals and critical infrastructure, the rate is over 60 percent (Sophos State of Ransomware, 2024).

Recovery Costs: The average total cost of a ransomware incident is 4.5 million Euros – regardless of whether ransom is paid or not. Payment only shortens the downtime.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

Should you pay at all?

The recommendation from BSI (Federal Office for Information Security), FBI, and Europol is: No. Reality shows: In existential threats, companies still pay. The decision must lie with the victim, not the legislator who does not know the concrete situation.

Does No More Ransom work as an alternative?

Partially. The platform offers free decryption tools for known ransomware variants. For new or adapted variants, there is often no solution. No More Ransom is an important building block but not a complete replacement for the payment option.

What are other countries doing?

Australia has introduced a mandatory reporting requirement. The USA is discussing a ban for federal agencies, not for the private sector. The EU is focusing on transparency and prosecution rather than bans. There is no global consensus.

Related Articles

More from the MBF Media Network

MyBusinessFutureCrisis Management for Decision-Makers on mybusinessfuture.comDigital ChiefsRegulation and Compliance on digital-chiefs.de

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH